Policies & Procedures
IT9004.2 Risk Assessment Procedure
| Procedure | IT Risk Assessment | Procedure No. | IT 9004.2 |
|---|---|---|---|
| Delegated Authority | College President | Associated Policy Reference No. | IT9004 |
| Procedure Owner | VPAA | Responsible Party | Information Technology Services |
| Approved | June 17, 2025 | Revised |
Purpose
The purpose of this procedure is to ensure that SUNY Broome Community College (the “College”) performs an annual Information Technology (IT) Risk Assessment. The IT Risk Assessment is the process of identifying and assessing security risks at the College to implement measures and manage threats.
The IT Risk Assessment aims to help the Information Technology Services (ITS) department identify, analyze, and evaluate security risks to assets, data, and operations, develop appropriate risk responses, and minimize vulnerabilities that can negatively impact College assets and IT.
Scope
The scope of an IT Risk Assessment covers the connection of the internal network with the Internet, the security of the Data Center, the use of the IT infrastructure by all departments, and the IT security of the entire organization.
Statement of the Procedure
SUNY Broome’s Information Security program is based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, availability, confidentiality, and integrity of information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks.
An IT Risk Assessment is performed annually to assess risk to College operations, assets, and information results from systems operations and associated processing, storage, and transmissions.
The IT Risk Assessment will be written and will include:
- Risks with third-party vendors who collect, process, share, or maintain College data;
- Criteria for the evaluation and categorization of identified security risks, threats, and vulnerabilities that the College faces;
- Criteria for the assessment of the confidentiality, integrity, and availability of the College’s information systems and data, including the adequacy of the existing controls in the context of the identified risk or threats the College faces; and
- Requirements describing how identified risks will be mitigated or accepted based on the IT Risk Assessment and how the Information Security Program will address them.
The Qualified Individual will report in writing to the Board of Trustees annually on the overall status of the Information Security Program, its compliance, and material matters related to it.
Material matters related to the Information Security Program contain such items as:
- Results of the IT Risk Assessment
- Risk Management and control decisions
- Service Provider arrangements
- Results of testing
- Security events or Violations
- Management responses to the above items; and
- Recommendations for changes to the Information Security Program
Related Policies (by number)
IT9004 Information Security Policy
To Whom it Applies (title or department)
This procedure applies to all students, faculty, affiliates, emeriti, and staff of the College (part-time and full-time), as well as all independent contractors, interns, consultants, and other third parties, inclusive of anyone who has access to network or email services. The procedure applies regardless of the user’s physical location (e.g., College offices, hotels, airports, user homes, etc.).
General Guidelines
Definitions
- Affiliate: The Foundation, FSA, and Housing Development Corporation.
- College Technology Resources: All computers, wired and wireless networking equipment, portable electronic devices, interactive white boards, projectors, and other electronic devices used to support the College’s educational mission and operational functions. The term College Technology Resources includes all Information Systems, as defined below.
- Information: Any data that is owned or licensed by the College, or is stored, processed or transmitted on any College Information System.
- Information System: Any electronic system owned or licensed by the College that stores, processes or transmits Information.
- Information Security Program: The procedures and guidelines for implementing this Policy. “Personally Identifiable Information” (PII) is defined as any information relating to an identified or identifiable natural person.
- Security Incident: Any actual or suspected event affecting the confidentiality, integrity or availability of Information or any Information System.
- User: Any individual member of the College Community who interacts with SUNY Broome information systems or College technology resources.
Appendix
Forms for Further Clarification of Procedure
| Action (Created, Reviewed, Retired) | Date | Initials | Position Title |
|---|---|---|---|
| Created | 011/01/2024 | BAM | Chief Information Officer |