MIME-Version: 1.0
Content-Location: file:///C:/907C5513/GLBA_Policies_Procedures.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:w=3D"urn:schemas-microsoft-com:office:word"
xmlns:st1=3D"urn:schemas-microsoft-com:office:smarttags"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DWord.Document>
<meta name=3DGenerator content=3D"Microsoft Word 11">
<meta name=3DOriginator content=3D"Microsoft Word 11">
<link rel=3DFile-List href=3D"GLBA_Policies_Procedures_files/filelist.xml">
<title>Gramm-Leach-Bliley Act (GLBA)</title>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"PlaceType"/>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"PlaceName"/>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"place"/>
<!--[if gte mso 9]><xml>
 <o:DocumentProperties>
  <o:Author>Computer User</o:Author>
  <o:Template>Normal</o:Template>
  <o:LastAuthor>17996398</o:LastAuthor>
  <o:Revision>2</o:Revision>
  <o:TotalTime>6</o:TotalTime>
  <o:LastPrinted>2006-10-19T14:13:00Z</o:LastPrinted>
  <o:Created>2006-10-25T18:30:00Z</o:Created>
  <o:LastSaved>2006-10-25T18:30:00Z</o:LastSaved>
  <o:Pages>1</o:Pages>
  <o:Words>1516</o:Words>
  <o:Characters>8642</o:Characters>
  <o:Company>SMU</o:Company>
  <o:Lines>72</o:Lines>
  <o:Paragraphs>20</o:Paragraphs>
  <o:CharactersWithSpaces>10138</o:CharactersWithSpaces>
  <o:Version>11.8107</o:Version>
 </o:DocumentProperties>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:SpellingState>Clean</w:SpellingState>
  <w:GrammarState>Clean</w:GrammarState>
  <w:ValidateAgainstSchemas/>
  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
  <w:IgnoreMixedContent>false</w:IgnoreMixedContent>
  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
  <w:Compatibility>
   <w:SelectEntireFieldWithStartOrEnd/>
   <w:UseWord2002TableStyleRules/>
  </w:Compatibility>
  <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel>
 </w:WordDocument>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:LatentStyles DefLockedState=3D"false" LatentStyleCount=3D"156">
 </w:LatentStyles>
</xml><![endif]--><!--[if !mso]><object
 classid=3D"clsid:38481807-CA0E-42D2-BF39-B33AF135CC4D" id=3Dieooui></objec=
t>
<style>
st1\:*{behavior:url(#ieooui) }
</style>
<![endif]-->
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;
	mso-font-charset:2;
	mso-generic-font-family:auto;
	mso-font-pitch:variable;
	mso-font-signature:0 268435456 0 0 -2147483648 0;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:1627421319 -2147483648 8 0 66047 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-parent:"";
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-noshow:yes;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:8.0pt;
	font-family:Tahoma;
	mso-fareast-font-family:"Times New Roman";}
span.SpellE
	{mso-style-name:"";
	mso-spl-e:yes;}
span.GramE
	{mso-style-name:"";
	mso-gram-e:yes;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
 /* List Definitions */
 @list l0
	{mso-list-id:575210987;
	mso-list-type:hybrid;
	mso-list-template-ids:-837363938 184715710 67698691 67698693 67698689 6769=
8691 67698693 67698689 67698691 67698693;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.75in;
	mso-level-number-position:left;
	margin-left:.75in;
	text-indent:-.25in;
	font-family:Symbol;
	mso-fareast-font-family:"Times New Roman";
	mso-bidi-font-family:"Times New Roman";}
@list l0:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.25in;
	mso-level-number-position:left;
	margin-left:1.25in;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l1
	{mso-list-id:1072853315;
	mso-list-type:hybrid;
	mso-list-template-ids:60698538 1419150252 67698691 67698693 67698689 67698=
691 67698693 67698689 67698691 67698693;}
@list l1:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.75in;
	mso-level-number-position:left;
	margin-left:.75in;
	text-indent:-.25in;
	font-family:Symbol;
	mso-fareast-font-family:"Times New Roman";
	mso-bidi-font-family:"Times New Roman";}
@list l2
	{mso-list-id:1660226462;
	mso-list-type:hybrid;
	mso-list-template-ids:-1693050288 -1313317556 67698713 67698715 67698703 6=
7698713 67698715 67698703 67698713 67698715;}
@list l2:level1
	{mso-level-tab-stop:.75in;
	mso-level-number-position:left;
	margin-left:.75in;
	text-indent:-.25in;}
@list l3
	{mso-list-id:1882862699;
	mso-list-type:hybrid;
	mso-list-template-ids:-1648569050 -1051974822 67698713 67698715 67698703 6=
7698713 67698715 67698703 67698713 67698715;}
@list l3:level1
	{mso-level-tab-stop:.75in;
	mso-level-number-position:left;
	margin-left:.75in;
	text-indent:-.25in;}
@list l4
	{mso-list-id:1919635640;
	mso-list-type:hybrid;
	mso-list-template-ids:1200377484 -406282082 67698713 67698715 67698703 676=
98713 67698715 67698703 67698713 67698715;}
@list l4:level1
	{mso-level-tab-stop:.75in;
	mso-level-number-position:left;
	margin-left:.75in;
	text-indent:-.25in;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
-->
</style>
<!--[if gte mso 10]>
<style>
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
</style>
<![endif]-->
</head>

<body lang=3DEN-US style=3D'tab-interval:.5in'>

<div class=3DSection1>

<p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><b style=3D=
'mso-bidi-font-weight:
normal'><span style=3D'font-size:14.0pt;mso-bidi-font-size:12.0pt'>Southern=
 <st1:place
w:st=3D"on"><st1:PlaceName w:st=3D"on">Methodist</st1:PlaceName> <st1:Place=
Type
 w:st=3D"on">University</st1:PlaceType></st1:place><o:p></o:p></span></b></=
p>

<p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><b style=3D=
'mso-bidi-font-weight:
normal'><span style=3D'font-size:14.0pt;mso-bidi-font-size:12.0pt'><o:p>&nb=
sp;</o:p></span></b></p>

<p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><b style=3D=
'mso-bidi-font-weight:
normal'><span style=3D'font-size:14.0pt;mso-bidi-font-size:12.0pt'>Policy a=
nd
Procedure for the Protection of Non-Public Personal Information and for
Compliance with the <span class=3DSpellE>Gramm</span>-Leach-Bliley Act (GLB=
A)<o:p></o:p></span></b></p>

<p class=3DMsoNormal><b style=3D'mso-bidi-font-weight:normal'><span
style=3D'font-size:14.0pt;mso-bidi-font-size:12.0pt'><o:p>&nbsp;</o:p></spa=
n></b></p>

<p class=3DMsoNormal><b style=3D'mso-bidi-font-weight:normal'><span
style=3D'font-size:14.0pt;mso-bidi-font-size:12.0pt'><o:p>&nbsp;</o:p></spa=
n></b></p>

<p class=3DMsoNormal><u>BACKGROUND<o:p></o:p></u></p>

<p class=3DMsoNormal><u><o:p><span style=3D'text-decoration:none'>&nbsp;</s=
pan></o:p></u></p>

<p class=3DMsoNormal>GLBA is another name for the Financial Services
Modernization Act of 1999 which regulates the disclosure of non-public pers=
onal
information by financial institutions. SMU is considered to be a financial
institution because we participate in financial activities, such as the Fed=
eral
Perkins Loan Program. Therefore we must ensure the security and confidentia=
lity
of customer personal information. The University&#8217;s focus is to protect
all private data rather than to identify which particular law applies (GLBA,
HIPAA, FERPA), in any given situation. Our emphasis applies to any record c=
ontaining
nonpublic information about students, faculty, staff or other third parties=
 who
have a relationship with the University, whether it is in paper, electronic=
 or
other form that is <span class=3DGramE>collected,</span> handled or maintai=
ned by
or on behalf of the University. </p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal>The Federal Trade Commission implemented GLBA by issui=
ng two
rules: The Privacy Rule and the Safeguards Rule. Colleges and universities =
are
deemed in compliance with the Privacy Rule if they already comply with the
FERPA. The Safeguards Rule has five required components:</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l4 level1 lfo1;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
1.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Designate
a Security Program Coordinator responsible for coordinating the program.</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l4 level1 lfo1;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
2.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Conduct
a risk assessment to identify reasonably foreseeable security and privacy r=
isks
(which we have completed).</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l4 level1 lfo1;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
3.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Ensure
that safeguards are employed to control the identified risks; regularly tes=
t and
monitor the effectiveness of these safeguards.</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l4 level1 lfo1;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
4.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Oversee
service providers, including selection of appropriate service providers and=
 use
of contract language to protect customer information handled by service pro=
viders.</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l4 level1 lfo1;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
5.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Evaluate
and adjust the program in light of relevant circumstances and changes in the
business. </p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal>The SMU Program to comply with GLBA applies to any rec=
ord
containing nonpublic information about students, faculty, staff or other th=
ird
parties who have a relationship with the University, whether it is in paper,
electronic or other form that is <span class=3DGramE>collected,</span> hand=
led or
maintained by or on behalf of the University. For these purposes, nonpublic
information includes, but is not limited to, information pertaining to a
student or other third party:</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l3 level1 lfo2;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
1.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Provided
in order to obtain a financial service for the University</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l3 level1 lfo2;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
2.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Resulting
from any transaction involving a financial service provided by the Universi=
ty</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l3 level1 lfo2;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
3.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Resulting
from providing a financial service to a student, faculty, staff or other th=
ird
party</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal>For purposes of this program, covered data and nonpubl=
ic
information includes, but is not limited to, bank and credit card informati=
on,
income and credit histories and tax information, in both paper and electron=
ic
format, received directly or indirectly in the course of business by SMU. In
addition to nonpublic financial information, data such as names, addresses,
phone numbers, credit card numbers, social security numbers and credit
histories are covered under GLBA. </p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal>Customer information is any record containing nonpublic
personal information about a customer obtained in connection with offering a
&#8220;financial product or service&#8221;. This includes paper, electronic=
 or
other form that is handled or maintained by or on behalf of the financial
institutions or its affiliates. Examples include: </p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l2 level1 lfo3;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
1.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Social
Security Numbers</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l2 level1 lfo3;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
2.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Bank
Account Numbers </p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l2 level1 lfo3;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
3.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Credit
Card Account numbers</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l2 level1 lfo3;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
4.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Date
and/or location of birth</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l2 level1 lfo3;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
5.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Account
balances; payment histories; credit ratings, income histories</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l2 level1 lfo3;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
6.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Drivers
License Information</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l2 level1 lfo3;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
7.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>ACH
(Automated Clearing House) numbers</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l2 level1 lfo3;
tab-stops:list .75in'><![if !supportLists]><span style=3D'mso-list:Ignore'>=
8.<span
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></sp=
an><![endif]>Tax
Return Information</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal><u>REQUIRED ACTIONS<o:p></o:p></u></p>

<p class=3DMsoNormal><u><o:p><span style=3D'text-decoration:none'>&nbsp;</s=
pan></o:p></u></p>

<p class=3DMsoNormal>All University departments are responsible for identif=
ying
reasonably foreseeable internal and external risks to the security,
confidentiality, and integrity of consumer nonpublic information; evaluating
the effectiveness of the current safeguards for controlling these risks; de=
signing
and implementing a safeguards program; and regularly monitoring and testing=
 the
program. In order to protect the security and integrity of the University
network and its data, registry of all computers attached to the University
network will be developed and maintained. The University operates under a
distributed technology support model. Information Technology Services (ITS)
will work with the appropriate areas of the University to ensure proper
registry records are maintained for those systems under the direct
responsibility of those areas. </p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal>Relevant SMU policies that already exist include:</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>1.12 <span style=3D'mso-tab-count:1'>&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Policy
on Privacy of Health Information</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>1.18 <span style=3D'mso-tab-count:1'>&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Family
Educational Rights and Privacy Act (&#8220;FERPA&#8221;) Policy</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>12.3 <span style=3D'mso-tab-count:1'>&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Computing
and Communications Policy</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>12.4 <span style=3D'mso-tab-count:1'>&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Electronic
Payment Processing</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>12.5 <span style=3D'mso-tab-count:1'>&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Information
Security</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>12.6<span style=3D'mso-tab-count:1'>&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Password
Management</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>13.8 <span style=3D'mso-tab-count:1'>&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Policy
for Service of Subpoenas and Responding to Subpoenas or <span style=3D'mso-=
tab-count:
1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></p>

<p class=3DMsoNormal style=3D'margin-left:1.5in'>Other Requests for Records=
 of
Current or Former Students and Employees</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal><u>SAFEGUARDS<o:p></o:p></u></p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal>There are three types of safeguards that must be consi=
dered
and that departments must assume responsibility that adequate safeguards ar=
e in
place within their areas of responsibility:</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Administrative</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Physical </p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Technical </p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal><u>Administrative Safeguards<o:p></o:p></u></p>

<p class=3DMsoNormal><u><o:p><span style=3D'text-decoration:none'>&nbsp;</s=
pan></o:p></u></p>

<p class=3DMsoNormal>These are generally within the direct control of a dep=
artment
and include:</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Checking references on potential employees</=
p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Training employees on basic steps as they mu=
st
take to protect customer information</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Ensuring that employees are knowledgeable ab=
out
applicable policies and expectations</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Limiting access to customer information to
employees who have a business need</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Reducing exposure to the GLBA by requesting
customer information only when it is required to conduct departmental activ=
ities
</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Imposing disciplinary measures where appropr=
iate</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal><u>Physical Safeguards<o:p></o:p></u></p>

<p class=3DMsoNormal><u><o:p><span style=3D'text-decoration:none'>&nbsp;</s=
pan></o:p></u></p>

<p class=3DMsoNormal>These are generally within a department&#8217;s contro=
l and
include:</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Locking rooms and file cabinets where custom=
er
information is kept</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Using password activated screensavers</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Using strong passwords</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Changing passwords periodically and not shar=
ing
or writing them down</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Encrypting sensitive customer information
transmitted electronically</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Referring calls or requests for customer
information to staff trained to respond to such requests</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Being alert to fraudulent attempts to obtain
customer information and reporting these to management for referral to
appropriate law enforcement agencies</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Ensuring that storage areas are protected
against destruction or potential damage from physical hazards, such as fire=
 or
floods</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Storing records in a secure area and limiting
access to authorized employees</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Disposing of customer information appropriat=
ely:</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in;text-indent:-.25in;mso-lis=
t:l0 level2 lfo5;
tab-stops:list 1.25in'><![if !supportLists]><span style=3D'font-family:"Cou=
rier New";
mso-fareast-font-family:"Courier New"'><span style=3D'mso-list:Ignore'>o<sp=
an
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </spa=
n></span></span><![endif]>Designate
a trained staff member to supervise the disposal of records containing cust=
omer
personal information</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in;text-indent:-.25in;mso-lis=
t:l0 level2 lfo5;
tab-stops:list 1.25in'><![if !supportLists]><span style=3D'font-family:"Cou=
rier New";
mso-fareast-font-family:"Courier New"'><span style=3D'mso-list:Ignore'>o<sp=
an
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </spa=
n></span></span><![endif]>Shred
or recycle customer information recorded on paper and store it in a secure =
area
until the recycling service picks it up</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in;text-indent:-.25in;mso-lis=
t:l0 level2 lfo5;
tab-stops:list 1.25in'><![if !supportLists]><span style=3D'font-family:"Cou=
rier New";
mso-fareast-font-family:"Courier New"'><span style=3D'mso-list:Ignore'>o<sp=
an
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </spa=
n></span></span><![endif]>Erase
all data when disposing of computers, diskettes, magnetic tapes, hard drive=
s or
any other electronic media that contains customer information </p>

<p class=3DMsoNormal style=3D'margin-left:1.25in;text-indent:-.25in;mso-lis=
t:l0 level2 lfo5;
tab-stops:list 1.25in'><![if !supportLists]><span style=3D'font-family:"Cou=
rier New";
mso-fareast-font-family:"Courier New"'><span style=3D'mso-list:Ignore'>o<sp=
an
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </spa=
n></span></span><![endif]>Promptly
dispose of outdated customer information within record retention policies</=
p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal><u>Technical Safeguards<o:p></o:p></u></p>

<p class=3DMsoNormal><u><o:p><span style=3D'text-decoration:none'>&nbsp;</s=
pan></o:p></u></p>

<p class=3DMsoNormal>This is generally the responsibility of central IT per=
sonnel
or departmental computing staff. Departments, however, should be knowledgea=
ble
about how their electronic customer information is safeguarded. If addition=
al
controls are warranted, departments should work with IT to improve safeguar=
ds.
Departments are also responsible for alerting IT to the existence of custom=
er
information networks. Examples of technical safeguards include: </p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Storing electronic customer information on a
secure server that is accessible only with a password, or has other security
protections, and is kept in a physically secure area. </p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Avoiding storage of customer information on
machines with an Internet connection</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Maintaining secure backup media and securing
archived data</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Using anti-virus software that updates
automatically</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Obtaining and installing patches that resolve
software vulnerabilities</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Following written contingency plans to addre=
ss
breaches of safeguards</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Maintaining up-to-date firewalls particularl=
y if
the institution uses broadband Internet access or allows staff to connect to
the network from home</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Providing central management of security too=
ls
and keeping employees informed of security risks breaches</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>If credit card information or other sensitive
financial data is collected, use a secure connection so that the informatio=
n is
encrypted in transit.</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>If information is collected directly from
consumers, make secure transmission automatic. Caution consumers against
transmitting sensitive data, like account numbers, via electronic mail.</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>If you must transmit sensitive data by
electronic mail, encryption is necessary.</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal>Effective security management includes the prevention,
detection and response to attacks, intrusions and other system failures,
including steps mentioned above and the following:</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Backing up data regularly and storing back-up
information offsite</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Imaging documents</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Shredding paper copies after imaging</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Other reasonable measure to protect the
integrity and safety of information systems</p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal><u>SUMMARIZATION OF DEPARTMENT AND SCHOOL RESPONSIBILI=
TIES<o:p></o:p></u></p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal>The responsibilities of all departments and schools ar=
e the
following: </p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Designate a key contact to work with the
Security Program Coordinator on all GLBA matters</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Ensure that the key contact carries out peri=
odic
risk assessments and monitors the identified risks</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Adhere to policies, standards and guidelines=
 for
the safeguarding of private data, and ensure the employees with access to
covered data do the same</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Ensure that new employees are made aware of =
the
GLBA and its safeguarding requirements</p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Ensure that companies that have access to
University customers&#8217; nonpublic personal information on behalf of the
University <span class=3DGramE>comply</span> wit <span class=3DSpellE>hthe<=
/span>
privacy and safeguards requirements of GLBA. </p>

<p class=3DMsoNormal style=3D'margin-left:.75in;text-indent:-.25in;mso-list=
:l0 level1 lfo5;
tab-stops:list .75in'><![if !supportLists]><span style=3D'font-family:Symbo=
l;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol'><span
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New Roma=
n"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Review with the Budgets and Information
Technology Services department changes to or any new software, networks or
electronic service providers that include access or processing nonpublic
personal information protected by GLBA to ensure that the technology in pla=
ce
includes appropriate safeguards.</p>

<p class=3DMsoNormal><u><o:p><span style=3D'text-decoration:none'>&nbsp;</s=
pan></o:p></u></p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

</body>

</html>
