The Official Web site for the Office of Information Technology - UTSA

This document should be rendered in an HTML format with cascading style sheets and JavaScript turned on.

Office of Information Technology Home Page

Skip to Main Content

Skip to Navigation

Please take a few minutes to read our Accessibility Page which will make your visit through this Web site easier.

Copyright (c) 2010. The University of Texas at San Antonio. All rights reserved.

OIT Home > About OIT > Information Resource Standards > Information Security Administrator (ISA)

Information Security Administrator (ISA)

The program for Information Security Administrators is designed to complement the information security program and to augment the protection of data and computing resources by identifying, training and assisting qualified representatives in the departments of the University.  The responsibilities of the ISA’s are established in UTS 165, UT System Information Resources Use and Security, p. 13:  http://www.utsystem.edu/bor/procedures/policy/policies/uts165.pdf.

The ISA must be appointed by the department head or the principal investigator of a grant.  If needed, an Information Technology Associate may function as the ISA for a department, as long as that person is qualified. Small departments may share the services of one ISA, if approved by the Information Security Officer.

ISA’s must be properly trained for their function. These individuals perform critical security tasks, which if not performed correctly can lead to costly information security breaches.  A department unable to provide or obtain appropriate technical training for the ISA, should not host departmental information systems and data.  Those functions should be moved to the institution’s central IT organization or be outsourced to an organization capable of providing professional services in a secure environment.

Effective Date:

February 1, 2011

Compliance Date:

September 1, 2011

Last Revision:

January 26, 2011

Account Management

Disposal of Computers
Other Electronic Devices

Laptop Encryption

Policy Exception and Risk Assumption Procedures

Administrative/Special Access

E-Mail Management

Log-in Disclaimer

Security Monitoring

Application Registration

Incident Management

Network Access

Security Training

Enterprise Backup &
Data Recovery

Information Resource Use and Security (pending)

Network Configuration

Server Hardening

Change Management

Information Security Risk Assessment

Password

Software Licensing

Computer Naming Convention

Information Security Administrator (ISA)

Patch Management Standard

Threat Detection and Prevention

Configuration and Asset Management

Information Security Training Standard

Personal Computing

Unauthorized File Sharing

Copiers and Printers

Information Services Privacy

Physical Access

Vendor Access

Data Center

Internet Use

Portable Computing

Web Application Vulnerability Scanning

Data Classification

Intrusion Detection

Protection Against Malicious Software

Wireless Network

 

 

 

Workstation Operating Systems Support