Standards

OIS standards reflect current security requirements and recommendations for the WashU Community. The accuracy, completeness, and relevance of the content may change over time as regulations, industry standards, and the security landscape evolve. Additionally, the expectations communicated in the standards may be impacted by OIS projects or projects underway elsewhere at WashU.

The OIS regularly reviews and updates these standards, but some details may become temporarily outdated due to the changes described above. Readers may reach the OIS team at infosec@wustl.edu with questions.

Showing: All results

200 Information Security Classification, Labeling, and Handling

This standard defines classification categories and control zones for data, information, and systems at Washington University in St. Louis (WashU).

200.1 Information Security Awareness, Behavior, and Culture

This standard establishes and describes a cybersecurity awareness training program for the WashU community.

201 Information Security Logging and Event Monitoring

This standard describes logging practices for events occurring within networks and systems of Washington University in St. Louis (WashU).

202 Information Security Identity, Authentication, and Access Control

DRAFT This standard establishes requirements for verifying user identities and authenticating user requests for access to systems and services at Washington University in St. Louis (WashU). This standard also communicates expectations that system managers and administrators must follow to control access to WashU information resources.

203 Universal Device Management

DRAFT This standard is designed to mitigate risk, protect sensitive data, and maintain the overall security posture of Washington University in St. Louis (WashU) by ensuring all devices used for university activities are properly configured, secured, and maintained.

204 Information Security Vulnerability Management

DRAFT This standard establishes a structured approach to identifying, assessing, prioritizing, and mitigating vulnerabilities within the IT infrastructure at Washington University in St. Louis (WashU).

205 Information Security Risk Management

DRAFT This standard supports Policy 105: Information Security Risk Management by providing a detailed framework for identifying, assessing, mitigating, and managing security risks to the university.

206 Server Security

DRAFT This standard establishes a protocol for securing servers within Washington University in St. Louis (WashU).

206.1 Network Security

DRAFT This standard establishes a comprehensive framework for protecting WashU’s network infrastructure against threats and vulnerabilities.

206.2 Virtual Private Networks

DRAFT This standard provides the minimum requirements for the use of Virtual Private Network (VPN) connections to internal networks at Washington University in St. Louis (WashU).

207 Information Technology Business Continuity and Disaster Recovery Planning

This standard provides a basis for funding decisions for incident response and recovery at Washington University in St. Louis (WashU).

208 Information Security Handling of Requests for Access to WashU User Content

DRAFT This standard specifies the circumstances in which the OIS facilitates access to user content
during investigations and for the continuation of university activities. Additionally, this standard
communicates typical retention practices for User Accounts and Content.

209 Information Security Incident Response and Recovery

This standard establishes processes related to incident detection, response, and containment.

211 Secure Software Development, Management, and Administration

DRAFT This standard establishes a comprehensive framework for ensuring the security and integrity of software systems within WashU.

213 Information Security Encryption

DRAFT This standard establishes security guidelines at the university to protect electronic information from unauthorized access, modification, or loss during storage, transfer, or use.

213.1 Digital Certificates

DRAFT This standard establishes guidelines and protocols for the issuance, management, and use of digital certificates at Washington University in St. Louis (WashU).