Skip to main content

Contingency Planning Policy

Policy Number:
ISO-900
Effective Date:
May 7, 2019
Last Revised Date:
December 1, 2021
Last Reviewed Date:
October 9, 2026
Responsible Unit(s):
Responsible Unit Email(s):
Status:
Active

Purpose and Summary

This Policy defines the overall contingency objectives of the University of Arizona (University) and establishes the organizational framework and responsibilities for system contingency planning.

Scope

This Policy applies to all University-Related Persons, as well as all Information Systems and Information Resources owned or operated by or on behalf of the University. 

Definitions

Information Owner means the individual(s) or Unit with operational authority for specified University Information and responsibility for establishing the controls for its generation, collection, processing, dissemination, and disposal. Such individual(s) or Unit is responsible for making risk tolerance decisions related to University Information on behalf of the University and is organizationally responsible for any loss associated with a realized information security risk scenario.

Information Resource Owner means the Information Owners and Information System Owners.​

Information Resources means University Information and related resources, such as equipment, devices, software, and other information technology.

Information System means a major application or general support system for storing, processing, or transmitting University Information. An Information System may contain multiple subsystems. Subsystems typically fall under the same management authority as the parent Information System. Additionally, an Information System and its constituent subsystems generally have the same function or mission objective, essentially the same operating characteristics, the same security needs, and reside in the same general operating environment.

Information System Owner means the individual(s) or Unit responsible for the overall procurement, development, integration, modification, and operation and maintenance of an Information System. Such individual(s) or Unit is responsible for making risk tolerance decisions related to Information Systems on behalf of the University and is organizationally responsible for the loss, limited by the bounds of the Information System, associated with a realized information security risk scenario.

Unit means any University college, school, department, program, or other operating Unit.

University Information means any communication or representation of knowledge, such as facts, data, or opinions, recorded in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual, owned or controlled by or on behalf of the University.

University-Related Persons means any University students and applicants for admission, University employees and applicants for employment, Designated Campus Colleagues (DCCs), retirees, alumni, temporary employees of agencies who are assigned to work for the University, and third-party contractors engaged by the University and their agents and employees.

Policy

  1. Restricted University Information and Business Critical Information Systems
    1. All Information Resource Owners must ensure contingency plans are documented for those Information Systems that are business critical or classified as Restricted, as defined in the University Information Resource Classification Standard.
      1. The plans must provide preventive measures, recovery strategies, and technical considerations in the event of a disruption.
    2. Contingency plans must include the following:
      1. procedures for restoring the Information System, including the acquisition and maintenance of resources needed to facilitate the recovery and/or continuity of essential system functions;
      2. processes for acquiring and maintaining the resources necessary to ensure viability of the restoration procedures;
      3. training for personnel to execute contingency procedures;
      4. the assignment of responsibilities to designated staff or positions involved in the execution of the plan; and
      5. readiness and preparedness procedures for the annual review and testing of the plan.
  2. Tracking, Measuring, and Reporting
    1. The Information Security Office must develop, test, review, maintain, and communicate a representation of the University’s information security practices to University leadership. 
    2. The Information Security Office is authorized to track compliance of this Policy and produce reports of compliance measures to support University decision making.
    3. Academic and administrative Unit leaders are responsible for implementing and ensuring compliance with this Policy within their respective areas. 
      1. Upon request, academic and administrative Unit leaders are responsible for providing the Information Security Office with information necessary to assess and report on compliance. 
      2. Specific responsibilities may be delegated to designees; however, overall accountability for University Information Resources, information security risk, and compliance remains with academic and administrative Unit leaders.   
  3. Recourse for Noncompliance
    1. The Information Security Office is authorized to limit network access for individuals or Units not in compliance with all University information security policies and related procedures. 
    2. In cases where University resources are actively threatened, the Chief Information Security Officer must act in the best interest of the University by securing the resources in a manner consistent with the Information Security Incident Response Plan. 
      1. In an urgent situation requiring immediate action, the Chief Information Security Officer is authorized to disconnect affected individuals or Units from the network. 
    3. In cases where University-Related Persons violate this Policy, the University may apply appropriate employee sanctions or administrative actions, in accordance with relevant administrative, academic, and employment policies. 
  4. Exceptions
    1. Any requests for exceptions to any information security policies must be submitted to the Chief Information Security Officer for review and approval pursuant to the Information Security Office Policy Exception Request Procedure. 
  5. Frequency of Policy Review
    1. The Chief Information Security Officer must review information security policies and procedures at least annually. This Policy may be revised based on these reviews.


Policy Feedback

For questions or comments regarding a particular policy or to notify us of broken links or typographical errors, please provide this information below.

To report violations of a policy, please notify the Responsible Unit.

Please Note: Policy feedback is available to the Policy Office, Policy Sponsor, and elected shared governance representatives, upon request, for policies impacting the populations they represent.

This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.