KU SEC 10 - Policy Precedence & Governance Policy

KU SEC 10 – Policy Precedence & Governance Summary

WHAT

  • Establishes the official hierarchy for IT, Information Security, and Data Governance documents.
  • Defines how conflicts are resolved and which source prevails.
  • Sets requirements for version control, metadata, repositories, and supersession.
  • Outlines processes for exceptions and waivers.
  • Aligns governance with NIST CSF 2.0 “Govern.”
  • Applies to the entire policy lifecycle.

WHO

  • Applies to employees, faculty, staff, student workers, contractors, and vendors.
  • CISO – Policy owner; handles security conflicts.
  • CIO – Co‑owner; handles operational conflicts.
  • General Counsel, Risk & Compliance, Internal Audit, University Policy Committee.
  • All University policy owners and approvers.

WHEN

  • Applies continuously.
  • Reviewed annually or earlier if laws or risks change.
  • Conflicts resolved within 10 business days.
  • Exceptions last up to 12 months and require renewal.
  • Each update must state what it supersedes.

WHY

  • Ensures a unified structure for all IT and security documentation.
  • Supports compliance with laws, regulations, contracts, and directives.
  • Maintains auditability and document integrity.
  • Reduces risk through structured conflict handling.
  • Provides consistent guidance across the University.

WHERE

  • Scrut.io – Authoritative repository.
  • SharePoint – Published PDFs.
  • FreshService – End‑user summaries and links.
  • Drafts stay only in restricted SharePoint areas.
  • Applies across all IT/security units.

HOW

  • Uses a defined hierarchy (laws → directives → policies → standards → procedures → guidelines).
  • Requires cross‑referencing among documents.
  • Conflict workflow: log → analyze → CISO/CIO → escalate → republish.
  • Exceptions require template, justification, and approvals.
  • Documents must include required metadata.

⭐ Key Takeaways

  • Defines the University’s documentation hierarchy.
  • Requires structured metadata and version controls.
  • Scrut.io is the system of record.
  • Exceptions require high‑level review and approval.

⚠️ Common Misunderstandings

  • “Guidelines are mandatory.” They are not.
  • “Drafts go in Scrut.io.” Only final versions go in Scrut.io.
  • “Standards and procedures are equal.” Standards sit above procedures.
  • “Departments set their own hierarchy.” KU SEC 10 sets this University‑wide.
  • “Exceptions last forever.” They expire after 12 months.

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.