As our world becomes increasingly connected, protecting Boston University’s data and technology is more important than ever. The Cybersecurity Policy, Compliance & Risk Service is here to guide the University community through a complex landscape of laws, regulations, policies, standards, and best practices that affect the information we use every day. Our team works to develop and maintain robust security policies and standards, and, most importantly, we’re ready to help you understand what’s required and how to put those requirements into practice in your daily work.
We provide support for faculty, staff, researchers, and students, helping you design systems and processes that comply with legal and regulatory requirements, follow Boston University’s policies, and reflect industry best practices. Whether you’re launching a new project, working on academic or research initiatives, installing third-party software, adopting cloud services, or managing operating systems and databases, our security consulting services are here to assist.
Through practical guidance and proactive risk management, we help you safeguard sensitive information, ensure the continuity of research and operations, and boost organizational resilience. Our goal is to make security measures accessible and adaptable, so you can confidently pursue your goals with the assurance that your work is protected by a responsive, vigilant information security framework.
-
We develop policies and standards to protect data and systems and helps the community understand and apply them. Their goal is to make it easier for everyone to practice good security and keep information safe.... more »
-
We assist the community in meeting diverse compliance requirements, including major regimes like PCI, NIST, HIPAA, GLBA, and GDPR. The team supports researchers by guiding them through data protection processes, interpreting agreements, and helping to prepare the necessary documentation to meet sponsor expectations.... more »
-
We work to protect University data on campus IT infrastructure, cloud solutions, and third-party services by actively assessing risks to these systems. They help ensure information systems used with university data take appropriate steps to safeguard information.... more »
