Information Security Plan
Protecting CSUN's Information and Technology
California State University, Northridge (CSUN) is committed to protecting the information and technology that support teaching, learning, research, administration, and campus operations.
The Information Security Plan provides a risk-based approach for protecting university information and technology while supporting CSUN's academic mission.
Cybersecurity is a shared responsibility. Students, faculty, staff, departments, and technology partners all play a role in protecting CSUN.
Our Security Priorities
CSUN's Information Security Plan focuses on:
- Protect Information — Safeguard university information based on its sensitivity and applicable requirements. Learn about Data Classification.
- Manage Risk — Identify and address cybersecurity risks involving university systems, projects, applications, and data. Learn about Risk Management.
- Secure Accounts & Technology — Protect accounts, devices, applications, and systems from unauthorized access. View Security Resources.
- Assess Vendors & Cloud Services — Review third-party services that access, store, or process university information. View the Hosted IT Services Security Checklist.
- Respond to Security Incidents — Report suspicious activity or potential cybersecurity incidents as soon as possible. Contact Information Security.
- Build Security Awareness — Help the CSUN community recognize threats and practice good cybersecurity habits. View Security Awareness Resources.
Know Your Data
Not all university information requires the same level of protection. CSUN's data classification standards help determine how information should be stored, accessed, transmitted, and shared.
Level 1 — Confidential
Information requiring the highest level of protection.
Level 2 — Internal Use
Information that requires protection from unauthorized disclosure.
Level 3 — Public
Information intended or approved for public access.
Learn more about CSUN Data Classification
When to Contact Information Security
Contact Information Security early when your department is:
- Purchasing or implementing technology that will handle Level 1 or Level 2 university information.
- Using a new cloud or third-party service involving sensitive university information.
- Providing a vendor access to university systems or data.
- Beginning a major technology project involving Level 1 or Level 2 information.
- Responding to a suspected cybersecurity incident.
- Unsure whether a cybersecurity review or risk assessment is required.
Engaging Information Security early in the planning or research process can help identify requirements and reduce delays.
Learn about the Risk Management Process
Information Security Resources
For additional information, visit:
- Information Security Policies & Standards — Review CSUN and CSU information security policies, standards, procedures, and guidelines.
- Risk Management — Learn about security risk assessments for projects, applications, vendors, and cloud services.
- Data Classification — Understand Level 1, Level 2, and Level 3 university information and protection requirements.
- Security Checklist for Hosted IT Services — Review security considerations for vendors, cloud applications, and hosted services.
- Security Resources for Students — Find cybersecurity guidance and resources designed for students.
- Security Resources for Faculty & Staff — Find cybersecurity guidance and resources for faculty and staff.
- CSUN Information Security — Access additional cybersecurity guidance, services, alerts, and resources.
Need Help?
For questions about the Information Security Plan, cybersecurity requirements, risk assessments, or security incidents, contact:
CSUN Information Security
Phone: (818) 677-6100
Email: iso@csun.edu