Audit and Accountability Policy

Version 2.0

For Students, Faculty, Staff, Guests, Alumni

Purpose

The purpose of this policy is to ensure consistent auditing of the University’s IT Resources through the generation, collection, protection, review, monitoring, management, and retention of auditable data. Audit records support the detection and investigation of potentially adverse events, accountability for User and system activity, incident response, and compliance with applicable University requirements, laws, regulations, and contracts. 

Scope

This IT security policy, and all policies referenced herein, shall apply to all members of the University community, including faculty, students, administrators, staff, alumni, authorized guests, delegates, and independent contractors (the “User(s)” or “you”) who use, access, or otherwise employ, locally or remotely, the University’s IT Resources, whether individually controlled, shared, stand-alone, or networked. 

Policy Statement

Information Security and Assurance must approve the methods for generating, collecting, transmitting, aggregating, protecting, reviewing, monitoring, managing, and retaining auditable data (e.g., logs), including system, application, security, administrative, and User activity logs.

  • The University’s Office of Information Technology must maintain an approved and documented program to monitor, manage, and review IT Resources and User activities. The program must identify the systems and services subject to logging, the events to be recorded, the responsible personnel, the review and escalation requirements, and the applicable retention periods. 
  • Hardware, software, and procedural mechanisms must be implemented to generate audit records and support the examination of activity involving IT Resources that store, process, transmit, or provide access to sensitive or University information. 
  • Audit records must be collected and stored in a manner that permits timely monitoring, review, analysis, reporting, investigation, and retrieval by authorized personnel. Audit record reduction, aggregation, correlation, and report generation must support on-demand review and after-the-fact investigations without altering the original content or time ordering of audit records. 
  • Audit records must be protected against unauthorized access, disclosure, modification, deletion, destruction, and other forms of tampering. Access to audit records and logging systems must be limited to authorized personnel based on job responsibilities and the principles of least privilege and separation of duties. 
  • The University must monitor relevant network activity, system and application activity, User and privileged-account activity, technology usage, hardware and software activity, and external service-provider activity to identify potentially adverse events. 
  • Potentially adverse events identified through audit records must be analyzed and, where appropriate, correlated with information from other relevant sources to determine their nature, scope, and impact, and to determine whether they constitute a cybersecurity incident. 
  • Designated personnel or roles must be alerted when unauthorized access to, modification of, deletion of, or interference with audit records or logging capabilities is detected or reasonably suspected. 
  • Suspected cybersecurity incidents identified through audit monitoring must be documented, escalated, and handled in accordance with the University’s Cybersecurity Incident Response Plan and related procedures. 
  • The University’s Office of Information Technology must maintain approved standards and processes to guide the implementation and management of logs per the Logging Requirements Policy.  
  • The University’s Office of Information Technology must retain logs that meet University retention requirements per the Records Retention and Disposal Policy. Audit records must also be securely disposed of at the end of the applicable retention period unless a longer retention period is required by legal or regulatory obligations, contractual requirements, litigation holds, investigative needs, or documented University requirements. 
  • Logging must be consistent with University policies, IT security policies, and applicable laws, regulations, and contracts. 
  • Logging and monitoring practices must be periodically reviewed and updated based on changes to technology, cybersecurity risk, legal and regulatory requirements, contractual obligations, and lessons learned from incidents, exercises, assessments, and operational activities. 

Definitions

IT Resources include computing, networking, communications, applications, and telecommunications systems, infrastructure, hardware, software, data, databases, personnel, procedures, physical facilities, cloud-based vendors, Software as a Service (SaaS) vendors, and related materials and services. 

NIST SP 800-53 Rev. 5 Control Alignment

AU-2 - Event Logging 

AU-6 - Audit Record Review, Analysis, and Reporting 

AU-7 - Audit Record Reduction and Report Generation 

AU-9 - Protection of Audit Information 

AU-11 - Audit Record Retention 

AU-12 - Audit Record Generation 

Related Policies and Procedures

Implementation Information

Review Frequency: Biennial
Responsible Person: Senior Director of IT Security and Assurance
Approved By: CISO
Approval Date: March 30, 2020

Revision History

Version: Date: Description:
1.0 03/30/2020 Initial document
1.1 04/20/2022 Update policy statement
1.2 04/30/2024 Updated scope, disclaimer, and policy statement
  05/09/2026  Reviewed no changes
2.0 09/22/2026  Substantive remediation aligned to NIST SP 800-53 Rev. 5 (AU-2, AU-6, AU-7, AU-9, AU-11, AU-12); clarified audit generation, review/reporting, protection, and retention requirements; updated Logging Requirements Policy reference.  

Policy Disclaimer Statement

Deviations from policies, procedures, or guidelines published and approved by Information Security and Assurance (ISA) will only be considered cooperatively between ISA and the requesting entity, with sufficient notice to allow for conducting appropriate risk analysis, documentation, review, and notification to authorized University representatives where necessary. Failure to adhere to ISA written policies may be met with University sanctions up to and including dismissal.

Need Help?


Walk-In Centers

McShane Center 266 | RH
Leon Lowenstein SL18 | LC

View Our Walk-In Hours