KU SEC 10 – Policy Precedence & Governance Summary
WHAT
- Establishes the official hierarchy for IT, Information Security, and Data Governance documents.
- Defines how conflicts are resolved and which source prevails.
- Sets requirements for version control, metadata, repositories, and supersession.
- Outlines processes for exceptions and waivers.
- Aligns governance with NIST CSF 2.0 “Govern.”
- Applies to the entire policy lifecycle.
WHO
- Applies to employees, faculty, staff, student workers, contractors, and vendors.
- CISO – Policy owner; handles security conflicts.
- CIO – Co‑owner; handles operational conflicts.
- General Counsel, Risk & Compliance, Internal Audit, University Policy Committee.
- All University policy owners and approvers.
WHEN
- Applies continuously.
- Reviewed annually or earlier if laws or risks change.
- Conflicts resolved within 10 business days.
- Exceptions last up to 12 months and require renewal.
- Each update must state what it supersedes.
WHY
- Ensures a unified structure for all IT and security documentation.
- Supports compliance with laws, regulations, contracts, and directives.
- Maintains auditability and document integrity.
- Reduces risk through structured conflict handling.
- Provides consistent guidance across the University.
WHERE
- Scrut.io – Authoritative repository.
- SharePoint – Published PDFs.
- FreshService – End‑user summaries and links.
- Drafts stay only in restricted SharePoint areas.
- Applies across all IT/security units.
HOW
- Uses a defined hierarchy (laws → directives → policies → standards → procedures → guidelines).
- Requires cross‑referencing among documents.
- Conflict workflow: log → analyze → CISO/CIO → escalate → republish.
- Exceptions require template, justification, and approvals.
- Documents must include required metadata.
⭐ Key Takeaways
- Defines the University’s documentation hierarchy.
- Requires structured metadata and version controls.
- Scrut.io is the system of record.
- Exceptions require high‑level review and approval.
⚠️ Common Misunderstandings
- “Guidelines are mandatory.” They are not.
- “Drafts go in Scrut.io.” Only final versions go in Scrut.io.
- “Standards and procedures are equal.” Standards sit above procedures.
- “Departments set their own hierarchy.” KU SEC 10 sets this University‑wide.
- “Exceptions last forever.” They expire after 12 months.