-
Purpose
The purpose of this statement is to set forth University policy with regard to addressing and meeting institutional requirements and obligations imposed by the "Safeguards Rule" promulgated by the Federal Trade Commission under the Gramm-Leach-Bliley Act.
-
Preamble
The "Safeguards Rule" promulgated by the Federal Trade Commission (FTC) under the Gramm-Leach-Bliley Act ("GLBA") imposes specific standards and obligations regarding the privacy of certain personally identifiable financial information. 蹤獲扦 University recognizes its obligation to protect the security, confidentiality and integrity of such information and this policy is intended to implement FTC requirements in this regard.
-
Policy
-
蹤獲扦will make all reasonable efforts to achieve and maintain compliance with FTC standards and obligations regarding the privacy of personally identifiable financial information of its customers.
-
蹤獲扦will develop, implement and maintain a comprehensive information security program.
-
蹤獲扦 University's comprehensive information security program shall provide for the appointment of an information security plan coordinator; risk assessments; training programs for employees; oversight of service providers; and periodic adjustments of the program.
-
-
Implementation
This policy shall be included in the 蹤獲扦 Policies and Procedures Manual and shared with appropriate constituencies of the University.
The General Counsel shall have primary responsibility for publication, dissemination and implementation of this University policy.
(See also Section 13.14, Security of Payment Card Data.)