Policy Alerts

This page lists any significant updates that have been made to UVA information technology policies, standards, or procedures.  By clicking the button below, you can sign-up to receive an emaill notice whenever a new policy alert is created.  Unless otherwise noted below, all changes are effective immediately.

We encourage you to review and familiarize yourself with these changes and encourage you to seek assistance from technology experts (i.e. Local Support Partners) in your areas or the UVA Help Desk by emailing [email protected] or calling 434-924-4357. Background and additional information about these updated policies, standards, and procedures (PSPs) is on our Information Technology Policies, Standards, & Procedures webpage.  For questions or concerns, please speak with your Local Support Partner (LSP) or email us at [email protected].  

Subscribe or manage policy alerts email

Latest IT Policy changes and updates at the University of Virginia:

Last updated: 12/15/2022 - 9:46am

Effective: September 21, 2022 the Accounts Provisioning and Deprovisioning standard webpage had non-substantive changes to remove references to ESharp and instead point users to the replacement information on the ITS website.  

 

Last updated: 09/12/2022 - 12:58pm

Effective: September 12, 2022 

On September 12, 2022, the Electronically Stored Information Release procedure webpage had non-substantive changes to the contact email and phone number for the Vice-President of Student Affairs office.  Also, the reference to the UVA Policy on Sexual and Gender-Based Harassment and Other Forms of Interpersonal Violence was dropped. 

Last updated: 08/15/2022 - 10:41am

Effective: June 1, 2022 

On June 1, 2022 the Information Security Risk Mangement standard was updated to remove the requirement for a department head to sign-off on the final departmental ISRM report.

Also revised to remove the use of email to contact departments as well as a survey to complete the Information Security Risk Management assessment.  A tool, OneTrust, is used to complete the ISRM assessment. The phrase "information security" replaced where IT or Information Technology was used to refer to the information security risk assessment.

Please review the details of this standard as well as the procedure with which it is associated.

Last updated: 08/15/2022 - 10:37am

Effective: June 1,  2022 

On June 1, 2022 the Security of Network-Connected Devices standard had a non-substantive change that aligned the names and numbers of the severity of a security vulnerability to the names and numbers that Qualys, the vulnerability management software, uses in the additional requirements section of the standard.

Last updated: 08/15/2022 - 10:37am

Effective: June 1, 2022 

On June 1, 2022 the Policy, Standards, and Procedures Exceptions Process webpage had non-substantive changes to identify the appropriate name of the reviewing group and drop the parenthetical comment about the Highly sensitive data (HSD) request form that the Exception process replaces. 

Last updated: 08/15/2022 - 7:45am

Effective: May 6, 2022 

The Information Security Risk Mangement procedure was updated to include the procedures and directions used to complete the Information Security Risk Management assessment in OneTrust for 2022.

In addition, the word "survey" was replaced with "tool" and "information security"  replaced where IT or Information Technology was used to refer to the information security risk assessment.

Please review the details of this procedure as well as the standard with which it is associated.

Last updated: 04/20/2022 - 12:26pm

Effective: April 1, 2022 

The vulnerability scanning requirement for all network connected managed devices to be scanned has been rescinded for another six months while Information Security works to release the new solution that offers this service as required in the standard. 

Please review the details of the exception and its compensating controls as well as the standards to which this exception applies.

Last updated: 03/14/2022 - 11:18am

Effective: March 14, 2022

The Authentication standard, has been amended to make clear that all administrators or those who create accounts of any kind must follow the standard.  Also added is a statement to require the use of  UVA approved single-sign-on (SSO) applications (e.g., Netbadge) if you're accepting UVA or UVA Health passwords.  As well as slight changes for clarity to the two tables and clear statement that the HSVPN is required for user access to HSD in the Academic Division.  Please review these changes to the standard for the details.

This change approved by the VP-CIO, Virginia Evans, on January 5, 2022

Last updated: 01/26/2022 - 11:30am

Effective: January 26, 2022

The standard, Vendor Security Review, has been amended to make clear that if a vendor will process, process, store, or transmit credit card information (aka PCI data or cardholder data (CHD)) the review of this vendor is completed by the University Payment Card Services office.  Please review this change to the standard for the details.

This change approved by the VP-CIO, Virginia Evans, on January 21, 2022

Last updated: 08/03/2021 - 12:48pm

Effective: August 3, 2021

A new standard, Responsible Disclosure was reviewed by the Information Technology Services (ITS) directors, the Security Advisory Committee, and the Information Security leadership team and approved by the VP-CIO, Virginia Evans, on March 8, 2021. 

Please review the details of this new standard.