We Updated All Thirteen Data Protection Standards—Here’s What Changed

If you work with BU data—and nearly everyone here does—the rules that govern how you protect it just got clearer.

We’ve completed a full revision of the Data Protection Standards, the documents that function as university policy under the Information Security Policy. This was more than a refresh. Several documents were renamed from Policy to Standard so they sit properly in the collection, and every one now follows a common template with a uniform compliance notice, a defined exemption request process, and a complete version history. If you’ve ever gone looking for the current version of a requirement and couldn’t tell whether you’d found it, that problem is solved.

The revisions also close real gaps. Artificial intelligence, Internet of Things devices, and removable media now get explicit treatment. Several standards are entirely new or replace narrower predecessors—covering data centers, network security monitoring, cyber risk management and assessment, and log retention.

You don’t need to read all ten. Find the ones that touch your work, and start there. Here’s what changed.

This set of standards are part of the Data Protection Standards which function as university policy through authorities delegated by the Information Security Policy. Some documents have been renamed from Policy to Standard to make them fit appropriately in the standards collection. The documents have also been adjusted to fit a common template, which includes a uniform compliance notice and exemption request process as well as a complete version history.

In addition to these housekeeping changes, the standards have been revised as follows:

01Data Classification Standards

The standard articulates a more refined stance on research data which was previously categorized as Public. This is consistent with our current practices. The standard also gives more authority to the CISO to limit Restricted Use data processing.

02Data Access Management Standards

The standard removes mainframe references, adds audit requirements for Data Custodian work, transfers maintenance of the Data Trustee and Data Security Administrator program to AS&IR, acknowledges the role of developers outside of IS&T and requires all developers to address access control to Subject Data, including in AI systems.

03Identity and Access Management Standards

The standard removes mainframe references and language regarding a retired legacy directory system, specifies account disables for inactive accounts. Mapping to the most common NIST standard, Special Publication 800.171, has been updated.

04Minimum Security Standards

The section describing how the standard intersects with Restricted Use data was rewritten and the standard was reorganized into “parts” to enable easier reference of the required controls. Explicit callouts for removable media/storage and Artificial Intelligence were added. Additional audit controls were added for endpoints to support compliance objectives, and a section was added for Internet of Things (IoT) devices. Overall, language was modified to make the requirements more strict, which enables better visibility to areas of weakness by requiring documentation of non-compliance with controls. Mapping to the most common NIST standard, Special Publication 800.171, is provided at the end of the policy as an appendix.

05Cybersecurity Training, Compliance, and Remediation Standards

The changes to this standard are largely minor, restating the awareness methods and objectives and replacing a list of compliance monitoring methods that overlaps other standards with a more general statement of intent for monitoring compliance.

06Data Center Standard

This standard establishes the required safeguards at all data centers that provide services to the university broadly. This is a replacement of the existing Data Center Policy that applies only to IS&T-managed datacenters.

07Vulnerability Management Standard

Derived from the existing Vulnerability Management Policy, this policy applies across the university. Some portions of the existing policy are moved to a procedures section to enable more frequent/responsive updating while leaving the core principles in place.

08Cyber Risk Management Standard

This is a new standard to define how cyber risks are accepted by the organization, requiring mitigation efforts as appropriate. It defines roles, timelines, and the approval process for accepting risk.

09Cyber Risk Assessment Standard

This standard establishes an approach for identifying, evaluating, and prioritizing cybersecurity risks at Boston University. This ensures a consistent methodology for determining the severity of risks, which serves as a precursor to risk management decisions.

10Log Collection, Analysis, and Retention Standard

Sets the standard for what systems and application activity data must be logged, and how those logs must be managed and retained to support university operations, including digital forensics and other legal, regulatory, and contractual requirements.