Country-Based Access Restriction Standards

Objective:

The purpose of this standard is to restrict access to Texas State Technical College (TSTC) resources based on geographic locations to enhance security measures and safeguard sensitive information.

Scope:

This policy applies to all employees, contractors, vendors, students, and any other entities requiring access to Texas State Technical College (TSTC) resources from foreign countries.

Policy Statements:

Country Access Restriction: Access to Texas State Technical College (TSTC) resources from foreign countries is restricted by default. Only authorized countries, as per this policy, will be granted access.

Authorized Countries: Access to Texas State Technical College (TSTC) resources from countries outside the authorized list requires either:

  • A valid and approved vendor contract that explicitly permits access from the respective foreign country.

  • Active military personnel, duly identified and authorized, who need access for official purposes.

Approval Process:

  • Requests for access from non-authorized countries must be submitted to the Office of Information Technology.

    • Requests should include the rationale, specific requirements, and duration of access needed.

    • Approval for access will be evaluated on a case-by-case basis by designated personnel.

Monitoring and Compliance:

  • The Security or IT department will monitor access logs regularly to ensure compliance with this policy.

  • Any unauthorized access attempts will be promptly investigated, and appropriate actions will be taken.

Exceptions:

  • Exceptions to this policy may be granted in exceptional circumstances, subject to approval by senior management from the Office of Information Technology.

Review and Updates:

This standard will be reviewed periodically, at least biennially, to ensure its effectiveness and relevance.

Updates or modifications to this policy will be made as necessary to address evolving security risks or changes in business requirements.

Responsibilities:

The Security or IT department is responsible for implementing and enforcing this policy.

Enforcement:
Failure to comply with this standard may result in actions taken pursuant to Statewide Operating Standard HR 2.4.1 Employee Corrective Action (Disciplinary Action)

Details

Article ID: 156053
Created
Thu 12/14/23 1:45 PM
Modified
Mon 3/25/24 3:45 PM