Responsible Executive: Executive Vice President for Business and Finance
Responsible Officer: Chief Information Officer
I. Purpose
This policy establishes the guidelines individuals must follow regarding security awareness training, including the understanding of following internal and external governance and having a general awareness of potential threats the College can face, as well as to maintain compliance with various governance and governing bodies as required for ongoing business operations.
II. Scope
This policy applies to all Motlow State employees regardless of status and all others with access to Motlow systems.
III. Definitions
- Information Technology or IT - shall refer to the College’s Information Technology department.
- Covered Data and Information:
- Nonpublic financial information – In accordance with TBR policy B-090: Non-public financial information is any record not publicly available that an institution obtains about a customer in the process of offering a financial product or service, as well as such information provided to the institution by another source. Nonpublic financial information includes information that a person submits to apply for financial aid (e.g., tax returns and other financial information), that an institution collects from third parties relating to financial aid (e.g., FAFSA information), and that an institution creates based on customer information in its possession.
- Personally identifiable information or PII - shall refer to information which can be used to distinguish or trace an individual’s identity, such as their name, Social Security number, or biometric records, alone, or when combined with other personal or identifying information which is linked or linkable to specific individual, such as date and place of birth, mother’s maiden name, etc.
IV. Introduction
- As part of ongoing business operations, the College must meet and remain in compliance
with various internal and external governance, including but not limited to, the Tennessee
Board of Regents, the State of Tennessee, and various Federal laws and acts. Such
governance includes, but is not limited to:
- The Family Educational Rights and Privacy Act (FERPA)
- The Health Insurance Portability and Accountability Act (HIPAA)
- The Gramm-Leach-Bliley Act (GLBA)
- The Federal Trade Commission (FTC) Safeguards Rule
- The Payment Card Industry Data Security Standard (PCI DSS)
- NIST SP 800-171
- Data Retention and Disposal as per TBR Policy 1.12.01.00
- Motlow Cyber Incident Response Plan (CIRP). The CIRP includes protocols and procedures for reporting incidents in writing to State and Federal agencies.
- The College processes nonpublic financial information as part of ongoing business
operations. Nonpublic financial information includes any information that either:
- Student or other third party provides in order to obtain a financial service from the College
- Any list, description, or other grouping of consumers (including publicly available information pertaining to them) that is derived using any personally identifiable financial information that is not publicly available.
V. Security Risk Assessment
The College’s Information Security Program will identify reasonably foreseeable internal and external risks regarding the security, confidentiality, and integrity of nonpublic financial information that could result in the unauthorized disclosure, misuse, vandalism, or compromise of such information, and assess the sufficiency of all safeguards in place regarding these identified risks. The College will assess the following:
- Identify all employees that have any access to personally identifiable information and/or nonpublic financial information (collectively, privileged information).
- Identify and develop awareness training for all employees based on the level of access to privileged information.
- Identify and implement reasonable safeguards for both physically accessed information aand digitally accessed information.
- Identify the controls that are required to detect, prevent, and respond to threats or failures of systems in place.
- Security Awareness Training
- The College recognizes that one of the most serious threats to the security, confidentiality, and integrity of privileged information is human error.
- Training employees to recognize and protect privileged information is paramount to the success of the program.
- Mandatory training will be offered in an online format with content designed to satisfy security awareness training requirements that meet or exceed the requirements assigned through governance.
- Additionally, supplemental training will be offered to build upon the mandatory annual training offered.
- The Chief Information Security Officer (CISO) will monitor and report training status and completion to the appropriate College personnel.
- The CISO will review training content at least annually to ensure up-to-date information within the training. For more details, reference Motlow policy: 1:08:00:06 IT Security Awareness Training.
II. Safeguards of Information Systems / Technology
- Hard Copy Records
- Motlow State recognizes that it has both internal and external risks involving hard
copy records. These risks may include, but are not limited to:
- Unauthorized access to covered data and information (i.e., mailing addresses, phone numbers, bank and credit card account numbers, income tax records, credit histories, and Social Security numbers) by someone other than the owner of the covered data and information
- Unauthorized access of covered data and information by employees
- Unauthorized requests for covered data and information by someone other than the owner of the covered data and information Unauthorized access to hard copy files or records
- Unauthorized transfer/delivery of covered data and information through third parties
- Risks associated with the protection of hard copy and covered data and information change as procedures within the College change. To this end, the College will actively monitor and/or participate in advisory groups associated with the security risks involving hard copy records.
- Motlow State assesses a need for reasonable and appropriate steps to be taken to specifically train employees who are in contact with hard copy records of covered data and information to ensure that hard copy records of covered data and information may be protected from internal and external risks.
- Motlow State recognizes that it has both internal and external risks involving hard
copy records. These risks may include, but are not limited to:
- Electronic Records
-
- Motlow State’s computer network consists of thousands of staff and customers, most of whom are students, stretched across the Middle Tennessee region. These users are capable of reaching all College computer resources from any of the College’s campuses via data lines connected to the main campus. A network the size of Motlow State’s is vulnerable to many types of security breaches, malware, and malicious use by unauthorized as well as authorized users. Internal network resources, servers, and computers are vulnerable to staff and/or student misuse by releasing known or unknown malware that could infect the entire network, possibly allowing data to be easily accessed.
- Computer systems that lack password authentication could open confidential information to countless numbers of unauthorized users. Having networks that are commingled with many types of users can also allow unscrupulous users the ability to intercept traffic as it flows across the network as well as launch denial of service attacks at multiple systems. Other ways data integrity can be violated is simply by users sharing passwords or allowing others to access their computer session. Loss of data is always a possibility due to power failure, system failure, or user error.
- Motlow State requires Multi-Factor Authentication (MFA) for all user accounts that access institutional information systems, applications, cloud services, and network resources. MFA shall be enabled for all faculty, staff, students, contractors, and other authorized users where technically feasible.
-
- Methods to Detect, Prevent, and Respond to Incidents
-
- Motlow State offers Internet access to all users at all campuses. By allowing access to the Internet, the College is also allowing Internet users to access its internal network. This can often lead to many of the same risks that are associated with the internal network as stated above, but those risks are multiplied due to the vastness of the Internet. Malicious users on the Internet often take advantage of vendor security flaws to attack systems and access restricted data.
- Motlow State has identified that users from the Internet could attack college computers and servers using known and unknown software and hardware vulnerabilities or deliver malware payloads directly to a computer or indirectly via email. Having open systems available to the Internet can often lead to direct system attacks by using specialized software written specifically to locate user accounts, user passwords, system security vulnerabilities, or vendor specific system flaws.
-
VII. Implementation of Safeguards
- Employee Training and Management
- During employee orientation, each new employee from areas that work with covered data and information will be informed of the online training on the importance of confidentiality of student records, student financial information, and other types of covered data and information.
- Each new employee will also be trained in the proper use of computer information and passwords.
- Training will also include controls and procedures to prevent Mandate Encryption at Rest and in Transit for all covered employees from providing confidential information to an unauthorized individual and how to properly dispose of documents that contain covered data and information.
- Each employee responsible for maintaining covered data and information will be instructed on how the College takes steps to protect the information from destruction, loss or damage due to environmental hazards, such as fire and water damage or technical failures.
- Mandatory training will be offered in an online format with content designed to satisfy GLBA training requirements.
- Once the training has been completed, the employee will certify that he or she has participated in this training.
- The Human Resources Office will then receive an email that the training has been completed.
- Motlow State will continue with annual training requirements as required by Motlow State and TBR policy for all GLBA affected employees.
- All new employees will be informed of the GLBA online training as part of the orientation process. For more details, reference Motlow policy: 1:08:00:06 IT Security Awareness Training.
B. Safeguards of Information Systems/Technology
-
- Hard Copy Records: To ensure that all Motlow State employees are in compliance with
the GLBA, the following guide outlines basic measures for ensuring student hard copy
records. Information that must be protected under GLBA includes, but is not limited
to, is the the following:
- Information including, but not limited to, names, addresses, phone numbers, bank and credit card account numbers, financial information, income credit histories, and Social Security numbers.
- Directory information not associated with GLBA may be released in accordance with the Motlow State student record policy and FERPA guidelines.Covered data and information may be requested by phone, text or email from a third party other than the owner of the data or information. This fraudulent attempt to access personal information is called “social engineering.” Social engineering refers to all techniques that are utilized to trick an individual into divulging information or performing an action for illegitimate reasons. These attacks can result in identity theft and financial loss. It is important that any employee who receives a fraudulent request to report the request for information to the Chief Information Security Officer (CISO) or Chief Information Officer (CIO) or their designee.
- At times, an employee may suspect that the third party requesting information is involved in pretexting, which is defined as an attacker that fabricates a story to convince a victim to give up information or access to a service or system utilizing improperly obtained personal information. Pretexters may pose as a student or someone authorized to have student covered data and information. The pretexter, in an effort to gain employee trust, may offer a piece of personal information about the student already in their possession. If it is suspected that the request for covered student data and information is fraudulent, the request should immediately be reported to the Executive Vice President for Student Success, who is considered the keeper of all hard copy student data and information. An employee should never give out a student’s social security number over the phone or email and never confirm covered data and information a third party caller provides.
- A student’s personal information may be released only if the student has specifically authorized you (the employee) to do so in a written waiver, and only if the release meets one of the stipulations covered by the College’s internal policies that follow FERPA guidelines.
- Hard copy records, printouts, forms, phone messages, etc. that contain covered data and information Cmust also be secured. Employees should not leave any of the above materials containing covered data or information where an unauthorized person from inside or outside the institution could obtain this data.
- Hard copy materials containing student covered data and information should be secured in locked filing cabinets or other secured storage areas.
- Hard Copy Records: To ensure that all Motlow State employees are in compliance with
the GLBA, the following guide outlines basic measures for ensuring student hard copy
records. Information that must be protected under GLBA includes, but is not limited
to, is the the following:
C. Electronic Records
-
- Motlow State has taken proactive steps to protect the network and secure confidential information. Routine system upgrades are performed to ensure all network, server, and computer systems have the latest vendor releases. Network and server personnel routinely apply appropriate security system patches as released by the vendors. The College has implemented a domain structure where all computers are controlled centrally and require user authentication in order to logon. All shared server resources are secured by requiring user authentication. Data is further protected by allowing users the ability to view and edit data through restricted user rights. Only approved users will have read/write permissions to certain Motlow State data. In order to access a system, a user must have a unique username and password in accordance to 1:08:03:00 Access Control and adhere to system password policies and/or guidelines. Each user must agree to follow the College’s computer use policies and/or guidelines, which include not sharing usernames, passwords, or confidential information. Users are not allowed access to restricted information until properly authorized according to current policies. The College has protected against network traffic interception by implementing multiple virtual networks on switched networking equipment.
- Wireless network traffic is protected by using authentication to access the wireless network, and encrypting the data to secure it from being intercepted.
- All computers and server systems are protected by endpoint detection and response (EDR) software that is automatically updated to the latest vendor releases. All email is scanned for viruses before the user has access to the message or as the message is being sent by the user. Loss of information either by system failure, power failure, or user error is protected by having redundant server systems with multiple hard drives that are backed up on a daily basis. All phone systems and POE switches are protected from power outages or spikes by universal power supplies and will allow the system to operate for short periods during emergencies. Motlow State’s server rooms have UPS backups that will take over in case of a power outage. The College also has disaster recovery policies to mitigate risk of downtime and data loss after a disaster.
D. Methods to Detect, Prevent, and Respond to Incidents
-
- All Internet traffic must pass through a firewall that protects all internal campus computers from direct Internet attacks. Suspect network traffic is isolated and removed from the network. To further strengthen the network from intrusion from the Internet, internal non-routable private IP addressing has been implemented. This ensures that all traffic coming from the Internet pass through the firewall and be inspected before being forwarded to any College computer system. All servers that are accessible from the Internet are isolated on a separate network to further protect confidential information. No internal network system allows direct contact from the Internet.
- The Chief Information Security Officer and designees monitor all systems for any indication of attacks, intrusion, or system failures. Network monitoring systems are in place that will alert staff when systems have failed and are unreachable by users. Other systems alert staff that attacks are taking place against network systems, and some systems have automatic safeguards to isolate themselves to protect the network as a whole. Other methods of detection include, but are not limited to, monitoring system logs, paging systems, and email systems. Information Technology staff constantly research current trends in network and system security and attempt to implement safeguards before an attack takes place. Other safeguards include constant review of current policies and procedures and modifying ones needed to keep current with. technology changes. User accounts are periodically evaluated to make sure users are currently employed and that a user does not have access to unauthorized systems.
VIII. Oversight of Service Providers and Contracts
- The College may share customers’ nonpublic financial information with third parties as appropriate during the normal course of business. Such business activities may include, but not limited to, collection of accounts, transmission of documents, destruction of paper and electronic records, destruction of equipment, and other similar services. Within the framework of this policy, the College will ensure that reasonable steps are taken to secure third party contractors that are willing and capable of appropriately securing customers’ nonpublic financial information. College contracts with third party service providers will include standard contract provisions promulgated by the Tennessee Board of Regents that require the service provider to comply with GLBA safeguarding rules in its handling of such records. Existing contracts will be reviewed; if GLBA applies, the contracts will be amended by incorporating the standard TBR amendment.
- The Contracts Officer will work with the Office of Business and Finance and other units as appropriate to identify third party service providers that are provided access to customers’ nonpublic financial information. The Contracts Officer will work with appropriate campus and TBR personnel to ensure that third party service provider contracts contain language to protect customers’ nonpublic financial information.
IX. Evaluation and Revision of Program
- The Information Security Program will be subject to periodic review and adjustment. Continued administration of the development, implementation and maintenance of the program will be the responsibility of the executive staff who will assign specific responsibility for implementation and administration as appropriate. The executive staff will no less than annually review the standards set forth in this policy and recommend updates and revisions as necessary. It may be necessary to adjust the program to reflect changes in technology, the sensitivity of student/customer data, and internal or external threats to information security.
Sources
History
Information Security Program and Awareness Policy – Proposed Replacement for Policy 1:08.00.02, Information Security Program (Gramm-Leach-Bliley): May 29, 2026
IOC Approved: August 21, 2026
President’s Cabinet Approved: TBD
Effective Date: TBD
