Audit and Accountability Policy
Version 2.0
For Students, Faculty, Staff, Guests, Alumni
Purpose
The purpose of this policy is to ensure consistent auditing of the University’s IT Resources through the generation, collection, protection, review, monitoring, management, and retention of auditable data. Audit records support the detection and investigation of potentially adverse events, accountability for User and system activity, incident response, and compliance with applicable University requirements, laws, regulations, and contracts.
Scope
This IT security policy, and all policies referenced herein, shall apply to all members of the University community, including faculty, students, administrators, staff, alumni, authorized guests, delegates, and independent contractors (the “User(s)” or “you”) who use, access, or otherwise employ, locally or remotely, the University’s IT Resources, whether individually controlled, shared, stand-alone, or networked.
Policy Statement
Information Security and Assurance must approve the methods for generating, collecting, transmitting, aggregating, protecting, reviewing, monitoring, managing, and retaining auditable data (e.g., logs), including system, application, security, administrative, and User activity logs.
- The University’s Office of Information Technology must maintain an approved and documented program to monitor, manage, and review IT Resources and User activities. The program must identify the systems and services subject to logging, the events to be recorded, the responsible personnel, the review and escalation requirements, and the applicable retention periods.
- Hardware, software, and procedural mechanisms must be implemented to generate audit records and support the examination of activity involving IT Resources that store, process, transmit, or provide access to sensitive or University information.
- Audit records must be collected and stored in a manner that permits timely monitoring, review, analysis, reporting, investigation, and retrieval by authorized personnel. Audit record reduction, aggregation, correlation, and report generation must support on-demand review and after-the-fact investigations without altering the original content or time ordering of audit records.
- Audit records must be protected against unauthorized access, disclosure, modification, deletion, destruction, and other forms of tampering. Access to audit records and logging systems must be limited to authorized personnel based on job responsibilities and the principles of least privilege and separation of duties.
- The University must monitor relevant network activity, system and application activity, User and privileged-account activity, technology usage, hardware and software activity, and external service-provider activity to identify potentially adverse events.
- Potentially adverse events identified through audit records must be analyzed and, where appropriate, correlated with information from other relevant sources to determine their nature, scope, and impact, and to determine whether they constitute a cybersecurity incident.
- Designated personnel or roles must be alerted when unauthorized access to, modification of, deletion of, or interference with audit records or logging capabilities is detected or reasonably suspected.
- Suspected cybersecurity incidents identified through audit monitoring must be documented, escalated, and handled in accordance with the University’s Cybersecurity Incident Response Plan and related procedures.
- The University’s Office of Information Technology must maintain approved standards and processes to guide the implementation and management of logs per the Logging Requirements Policy.
- The University’s Office of Information Technology must retain logs that meet University retention requirements per the Records Retention and Disposal Policy. Audit records must also be securely disposed of at the end of the applicable retention period unless a longer retention period is required by legal or regulatory obligations, contractual requirements, litigation holds, investigative needs, or documented University requirements.
- Logging must be consistent with University policies, IT security policies, and applicable laws, regulations, and contracts.
- Logging and monitoring practices must be periodically reviewed and updated based on changes to technology, cybersecurity risk, legal and regulatory requirements, contractual obligations, and lessons learned from incidents, exercises, assessments, and operational activities.
Definitions
IT Resources include computing, networking, communications, applications, and telecommunications systems, infrastructure, hardware, software, data, databases, personnel, procedures, physical facilities, cloud-based vendors, Software as a Service (SaaS) vendors, and related materials and services.
NIST SP 800-53 Rev. 5 Control Alignment
AU-2 - Event Logging
AU-6 - Audit Record Review, Analysis, and Reporting
AU-7 - Audit Record Reduction and Report Generation
AU-9 - Protection of Audit Information
AU-11 - Audit Record Retention
AU-12 - Audit Record Generation
Related Policies and Procedures
Implementation Information
| Review Frequency: | Biennial |
|---|---|
| Responsible Person: | Senior Director of IT Security and Assurance |
| Approved By: | CISO |
| Approval Date: | March 30, 2020 |
Revision History
| Version: | Date: | Description: |
|---|---|---|
| 1.0 | 03/30/2020 | Initial document |
| 1.1 | 04/20/2022 | Update policy statement |
| 1.2 | 04/30/2024 | Updated scope, disclaimer, and policy statement |
| 05/09/2026 | Reviewed no changes | |
| 2.0 | 09/22/2026 | Substantive remediation aligned to NIST SP 800-53 Rev. 5 (AU-2, AU-6, AU-7, AU-9, AU-11, AU-12); clarified audit generation, review/reporting, protection, and retention requirements; updated Logging Requirements Policy reference. |
Policy Disclaimer Statement
Deviations from policies, procedures, or guidelines published and approved by Information Security and Assurance (ISA) will only be considered cooperatively between ISA and the requesting entity, with sufficient notice to allow for conducting appropriate risk analysis, documentation, review, and notification to authorized University representatives where necessary. Failure to adhere to ISA written policies may be met with University sanctions up to and including dismissal.