Kankakee Community College recognizes the vital role information technology plays in the College’s missions and related administrative activities as well as the importance in an academic environment of protecting information in all forms. As more information is used and shared in a digital format by students, faculty, and staff, both within and outside the college, an increased effort must be made to protect the information and the technology resources that support it. Increased protection of our information and information technology resources is necessary to assure the usability and availability of those resources and is the primary purpose of the College’s information security policies document. This document also addresses privacy and the usage of those who access College information and utilize College information technology resources as well as actions to be taken in the event of a data breach or disaster. Highlights of the policies document includes:
- General information technology policy addressing general principles, privacy, and data classifications and access restrictions.
- Acceptable use of the College’s computing resources.
- Retention of College records
- Copyright
- Social security numbers
- Information Security Program addressing the College’s approach to data security standards related to Family Educational Rights and Privacy Act (FERPA), Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standards (PCI DSS), and Gramm-Leach-Bliley Act (GLBA).
- Red Flags, which is the College’s identity theft prevention program.
- Incident Response Plan addressing privacy or security incidents in a way that limits damage, increases the confidence of external stakeholders, satisfies legal obligations, and reduces costs.
- Disaster Recovery Plan presents the requirements and the steps that will be taken in response to, and for the recovery from, any disaster affecting IT services at the College, with the fundamental goal of allowing basic business functions to resume and continue until such time as all systems can be restored to pre-disaster functionality.
The Senior Director of Information Technology Services, under the oversight of the Vice President of Business Affairs, will be responsible for administering these policies as well as chairing the teams/committees associated with the College’s overall information security.