Skip to Main Content

Information Security Information Resources & Technology

Support Page Content

CSU Information Security Policy and Standards

Sacramento State is committed to protecting the confidentiality, integrity, and availability of information assets owned, leased, or entrusted to the University. Therefore, we hereby adopt both the California State University Information Security Policies and Standards and the Sacramento State Supplemental Information Security Policies.

Policies vs. Standards vs. Procedures

  • Policies are formal statements created by the university that reflect our mission, which in this case is the protection of Sacramento State's information and assets.
  • Standards are rules or actions that must be done to ensure our policies are being followed. They indicate expected behavior and must be enforced.
  • Procedures are detailed step by step instructions on how to implement or adhere to the standards.
  • Guidelines are recommended practices that are based on industry-standard practices.

Sacramento State Information Security Policy

CSU Information Security Policy and Standards

I. Policy

II. Scope

III. Roles and Responsibilities

IV. ISO Policies

Policies and standards are organized in the following, clickable index:

Govern (GV)

Identify (ID)

Protect (PR)

Detect (DE)

Respond (RS)

Recover (RC)

Policy Section Supplemental Policies Standards Procedures, Guidelines, Others
RC.RP - Incident Recovery Plan Execution   RC.RP - Incident Recovery Plan Execution