ITS and UVa logos for printed output

Information Technology Security

Risk Management (ITS-RM) Program

The University’s Information Technology Security Risk Management (ITS-RM) Program is intended to provide departments with the information and tools they need to manage properly the security risks associated with their information technology assets.

Some examples of real events that have happened at the University include:

Fire. The University’s Treasurer’s Office is left with burned files and melted computers.

Flood. Health System Computing Services responds to a report of a down server and finds water rushing from the ceiling.

Loss of access. University Hall is closed for several months on 15-minutes’ notice after failing a routine structural safety inspection.

Cyber-attack. Machines containing sensitive data are hijacked via the network.

How prepared is your department to mitigate these risks and respond appropriately, if any one of these events occur in your area?

Given the serious security risks to information technology (IT) assets, managing those risks effectively is an essential task for the University and its departments. The process will benefit both the individual departments and the University as a whole. It is important that management understand what risks exist in their IT environment, and how those risks can be reduced or eliminated.

The University has business processes, research and instructional efforts, and legally protected data that depend on IT assets, which UVa cannot afford to lose or have exposed. Unfortunately, these IT assets are subject to an increasing number of threats, attacks and vulnerabilities, against which more protection is continually required. The ITS-RM program is an essential component in this overall effort.

University policy requires the management of each University department to complete the process outlined in the University's ITS-RM Program at least once every three years, when there are significant changes to departmental IT assets, or when there are significant changes to the risk environment. The department head will sign off on the deliverables from this process and file these deliverables in the University's central repository for these documents. The ITS-RM program applies to agencies 207 (Academic Division), 209 (Medical Center) and 246 (College at Wise).

All departments should have completed their first iteration of the process during 2007. The second iteration is due March 1, 2011.

Information, Templates and Tools

  • University of Virginia Information Technology Security Risk Management Program v. 3.0 packet (August 3, 2010)
    • Full packet: Microsoft Word format | PDF format
    • Templates required to complete your department’s ITS-RM report (these are spread throughout the full packet intermixed with background and instructions, but are collected in a compact reporting format here): Microsoft Word format | PDF format
  • PowerPoint presentation given at a 2004 LSP conference explaining the initial version of the program. Useful background and explanation of expectations for anyone working on this ITS-RM program.
  • PowerPoint presentation given at a 2005 Mid-Atlantic EDUCAUSE meeting on the process involved in creating and implementing a IT security risk management program.

For further information, please contact us at its-rm@virginia.edu.

  Page Updated: Thursday 2012-02-16 16:58:19 EST

Standards & Policy

University of Virginia
Information Technology Services
2015 Ivy Road
P.O. Box 400324
Charlottesville, Virginia, 22904-4324 USA

UVa Help Desk: 434-924-HELP (434-924-4357) • 4help@virginia.edu

Page Updated: 2012-02-16; © 2012 by the Rector and Visitors of the University of Virginia.

The information contained on the University of Virginia’s Department of Information Technology Services (ITS) website is provided as a public service with the understanding that ITS makes no representations or warranties, either expressed or implied, concerning the accuracy, completeness, reliability or suitability of the information, including warrantees of title, non-infringement of copyright or patent rights of others. These pages are expected to represent the University of Virginia community and the State of Virginia in a professional manner in accordance with the University of Virginia’s Computing Policies.