Policy Number: 12-032
Information Security Awareness and Training Policy
Category: Information Technology
Responsible Executive: Senior Vice President and Chief Information Officer
Responsible Office: UFIT Information Security Office
1. Purpose
The purpose of this Information Security Awareness and Training Policy (“Policy”) is to promote a culture of shared responsibility at the University of Florida (“UF”) for safeguarding UF Data, Information Systems and UF Information Technology (“UFIT”) resources by managing human-related risks through ongoing education and training on recognizing and responding to cyber threats.
2. Applicability
This Policy applies to UF, its Direct Support Organizations (“DSOs”), and affiliated legal entities, but does not apply to UF Health, which for purposes of this Policy refers to UF Health clinical enterprises and their affiliated legal entities.
3. Definitions
Information System means an individual or collection of computing and networking equipment and software used to perform a discrete business function, including the collection, processing, maintenance, use, sharing, dissemination, or disposition of university data. Examples include the eLearning Management System, the Student Information System, the EPIC electronic medical records system, a lab system and associated PC, cloud or AI services or applications, or mobile computing/wireless devices.
Senior Leadership means the senior leader of a Unit, such as a dean, vice president, or director reporting directly to the Provost.
UF Activities means activities performed by employees, students and others as part of their UF affiliation, including academic, research, clinical, administrative and operational functions.
UF Data means data in any format collected, developed, maintained, or managed by or on behalf of UF, or within the scope of UF Activities. The terms ‘data’ and ‘information’ are used interchangeably in the context of UF’s information security program.
Unit means any UF entity, such as a department, office, college, or center, that has administrative and financial obligations to comply with UF information security policies.
Workforce Members means all individuals who are employed by or perform work under the direction of UF, its Direct Support Organizations (“DSOs”) or its affiliated legal entities. This includes both faculty and staff, whether full-time, part-time, temporary or contractual.
4. Policy Statement
4.1. Training Requirements
All Workforce Members must complete UF’s Information Security Awareness Training in accordance with the following requirements:
4.1.1. Newly hired Workforce Members must complete training within 30 days of their start date.
4.1.2. Workforce Members must complete refresher training at least once annually thereafter.
4.1.3. Workforce Members with access to UF Data, Information Systems or UFIT resources subject to specialized security requirements or data classification standards must complete role- or system-specific training.
4.1.4. Workforce Members with designated information security roles and responsibilities must complete training specific to those roles and responsibilities.
4.2. Responsibilities
Senior Leadership is responsible for ensuring Workforce Members under their purview complete required training and for addressing instances of noncompliance in accordance with applicable UF policies and procedures.
4.3. Policy Violations
Failure to comply with this Policy may result in corrective or disciplinary action in accordance with applicable UF policies and procedures. UF may restrict, suspend or revoke access to UF Data, Information Systems or UFIT resources for individuals who fail to complete required training.
5. References and Related Information
UF Regulation 1.0102; Policies on Information Technology and Information Security
NIST Special Publication 800-53 revision 5: AT-2, AT-3, AT-4
NIST Cybersecurity Framework v2.0: PR.AT-01, PR.AT-02
History
History: New 8-11-26.