Table of Contents
- Purpose
- Policy Statement
- Applicability
- Compliance with Federal Law
- Security Standards
- CRSP Standard 3.1: Access Control (AC)
- CRSP Standard 3.2: Awareness and Training (AT)
- CRSP Standard 3.3: Audit and Accountability (AU)
- CRSP Standard 3.4: Configuration Management (CM)
- CRSP Standard 3.5: Identification and Authentication (IA)
- CRSP Standard 3.6: Incident Response (IR)
- CRSP Standard 3.7: Maintenance (MA)
- CRSP Standard 3.8: Media Protection (MP)
- CRSP Standard 3.9: Personnel Security (PS)
- CRSP Standard 3.10: Physical Protection (PE)
- CRSP Standard 3.11: Risk Assessment (RA)
- CRSP Standard 3.12: Security Assessment (CA)
- CRSP Standard 3.13: System and Communications Protection (SC)
- CRSP Standard 3.14: System and Information Integrity (SI)
- CRSP Standard 3.15: Planning (PL)
- CRSP Standard 3.16: System and Services Acquisition (SA)
- CRSP Standard 3.17: Supply Chain Risk Management (SR)
- Definitions
- Relevant Federal and State Statutes and Regulations
- Program Overview and Authority
- Revision History
Purpose
A supplement to the Information Resources Use and Security Policy (IRUSP) establishing specific requirements for the protection of Controlled Unclassified Information (CUI) in university research activities.
The Information Resources Use and Security Policy (IRUSP) provides the University of Texas at Austin with foundational requirements for the protection of all university information resources. This Policy supplements the IRUSP and establishes specific requirements for the protection of Controlled Unclassified Information (CUI) used in research activities governed by NIST SP 800-171.
This Policy establishes the authority for the Office of Research Support and Compliance (ORSC) and the Information Security Office (ISO) to implement and enforce security requirements for the Controlled Research Support Program (CRSP), including the operation of the Controlled Research Environment (CRE) — the central secure enclave used to process, store, and transmit CUI on behalf of sponsored research programs.
Policy Statement
It is the policy of the university to:
- Protect Controlled Unclassified Information (CUI) used in research activities against unauthorized access, disclosure, modification, or destruction, in compliance with NIST SP 800-171 and applicable federal regulations;
- Establish and maintain a Controlled Research Support Program (CRSP) that provides centrally managed security controls for research projects handling CUI;
- Ensure that all researchers, Principal Investigators, and research support staff who access CUI understand and comply with applicable security requirements; and
- Maintain compliance with federal regulations governing controlled research data, including requirements associated with the Cybersecurity Maturity Model Certification (CMMC) and International Traffic in Arms Regulations (ITAR), as applicable to sponsored research agreements.
Applicability
This Policy applies to:
- All CUI processed, stored, or transmitted within U. T. Austin information resources in connection with sponsored research activities;
- All systems, services, and infrastructure that are part of the Controlled Research Support Program (CRSP) or connected to the Controlled Research Environment (CRE);
- All Principal Investigators (PIs), researchers, staff, students, and third-party collaborators who access CUI in support of U. T. Austin research activities; and
- All vendors, contractors, and service providers that handle CUI on behalf of U. T. Austin research programs.
This Policy does not apply to research data that does not meet the definition of CUI as established by the National Archives and Records Administration (NARA) CUI Registry, or to general university information resources governed solely by the IRUSP.
Compliance with Federal Law
Research involving CUI is subject to federal regulations and contractual obligations that govern the handling, protection, and dissemination of controlled information. U. T. Austin research programs receiving federal funding or performing work under federal contracts must comply with NIST SP 800-171 as incorporated by reference in the Defense Federal Acquisition Regulation Supplement (DFARS) and other applicable federal acquisition regulations.
Failure to comply with applicable requirements may result in the loss of federal funding, contract termination, or other legal consequences. Nothing in this Policy is intended to prohibit or restrict legitimate research activities, the exchange of information necessary to conduct research, or collaboration with authorized partners in compliance with applicable federal regulations and sponsored research agreements.
Security Standards
The following standards establish the specific security requirements applicable to CUI systems and research activities covered by this Policy. Each standard corresponds to a control family defined in NIST SP 800-171 Revision 3. Compliance with these standards is mandatory for all covered systems, personnel, and activities.
About the numbering: CRSP Standards are numbered to align with the NIST SP 800-171 Rev. 3 control family structure (e.g., Standard 3.1 corresponds to NIST family 3.1 — Access Control, Standard 3.2 to family 3.2 — Awareness and Training, and so on). Controls within each standard follow the same scheme (e.g., 03.01.01, 03.01.02).
CRSP Standard 3.1 Access Control (AC)
CRSP Standard 3.2 Awareness and Training (AT)
CRSP Standard 3.3 Audit and Accountability (AU)
CRSP Standard 3.4 Configuration Management (CM)
CRSP Standard 3.5 Identification and Authentication (IA)
CRSP Standard 3.6 Incident Response (IR)
CRSP Standard 3.7 Maintenance (MA)
CRSP Standard 3.8 Media Protection (MP)
CRSP Standard 3.9 Personnel Security (PS)
CRSP Standard 3.10 Physical Protection (PE)
CRSP Standard 3.11 Risk Assessment (RA)
CRSP Standard 3.12 Security Assessment (CA)
CRSP Standard 3.13 System and Communications Protection (SC)
CRSP Standard 3.14 System and Information Integrity (SI)
CRSP Standard 3.15 Planning (PL)
CRSP Standard 3.16 System and Services Acquisition (SA)
CRSP Standard 3.17 Supply Chain Risk Management (SR)
Definitions
Relevant Federal and State Statutes and Regulations
- NIST Special Publication 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- NIST Special Publication 800-171Ar3, Assessing Security Requirements for Controlled Unclassified Information
- Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012
- CMMC — Cybersecurity Maturity Model Certification, Level 2
- 32 CFR Part 2002 — Controlled Unclassified Information
- International Traffic in Arms Regulations (ITAR), 22 CFR Parts 120-130
- Texas Administrative Code 202 — Information Security Standards
- UT System UTS-165 — Information Resources Use and Security Policy
- UT Austin Information Resources Use and Security Policy (IRUSP)
- UT-Austin CRSP 3.0 CUI Governance Policy
Program Overview and Authority
The Controlled Research Support Program (CRSP) establishes the institutional framework through which U. T. Austin protects Controlled Unclassified Information (CUI) entrusted to the university through federal sponsored research awards. The CRSP is authorized under the UT Austin Information Resources Use and Security Policy (IRUSP) and derives additional authority from NIST Special Publication 800-171 Rev. 3, the NARA CUI Federal Regulation (32 CFR Part 2002), DFARS Clause 252.204-7012, and applicable University of Texas System policies (UTS 165).
The Controlled Research Environment (CRE) is the centrally managed secure enclave operated under the CRSP that provides the technical boundary within which CUI is processed, stored, and transmitted. All research activities involving CUI must occur within or under the authority of the CRE unless otherwise formally authorized.
The security standards established in this policy supplement — and do not replace — the university's existing IRUSP. Where CUI handling, federal contracting obligations, or CMMC Level 2 requirements impose requirements more restrictive than those in the IRUSP, the CRSP standards govern within the CRE. Where this policy is silent, the IRUSP applies.
The Office of Research Support and Compliance (ORSC) maintains institutional authority over the CRSP. The Information Security Office (ISO) is responsible for policy development, technical standards, and compliance oversight. The Research Security Office (RSO) provides research-domain expertise and coordinates with federal sponsors. Principal Investigators serve as system owners for research systems within the CRE boundary.
Questions? Contact the UT Austin Information Security Office at security@utexas.edu or the Research Security Office for CUI-related research compliance questions.
CRSP Standard 3.1: Access Control (AC)
NIST SP 800-171 Rev. 3, Family 3.1
U. T. Austin shall control access to CUI systems within the Controlled Research Environment (CRE) in accordance with the principles of least privilege, separation of duties, and need-to-know. CRE access control requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern for all CRE systems and personnel.
3.1 Access Control (AC) Policy
03.01.01 Account Management. (See IRUSP §5; IRUSP §4) U. T. Austin shall establish, document, and enforce account management requirements for all information systems that store, process, or transmit CUI within the CRE, and shall enforce account management controls that:
- define and approve the types of system accounts that are permitted and explicitly prohibit unauthorized or unmanaged accounts;
- require that all system accounts are created, enabled, modified, disabled, and removed only in accordance with formally approved policies, procedures, prerequisites, and authorization criteria;
- ensure each system account is associated with an authorized individual, group, role, service, or device, and that group membership, role assignments, and access privileges are explicitly defined and aligned with assigned duties and intended system usage;
- authorize logical access to systems and CUI only after verification of a valid access authorization and documented need-to-know;
- monitor the use of system accounts to detect unauthorized, inappropriate, or anomalous activity;
- require the disabling of system accounts that are expired, inactive for no more than ninety (90) days, no longer associated with an authorized individual, in violation of organizational policy, or determined to present significant organizational risk;
- mandate notification to designated account managers and responsible roles within twenty-four (24) hours when accounts are no longer required, when users are terminated or transferred, or when an individual's system usage or need-to-know changes; and
- require users to log out of systems after no more than twenty-four (24) hours of expected inactivity, or when defined organizational circumstances occur, including at the end of the work period for privileged users, at a minimum, to reduce the risk of unauthorized access.
Note: Account management requirements shall support the principles of least privilege, separation of duties, and accountability, and shall be consistently enforced across all systems within the CRE in accordance with the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Program Authority | Office of Research Support and Compliance (ORSC) | Provides executive oversight and ensures resources and leadership support for the implementation of account management policies.; Notify account managers and IT personnel within 24 hours of employee onboarding, termination, transfer, or role changes affecting system access. |
| Policy Owner | Information Security Office (ISO) | Approves account management policy, ensures alignment with NIST SP 800-171 and ORSC CUI requirements, and oversees enforcement across all systems; Monitors system accounts for unauthorized or anomalous activity; reviews account status and logs; coordinates disabling of inactive or non-compliant accounts; Provide oversight and support for account management policy enforcement; ensure alignment with CUI governance requirements. |
| Research Coordination | Research Security Office (RSO) | Coordinates account management practices within research environments, including monitoring for policy compliance. |
| System Owner | Project Participants (PP) / Principal Investigators | Defines account types and access privileges; approves creation, modification, and removal of system accounts; verifies account usage aligns with intended purpose.; Approve access for research team members; ensure team members follow account management policies; report unauthorized or unusual account activity.; Log out of systems as required; comply with approved account usage policies; report anomalies or unauthorized access attempts. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Create, enable, modify, disable, and remove system accounts per policy and approved procedures; configure role assignments and privileges; enforce logout requirements. |
03.01.02 Access Enforcement. (See IRUSP §5; IRUSP §4) U. T. Austin shall enforce approved authorizations for logical access to CUI and system resources within the CRE, and shall enforce access control mechanisms that:
- ensure logical access to information systems, applications, and CUI is permitted only for authorized users, roles, services, and processes with documented access approvals;
- restrict access to system resources and CUI in accordance with established access control policies, least privilege principles, and approved role-based access authorizations;
- prevent unauthorized access, privilege escalation, and circumvention of access control mechanisms; and
- apply access enforcement consistently across all system components, including operating systems, applications, databases, and networked services.
Note: Access enforcement controls shall be implemented to support accountability, protect the confidentiality of CUI, and ensure compliance with the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Program Authority | Office of Research Support and Compliance (ORSC) | Provides executive oversight and ensures resources and leadership support for enforcement of access control policies. |
| Policy Owner | Information Security Office (ISO) | Approves access enforcement policy; ensures alignment with NIST SP 800-171 and ORSC CRE requirements; oversees university-wide implementation.; Monitors enforcement of access controls; audits access logs to detect unauthorized access or violations; coordinates remediation of access violations. |
| Research Coordination | Research Security Office (RSO) | Coordinates enforcement of access controls within research environments; monitors adherence to approved access authorizations. |
| System Owner | Project Participants (PP) / Principal Investigators | Defines access requirements and ensures users, roles, services, and processes are authorized before granting access; approves role-based access. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure and enforce access control mechanisms (operating systems, applications, databases, and networked services); implement role-based access controls; prevent privilege escalation. |
03.01.03 Information Flow Enforcement. (See IRUSP §5; IRUSP §4) U. T. Austin shall enforce approved authorizations to control the flow of CUI within CRE information systems and between interconnected systems, and shall enforce information flow controls that:
- ensure CUI is transmitted, accessed, and exchanged only through authorized system interfaces, services, and communication pathways;
- restrict the movement of CUI based on defined access authorizations, system interconnection agreements, and documented data handling requirements;
- prevent unauthorized transfer, dissemination, or exposure of CUI within systems or across system boundaries; and
- support the secure integration of interconnected systems while maintaining compliance with applicable CUI handling and protection requirements.
Note: Information flow enforcement supports the confidentiality and controlled dissemination of CUI within the CRE and is implemented in accordance with the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Program Authority | Office of Research Support and Compliance (ORSC) | Provides executive oversight for compliance with information flow policies; ensures resources and leadership support enforcement across research and organizational environments. |
| Policy Owner | Information Security Office (ISO) | Approves and oversees information flow enforcement strategy; ensures alignment with NIST SP 800-171 and UT-Austin ORSC CRE requirements.; Monitors system communications and interfaces to ensure CUI is transmitted and accessed only according to approved authorizations; audits logs and alerts for violations. |
| Research Coordination | Research Security Office (RSO) | Coordinates and monitors enforcement of information flow controls within research systems; supports secure system interconnections. |
| System Owner | Project Participants (PP) / Principal Investigators | Defines and authorizes the flow of CUI within systems and across interconnected systems; approves interconnection agreements and access permissions. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure and enforce network and system controls to restrict unauthorized CUI flow; implement secure interfaces, firewalls, and other technical controls. |
03.01.04 Separation of Duties. (See IRUSP §5; IRUSP §4) U. T. Austin shall identify duties and functions requiring separation and shall define system access authorizations that enforce separation of duties for information systems processing, storing, or transmitting CUI within the CRE. U. T. Austin shall enforce separation of duties by:
- assigning distinct roles and responsibilities to individuals or teams to reduce the risk of unauthorized, unintentional, or malicious activity;
- ensuring that critical system functions — such as access approval, system administration, security oversight, and audit review — are not performed by the same individual; and
- defining role-based access authorizations that prevent any single individual from exercising excessive control over CUI CRE systems or data.
Note: Where full separation of duties cannot be achieved due to operational or technical constraints, U. T. Austin shall implement and document compensating controls, such as management oversight, peer review, or enhanced auditing. Separation of duties assignments and associated access authorizations shall be reviewed periodically by designated system and security officials to ensure continued alignment with organizational structure, risk management objectives, and UT-Austin CRSP 3.0 CUI Governance Policy requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Program Authority | Office of Research Support and Compliance (ORSC) | Approves and oversees separation of duties strategy; ensures compliance with NIST SP 800-171 and UT-Austin CUI requirements; validates critical function segregation across systems. |
| Research Coordination | Research Security Office (RSO) | Supports enforcement of separation of duties in research environments; ensures role segregation in CUI-related systems and monitors compliance. |
| System Owner | Project Participants (PP) / Principal Investigators | Defines system roles and responsibilities; approves access authorizations to enforce separation of duties; ensures no single individual can perform all critical system functions. |
| Policy Owner | Information Security Office (ISO) | Monitors access and system activity to detect violations of separation of duties; ensures compensating controls are applied when full segregation is not feasible. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement RBAC and technical access controls to enforce separation of duties; prevent unauthorized consolidation of critical privileges. |
03.01.12 Remote Access. (See IRUSP §4.6; IRUSP §4.2) U. T. Austin shall control and secure all remote access to systems processing, storing, or transmitting CUI within the CRE to ensure confidentiality, integrity, and availability, and shall ensure that:
- usage restrictions and configuration requirements are established for each type of remote access, including remote desktops, VPN connections, and cloud-based access, to enforce organizational security policies;
- authorization for each type of remote system access is obtained prior to establishing connections, and access is granted only to defined and approved personnel in alignment with their roles and responsibilities;
- all remote connections are routed through authorized and managed access control points, such as secure VPN gateways or multi-factor authenticated portals, to ensure accountability and monitoring of traffic;
- remote execution of privileged commands or access to security-relevant information requires explicit approval and is restricted to authorized roles only, with all actions logged and auditable; and
- remote access is continuously monitored, logged, and reviewed to ensure compliance with access policies, detect unauthorized activity, and support incident response.
Note: Security configurations and access authorizations shall be updated in response to changes in personnel, risk assessments, or system architecture.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee university-wide remote access policy enforcement; review and approve authorizations for remote access; Monitor remote access activity, verify compliance with authorized use restrictions; conduct quarterly reviews |
| System Owner | Project Participants (PP) | Define usage restrictions, configuration requirements, and connection requirements for remote access under their purview; Access systems remotely only according to approved authorizations and connection requirements |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement, configure, and maintain remote access mechanisms, including VPN, tunneling, and encryption controls |
03.01.16 Wireless Access Authorization. (See IRUSP §4.6; IRUSP §4.2) U. T. Austin shall control and secure all wireless access to systems processing, storing, or transmitting CUI within the CRE, and shall ensure that:
- usage restrictions, configuration requirements, and connection requirements are established for all types of wireless access, including Wi-Fi, mobile hotspots, and any wireless-enabled devices, to enforce compliance with organizational security policies;
- authorization for wireless access is obtained prior to establishing any connection, and access is restricted to defined and approved personnel in accordance with their roles and operational need;
- wireless networking capabilities not required for operational purposes are disabled prior to issuance and deployment of devices;
- all wireless access is protected using strong authentication mechanisms and encryption protocols to prevent unauthorized access and eavesdropping; and
- monitoring, logging, and periodic review of wireless connections is conducted to ensure compliance with security policies, detect unauthorized access, and support incident response.
Note: Wireless security configurations and authorizations shall be updated as needed to reflect changes in personnel, system architecture, or emerging risks.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee university-wide wireless access policy enforcement; review and approve authorizations for wireless access; Audit and review wireless access logs; ensure compliance with authorized use restrictions |
| System Owner | Project Participants (PP) | Define wireless access usage restrictions, configuration requirements, and connection requirements for systems under their purview; Access systems via wireless connections only according to approved authorizations and connection requirements |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement and enforce wireless access controls; disable unused wireless access points; configure encryption and authentication |
03.01.18 Access Control for Mobile Devices. (See IRUSP §4.6; IRUSP §4.2) U. T. Austin shall control and secure the use of mobile devices that access, process, store, or transmit CUI within the CRE, and shall ensure that:
- usage restrictions, configuration requirements, and connection requirements are established for all mobile devices, including laptops, tablets, and smartphones, that connect to organizational systems;
- authorization to connect mobile devices to CRE systems is granted prior to access, limited to defined and approved personnel in accordance with their assigned roles and operational needs;
- full-device encryption or container-based encryption is implemented on all mobile devices used to access, store, or transmit CRE CUI to prevent unauthorized disclosure in case of loss or theft; and
- monitoring and auditing of mobile device access is conducted regularly to detect unauthorized usage, ensure compliance with security policies, and support timely incident response.
Note: Mobile device configurations and authorizations shall be reviewed and updated as required by personnel changes, device lifecycle events, or emerging risks.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Provide oversight of mobile device policy enforcement; review and approve authorizations for mobile device access; Audit mobile device usage and access logs; ensure compliance with authorized use restrictions |
| System Owner | Project Participants (PP) | Define usage restrictions, configuration requirements, and connection requirements for mobile device access under their purview; Access CRSP systems via mobile devices only according to approved authorizations and policies |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement and enforce mobile device access controls; configure encryption, authentication, and remote wipe capabilities |
03.01.05 Least Privilege. (See IRUSP §5) U. T. Austin shall enforce the principle of least privilege by authorizing only the minimum system access necessary for users, roles, and system processes to perform assigned organizational tasks involving CUI within the CRE. U. T. Austin shall restrict access to system functions, security functions, and security-relevant information based on documented role assignments, approved need-to-know, and intended system usage.
Access to security functions shall be limited to authorized roles and, at a minimum and where applicable, includes the ability to:
- establish system accounts and assign privileges;
- configure access authorizations;
- configure settings for events to be audited;
- establish vulnerability scanning parameters;
- establish intrusion detection parameters; and
- manage audit information.
Access to security-relevant information shall also be restricted to authorized roles and, at a minimum and where applicable, includes:
- threat and vulnerability information;
- router or firewall filtering rules;
- configuration parameters for security services;
- cryptographic key management information;
- security architecture documentation;
- access control lists; and
- audit information.
Note: Privileges assigned to roles or classes of users shall be reviewed at least every twelve (12) months to validate continued operational necessity and risk appropriateness. Access rights that are no longer required, exceed job responsibilities, or present unnecessary risk shall be promptly reassigned, reduced, or removed.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approves privileged account policy and assignment criteria; ensures alignment with NIST SP 800-171 and ORSC CUI requirements; oversees enforcement for university systems.; Monitors privileged account activity; audits use of privileged accounts to detect misuse or policy violations; coordinates revocation or adjustment of privileges as needed. |
| System Owner | Project Participants (PP) / Principal Investigators | Approves assignment of privileged accounts; ensures only defined and authorized personnel are granted elevated access; validates operational need for privileged access. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implements and enforces privileged account configurations; ensures users perform non-security functions with non-privileged accounts; supports monitoring and auditing. |
03.01.06 Least Privilege — Privileged Accounts. (See IRUSP §5) U. T. Austin shall restrict the use of privileged accounts on information systems that store, process, or transmit CUI within the CRE to only defined and authorized personnel or roles with an approved operational need. U. T. Austin shall require that:
- privileged accounts are used solely for the performance of authorized security or system administration functions;
- individuals assigned privileged access use non-privileged accounts when performing non-security functions or accessing non-security information, to reduce the risk of misuse, error, or unauthorized activity; and
- the assignment, use, and oversight of privileged accounts is subject to management oversight, monitoring, and periodic review to ensure continued appropriateness and compliance with applicable access control policies.
Note: This policy supports compliance with the UT-Austin CRSP 3.0 CUI Governance Policy by minimizing exposure of elevated privileges and reducing the potential impact of compromise within the CRE.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approves privileged account policy, assignment criteria, and overall enforcement strategy; ensures alignment with NIST SP 800-171 and UT-Austin ORSC CUI requirements.; Monitors and audits privileged account usage; identifies misuse, inappropriate activity, or deviations from approved operational use; recommends corrective actions. |
| System Owner | Project Participants (PP) / Principal Investigators | Approves assignment of privileged accounts; validates operational need; ensures accounts are granted only to defined and authorized personnel or roles. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implements technical enforcement of privileged account restrictions; ensures non-privileged accounts are used for non-security tasks; maintains audit logs of privileged activity. |
03.01.07 Least Privilege — Privileged Functions. (See IRUSP §5) U. T. Austin shall ensure that privileged functions on information systems that store, process, or transmit CUI within the CRE are restricted to authorized privileged users and roles only. U. T. Austin shall:
- prevent non-privileged users from executing privileged system functions, including administrative, security, and configuration-related actions, through the enforcement of logical access controls and role-based authorization mechanisms;
- require that the execution of privileged functions is logged and auditable to support accountability, monitoring, and the detection of unauthorized or inappropriate activity; and
- protect logs associated with privileged function execution from unauthorized access and review them in accordance with applicable audit and monitoring policies.
Note: This policy enforces the principles of least privilege and accountability and supports compliance with the UT-Austin CRSP 3.0 CUI Governance Policy by reducing the risk associated with elevated system privileges within the CRE.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approves policy governing privileged functions; ensures alignment with NIST SP 800-171, least privilege principles, and UT-Austin ORSC CUI requirements.; Monitors and audits execution of privileged functions; reviews logs for unauthorized or inappropriate activity; enforces corrective actions as needed. |
| System Owner | Project Participants (PP) / Principal Investigators | Authorizes which users and roles are allowed to execute privileged functions; defines access privileges for system administration, security, and configuration actions. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implements technical controls to restrict privileged functions to authorized users; ensures execution logs are captured, secured, and retained for review. |
03.01.08 Unsuccessful Logon Attempts. (See IRUSP §15.2.5) U. T. Austin shall enforce controls to limit the number of consecutive unsuccessful logon attempts for user accounts accessing systems that store, process, or transmit CUI within the CRE. U. T. Austin shall restrict user accounts to a maximum of five (5) consecutive invalid logon attempts within a five (5) minute period. When this threshold is exceeded, the system shall automatically:
- lock the account or node for at least fifteen (15) minutes, or until released by an administrator; and
- notify the system administrator of the event.
Note: All account lockouts shall be logged and reviewed to support audit, accountability, and incident response processes in accordance with the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approves policy for unsuccessful logon attempt limits; ensures alignment with NIST SP 800-171 and UT-Austin ORSC CUI requirements.; Monitors logs for lockout events; investigates repeated lockouts for potential unauthorized access; coordinates remediation. |
| System Owner | Project Participants (PP) / Principal Investigators | Defines account lockout thresholds, duration, and administrative release procedures; authorizes systems to enforce these settings. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure systems to enforce lockout thresholds, account lock duration, and administrator notification; ensure logs of failed logon attempts are captured and protected. |
03.01.09 System Use Notification. (See IRUSP §15.2.5) U. T. Austin shall display a system use notification message to all users prior to granting access to systems that store, process, or transmit CUI within the CRE. The notification shall include:
- privacy notices informing users of the confidentiality of CUI and the monitoring of system activity;
- security notices specifying authorized use, restrictions, and user responsibilities; and
- acknowledgment of compliance requirements, including adherence to the UT-Austin CRSP 3.0 CUI Governance Policy.
Note: Users must acknowledge the notification before being granted access to the system. The system shall prevent access to any user who does not provide the required acknowledgment. System use notifications shall be regularly reviewed and updated to ensure continued compliance with applicable regulations, institutional policies, and evolving cybersecurity requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| System Owner | Project Participants (PP) / Principal Investigators | Ensure publicly accessible systems under their control have defined procedures for CUI review and removal; oversee content management policies for compliance.; Follow training and procedures to prevent posting CUI on publicly accessible platforms; report any identified CUI exposure.; Ensure their teams comply with training and content handling policies; verify that publicly accessible content generated by team members contains no CUI. |
| Policy Owner | Information Security Office (ISO) | Monitor publicly accessible systems for CUI exposure; conduct periodic audits and coordinate content removal or remediation of any discovered CUI. |
| Program Authority | Research Security Office (RSO) | Develop and deliver training programs on handling and preventing CUI exposure on public systems; support compliance oversight. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement and maintain technical controls to support content monitoring; remove or secure publicly exposed CUI promptly; manage access to publishing tools. |
03.01.10 Device Lock. (See IRUSP §15.2.5) U. T. Austin shall prevent unauthorized access to systems storing, processing, or transmitting CUI within the CRE by implementing device lock mechanisms. U. T. Austin shall ensure that:
- systems automatically initiate a device lock after at most fifteen (15) minutes of user inactivity;
- users manually engage a device lock before leaving the system unattended;
- locked devices retain access control until the user successfully reestablishes access using approved identification and authentication procedures; and
- any information previously visible on the display is concealed or obscured during the device lock, preventing exposure to unauthorized viewers.
Note: Device lock policies shall be applied to all user devices, including desktops, laptops, mobile devices, and workstations that handle CUI within the CRE. Implementation and compliance shall be periodically reviewed to ensure effectiveness and alignment with institutional security requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| System Owner | Project Participants (PP) | Ensure that device lock policies are defined for all systems under their purview; approve acceptable inactivity timeout thresholds; Engage device locks manually before leaving unattended systems; comply with device lock policies |
| Policy Owner | Information Security Office (ISO) | Monitor compliance with device lock requirements; verify automatic lockout is functioning correctly |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure systems to automatically initiate device locks after defined inactivity periods; enforce screen-locking controls |
03.01.11 Session Termination. (See IRUSP §15.2.5) U. T. Austin shall protect systems and CUI within the CRE by automatically terminating user sessions under specific conditions to reduce the risk of unauthorized access or policy violations. User sessions shall be automatically terminated:
- after a maximum of twenty-four (24) hours of inactivity;
- immediately in response to misbehavior, including attempts to violate established access control or security policies; and
- to support system maintenance, including software upgrades, patching, or service outages, to prevent conflicts or unauthorized access during these events.
Note: Automatic session termination mechanisms shall be applied to all systems and applications that process, store, or transmit CUI within the CRE. Termination events shall be logged, monitored, and reviewed to ensure compliance and to detect potential security incidents.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Monitor session termination events, review logs for compliance; audit adherence to session termination policies |
| System Owner | Project Participants (PP) | Define session termination requirements, including inactivity thresholds, for systems under their purview; Comply with session termination procedures and policies; save work before sessions expire |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure systems and applications to automatically terminate sessions after defined inactivity periods |
03.01.20 Use of External Systems. (See IRUSP §15.2.5) U. T. Austin shall restrict and control the use of external systems to protect CUI within the CRE and ensure compliance with organizational security requirements.
- Prohibited Use: Access to organizational systems or processing, storing, or transmitting CUI within the CRE on external systems is prohibited unless those systems are specifically authorized.
- Security Requirements: External systems must satisfy defined security requirements prior to use, including, at a minimum:
- approval of the types of applications and services that can access organizational systems from external systems;
- confirmation that the external system can adequately protect the highest security category of CUI intended for processing, storage, or transmission; and
- compliance with guidance from NIST SP 800-47 when establishing information exchanges between organizational and external systems.
- Authorization and Agreements: Authorized individuals may use external systems only after:
- verification that the security requirements for the external systems, as specified in the organizational system security plans, have been satisfied; and
- retention of approved system connection or processing agreements with the external system owners.
- Portable Storage Restrictions: Use of organization-controlled portable storage devices on external systems is restricted and permitted only in accordance with organizational policy and authorization.
Note: Monitoring, auditing, and periodic review of authorized external system connections shall be conducted to ensure ongoing compliance with CRE security requirements. Unauthorized or non-compliant external system usage shall be reported and addressed according to institutional access control and incident response procedures.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Provide oversight and approval for external system policies and connection agreements; review annually; Monitor and audit external system connections; verify that systems comply with security requirements |
| Research Coordination | Research Security Office (RSO) | Establish and maintain system connection or processing agreements for external systems; perform periodic reviews |
| System Owner | Project Participants (PP) | Approve and define which external systems may connect to CRSP environments; establish usage restrictions; Access CRSP systems via external systems only when explicitly authorized and in accordance with established agreements |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement and enforce technical controls for authorized external system connections |
03.01.22 Publicly Accessible Content. (See IRUSP §4) U. T. Austin shall ensure that CUI within the CRE is not inadvertently exposed on publicly accessible systems.
- Train authorized individuals to ensure that publicly accessible information does not contain CUI.
- Review the content on publicly accessible systems for CUI and remove such information, if discovered.
Note: U. T. Austin shall ensure that CUI within the U. T. Austin CRE is not inadvertently exposed on publicly accessible systems. Training: All authorized individuals with access to CUI shall receive training to recognize and prevent the disclosure of CUI on public websites, cloud services, or other publicly accessible platforms. Content review: Authorized personnel shall regularly review publicly accessible content to verify that no CUI is present. Any CUI identified on such systems must be promptly removed or secured in accordance with U. T. Austin CUI handling policies.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| System Owner | Project Participants (PP) | Ensure publicly accessible systems under their control have appropriate controls to prevent CUI exposure; Follow training and procedures to prevent posting CUI on publicly accessible systems |
| Policy Owner | Information Security Office (ISO) | Monitor publicly accessible systems for CUI exposure; conduct regular reviews and audits |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement and maintain technical controls to support content review and prevent CUI from being posted publicly |
| Program Authority | Office of Research Support and Compliance (ORSC) | Develop and deliver training programs on handling and preventing CUI from appearing on publicly accessible systems |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides institutional authority and resources for CUI access control compliance; ensures leadership support for policy implementation |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Develops, reviews, and enforces access control policy; ensures alignment with NIST SP 800-171 and institutional requirements; implements and monitors access control mechanisms; ensures access logging, reporting, and compliance monitoring across CRE systems |
| Technical Implementation | Controlled Research Support Program (CRSP) | Provisions and deprovisions accounts based on approved requests; implements RBAC configurations; configures and maintains technical access controls and system logging |
| Research Coordination | Research Security Office (RSO) | Coordinates research-specific access control activities; incorporates insider threat, foreign influence, and research security requirements |
| System Owner | Project Participants (PP) / Principal Investigators | Defines system-specific access requirements; approves user access for research personnel; ensures access privileges align with research scope and compliance obligations; reports personnel changes affecting access within 24 hours |
CRSP Standard 3.2: Awareness and Training (AT)
NIST SP 800-171 Rev. 3, Family 3.2
U. T. Austin shall ensure that all personnel with roles in the Controlled Research Environment are made aware of the security risks associated with CUI and are trained to carry out their assigned security responsibilities. CRE awareness and training requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.2 Awareness & Training (AT) Policy
03.02.01 Literacy Training and Awareness. (See IRUSP §18) U. T. Austin ensures that all personnel—including faculty, staff, researchers, contractors, and affiliates—receive comprehensive security literacy and awareness training designed to promote the responsible handling and protection of CUI within the CRE.
U. T. Austin enforces the completion of the Center for Development of Security Excellence (CDSE) Cyber Awareness Challenge Course prior to initial access to CUI systems and annually thereafter. This training, combined with specialized modules such as Insider Threat Awareness (INT101.16), ensures that personnel understand their responsibilities in identifying, reporting, and mitigating cybersecurity risks, including insider threats, phishing attempts, social engineering, and social mining.
The Information System Security Officer (ISSO) maintains a Training and Certification Tracker within the secured CRE to document and verify completion of all required courses for authorized personnel.
U. T. Austin’s literacy and awareness program incorporates:
- Role-based content tailored for system users, administrators, and management;
- Instruction on recognizing and reporting insider threats, social engineering tactics, and social mining activities;
- Training on appropriate handling, safeguarding, and transmission of CUI, consistent with NIST SP 800-171 requirements;
- Regular updates to training content based on audit findings, security incidents, regulatory or policy changes, and evolving threat landscapes.
- Security awareness is reinforced through institutional communications, including periodic email bulletins, system login banners, awareness campaigns, and simulated phishing exercises to ensure continuous engagement and understanding of cybersecurity responsibilities across the U. T. Austin CRE.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Program Authority | Office of Research Support and Compliance (ORSC) | Provide security literacy training to all CRE system users, including new hires, contractors, and affiliates, covering CUI handling, insider threat indicators, social engineering, and social mining.; Deliver additional training following system changes, significant incidents, audit findings, or regulatory updates.; Update literacy training content to maintain relevance with evolving threats, laws, directives, or institutional policies.; Ensure personnel complete required literacy and awareness training prior to CRE system access and annually thereafter.; Reinforce training expectations; ensure team members complete required literacy courses.; Update training content based on audit findings, security incidents, and changes to laws, directives, or institutional policies. |
| System Owner | Project Participants (PP) / Principal Investigators | Complete assigned literacy and awareness training courses (CDSE Cyber Awareness Challenge and role-specific modules such as INT101.16). |
| Policy Owner | Information Security Office (ISO) | Maintain Training and Certification Tracker within the CRE; verify course completion for all personnel; report compliance metrics.; Approve and oversee literacy and awareness program; ensure alignment with institutional, federal, and NIST SP 800-171 requirements.; Complete initial literacy training prior to system access; complete refresher training annually; report suspicious activity or threats.; Disseminate security awareness bulletins, simulated phishing campaigns, and system login banners. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Ensure user enrollment in required courses; support access to training modules. |
03.02.02 Role-Based Security Training. (See IRUSP §18) U. T. Austin ensures that personnel with specific security responsibilities receive role-based security training tailored to their functions, access level, and operational environment within the (CRE.
U. T. Austin shall:
- Provide role-based security training prior to authorizing access to CRE systems, before performing assigned duties, and at least annually thereafter.
- Conduct additional training following significant system changes, updates to security policies, or other organization-defined events that impact user responsibilities or system security.
- Tailor training content to the specific duties and roles of personnel, including system administrators, developers, security assessors, acquisition staff, network personnel, and other personnel with CRE access.
- Ensure the Controlled Research Support Program (CRSP) reviews and updates all role-based training materials annually, or sooner as needed, to reflect changes in systems, technologies, regulatory requirements, or lessons learned from incidents.
Note: This policy reinforces U. T. Austin’s commitment to maintaining a security-aware workforce capable of protecting CUI and supporting compliance with NIST SP 800-171, NIST SP 800-53, DFARS 252.204-7012, and applicable federal and institutional standards.
The CRSP, or its designated representatives, are responsible for defining approved training paths, maintaining accurate training records, and reviewing course content to ensure alignment with institutional policies, federal regulations, and compliance requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Define approved role-based training paths based on personnel duties, access levels, and operational environment; ensure training content aligns with institutional policies, federal regulations, and compliance requirements.; Review and update role-based training materials to reflect changes in systems, technologies, regulatory requirements, or lessons learned from incidents.; Maintain accurate training records; track completion of role-based training; verify personnel compliance; report metrics to relevant leadership.; Update role-based training content to reflect emerging threats, system changes, audit findings, regulatory updates, or lessons learned from security incidents.; Support dissemination of role-based training reminders and updates; reinforce training through communications campaigns or system notifications. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure personnel assigned to their systems complete required role-based training prior to system access or performing duties; verify ongoing compliance with training requirements.; Complete assigned role-based training tailored to job function, access level, and operational environment; understand and carry out security responsibilities in accordance with assigned roles. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Ensure assigned personnel complete role-based training; reinforce awareness of role-specific security responsibilities and compliance expectations. |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides institutional authority and resources for the CRE security awareness and training program; ensures leadership commitment to training completion requirements. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Develops, reviews, and enforces awareness and training policy; ensures alignment with NIST SP 800-171 and federal training requirements; maintains training records. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Administers the training platform; enforces access prerequisites; monitors training completion rates and flags overdue personnel to ISO. |
| Research Coordination | Research Security Office (RSO) | Coordinates CRE-specific training content including insider threat awareness, CUI handling, and research-specific security topics. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensures all personnel on their research project complete required security awareness and role-based training before CRE access is provisioned. |
CRSP Standard 3.3: Audit and Accountability (AU)
NIST SP 800-171 Rev. 3, Family 3.3
U. T. Austin shall create, protect, retain, and review audit records for all CUI systems within the Controlled Research Environment sufficient to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. CRE audit and accountability requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.3 Audit & Accountability (AU) Policy
03.03.01 Audit Log Generation and Retention. (See IRUSP §17) U. T. Austin establishes and enforces comprehensive event logging requirements to ensure the collection of security-relevant audit information necessary to support accountability, incident detection, and compliance with NIST SP 800-171 and the UT-Austin CRSP 3.0 CUI Governance Policy.
U. T. Austin specifies the minimum set of event types that must be logged on all systems that process, store, or transmit CUI within the CRE. These event types are required to support monitoring, forensic analysis, and the detection of unauthorized or anomalous activity. At a minimum and where applicable, systems must generate audit records for the following event categories:
- Authentication Events
- Logons (Success/Failure)
- Logoffs (Success)
- Security-Relevant File and Object Events
- Create (Success/Failure)
- Access (Success/Failure)
- Delete (Success/Failure)
- Modify (Success/Failure)
- Permission modification (Success/Failure)
- Ownership modification (Success/Failure)
- Export/Write/Download Events to devices or digital media (e.g., USB, CD/DVD, SD cards) (Success/Failure)
- Import/Upload Events from devices or digital media (Success/Failure)
- User and Group Management Events
- User add, delete, modify, disable, lock (Success/Failure)
- Group/Role add, delete, modify (Success/Failure)
- Use of Privileged or Special Rights
- Security or audit policy changes (Success/Failure)
- Configuration changes (Success/Failure)
- Administrative or Root-Level Access (Success/Failure)
- Privilege or Role Escalation (Success/Failure)
- Audit and Security-Relevant Log Data Access (Success/Failure)
- System Reboot, Restart, and Shutdown (Success/Failure)
- Print to a Physical Device (Success/Failure)
- Print to File (e.g., PDF) (Success/Failure)
- Application Initialization Events (e.g., Adobe, Firefox, Microsoft Office) (Success/Failure)
- U. T. Austin reviews and updates the required event types at least every 12 months and following any significant security incident or material change in system risk, ensuring audit logging remains aligned with current operational, regulatory, and threat landscape requirements.
- Event logs must be generated consistently across all relevant systems, transmitted to centralized logging infrastructure where feasible, and protected from unauthorized access, modification, or deletion. All logging configurations and updates must support the confidentiality, integrity, and availability of CUI within the CRE and must reinforce U. T. Austin’s compliance with NIST SP 800-171 and UT-Austin CRSP 3.0 CUI Governance Policy requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee event logging program; ensure alignment with institutional policy and regulatory requirements; Implement and monitor logging configurations; validate log capture for defined events; Review logging coverage and effectiveness |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure assigned systems incorporate required event logging; Be aware that actions are logged; comply with usage policies |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure systems to log required events; maintain operational logging mechanisms |
| Program Authority | Office of Research Support and Compliance (ORSC) | Validate adherence to logging policies |
03.03.02 User Accountability via Unique Identification. (See IRUSP §17) U. T. Austin establishes and enforces standardized audit record content requirements to ensure that all audit logs produced within CRE systems processing, storing, or transmitting CUI contain the information necessary to support accountability, incident detection, forensic analysis, and compliance with NIST SP 800-171 and the UT-Austin CRSP 3.0 CUI Governance Policy.
Systems must generate audit records that provide sufficient detail to accurately identify the nature, context, and impact of security-relevant events. At a minimum, each audit record must include:
- Event Type — a description of what event occurred;
- Timestamp — the date and time when the event occurred;
- Event Location — the system, application, device, or component where the event took place;
- Event Source — the origin of the event, such as the process, interface, user, or system generating the action;
- Event Outcome — whether the event succeeded, failed, or generated a warning; and
- Identity Information — the unique identifiers of individuals, subjects, objects, or other entities associated with the event.
U. T. Austin also requires CRE systems to capture additional contextual information as needed to support audit log analysis, investigations, and operational needs. Such supplemental information may include, but is not limited to, network addresses, session identifiers, process IDs, command execution details, and object path metadata, when these details enhance the value and interpretability of audit records.
All audit records must be generated consistently across relevant systems and retained in accordance with applicable retention policies. Audit content must be protected from unauthorized access, modification, and deletion to maintain the confidentiality, integrity, and availability of CUI within the CRE and support compliance with NIST SP 800-171.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| System Owner | Project Participants (PP) / Principal Investigators | Ensure assigned systems capture required audit record content; Review records for regulatory compliance |
| Policy Owner | Information Security Office (ISO) | Ensure audit records capture required content; validate metadata accuracy; Validate completeness and accuracy of audit records |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement and maintain logging mechanisms that capture required content |
03.03.03 Audit Record Generation. (See IRUSP §17) U. T. Austin ensures that all CRE information systems processing, storing, or transmitting CUI generate audit records in accordance with the event types and audit record content defined in AU-03.03.01 and AU-03.03.02. Audit record generation is a required capability of all applicable system components to support accountability, incident detection, forensic analysis, and continuous security monitoring.
Systems must be configured to:
- Generate audit records for all organization-defined security-relevant events, including authentication activities, privilege use, configuration changes, user and group management actions, and other events specified in AU-03.03.01.
- Include complete audit record content as defined in AU-03.03.02, ensuring each log record captures the required details needed to understand what occurred, when, where, by whom, and with what outcome.
- Transmit audit records to designated centralized logging repositories or security monitoring tools to support analysis and correlation activities.
- Audit records must be retained for a period consistent with the institutional records retention policy, applicable federal requirements, and the UT-Austin CRSP 3.0 CUI Governance Policy. Retention periods must ensure sufficient availability of log data for security investigations, compliance reporting, and operational needs. Audit records must remain protected against unauthorized access, modification, and deletion throughout their retention lifecycle.
Note: This policy ensures that U. T. Austin maintains reliable, complete, and durable audit logging capabilities that support NIST SP 800-171 requirements and provide a trustworthy foundation for security oversight and incident response.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversight and governance of logging program; Ensure audit records are generated and transmitted correctly; Review log generation processes and completeness |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure system logging complies with retention and generation requirements |
| Technical Implementation | Controlled Research Support Program (CRSP) | Generate, secure, and maintain logs |
| Program Authority | Office of Research Support and Compliance (ORSC) | Verify adherence to record retention and generation policies |
03.03.04 Audit Logging Failure Alerts. (See IRUSP §17) U. T. Austin detects, alerts on, and responds to failures in audit logging processes to ensure the integrity, availability, and reliability of audit records for systems that process, store, or transmit CUI with the CRE. Audit logging capabilities must remain fully functional to support accountability, security monitoring, and incident investigation in alignment with NIST SP 800-171 and the UT-Austin CRSP 3.0 CUI Governance Policy.
System components must:
- Generate alerts in near real time, or as soon as practicable upon discovery, when audit logging processes fail, stop, reach capacity limits, become misconfigured, or otherwise cease to function as intended.
- Notify designated organizational personnel, including system owners, IT administrators, and security staff, so that prompt corrective action can be taken.
- Document all audit logging failures and corresponding resolutions, including timestamps, root cause analysis (when applicable), and corrective actions performed.
- Troubleshoot, repair, or restart failed audit logging services to restore normal operation as quickly as possible.
- Report the failure as a security incident when applicable, in accordance with the U. T. Austin Incident Response Plan (IRP), particularly if the failure results in the loss of audit data, degrades or disables monitoring capabilities, or indicates potential tampering or unauthorized modification of audit logging mechanisms.
- These requirements ensure that U. T. Austin maintains continuous and trustworthy audit logging functionality and responds effectively to disruptions that may impede the detection of unauthorized activity or compromise of CRE systems.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee resolution and incident escalation; Monitor logging processes; receive alerts; coordinate remediation |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure assigned systems participate in monitoring and recovery |
| Technical Implementation | Controlled Research Support Program (CRSP) | Troubleshoot and restore audit logging systems |
| Program Authority | Office of Research Support and Compliance (ORSC) | Document failures and verify resolution meets compliance |
03.03.05 Audit Record Review, Analysis, and Reporting. (See IRUSP §17) U. T. Austin establishes a structured process for the regular review, analysis, and reporting of system audit records to identify, evaluate, and respond to inappropriate or unusual activity within systems that process, store, or transmit CUI within the CRE. This process supports accountability, risk management, and continuous situational awareness across the U. T. Austin environment in accordance with NIST SP 800-171 and the UT-Austin CRSP 3.0 CUI Governance Policy.
Key requirements include:
- Review of Audit Records:
- Audit records are reviewed at least weekly and after significant security incidents, system changes, or identified risks.
- Reviews cover operating systems, applications, databases, network devices, and any other components generating audit logs relevant to CRE CUI.
- Analysis and Correlation:
- Audit logs are analyzed for indications of unusual, unauthorized, or potentially malicious activity.
- Correlation of audit records across multiple systems and repositories is performed to identify patterns, detect potential incidents, and provide organization-wide situational awareness.
- Reporting Findings:
- Identified anomalies, trends, or incidents are reported to responsible personnel, including the Chief Information Security Officer (CISO), Information System Security Officer (ISSO), and System Owners (SOs).
- Reports inform risk assessments, remediation actions, continuous monitoring activities, and compliance efforts.
- Documentation:
- All reviews, analyses, and resulting actions are documented in the System Security Plan (SSP), Plan of Action and Milestones (POA&M), or other institutional records to support traceability, audit readiness, and evidence of compliance.
Note: This policy ensures that U. T. Austin maintains proactive oversight of audit data, enables timely detection of potential threats or unauthorized activity, and supports comprehensive accountability and risk management for CRE systems.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversight and governance of review process; Support review, escalate findings; Ensure reviews align with policies |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure assigned systems support review/analysis |
| Technical Implementation | Controlled Research Support Program (CRSP) | Provide technical support for analysis |
| Program Authority | Office of Research Support and Compliance (ORSC) | Review and analyze audit logs for anomalies |
03.03.06 Audit Record Reduction and Report Generation. (See IRUSP §17) U. T. Austin implements structured processes and capabilities for audit record reduction and report generation to support effective review, analysis, reporting, and post-incident investigations of systems processing, storing, or transmitting CUI within the CRE. These capabilities ensure that relevant information is efficiently accessible while preserving the integrity and completeness of original audit data in accordance with NIST SP 800-171 and the UT-Austin CRSP 3.0 CUI Governance Policy.
Key requirements include:
- Audit Record Reduction:
- Audit records are filtered, summarized, or aggregated to produce manageable datasets for routine analysis, reporting, and trend identification without omitting critical security information.
- Reduction processes maintain the fidelity of the original records, ensuring that no essential information for compliance, investigation, or accountability is lost.
- Report Generation:
- Automated and manual reporting tools generate actionable audit summaries for system owners, ISSOs, CISO, and other stakeholders.
- Reports include relevant security events, anomalous activity trends, and indicators of potential system compromise, supporting informed risk management and decision-making.
- Preservation of Original Records:
- Original audit records are securely retained in their entirety, preserving content, sequence, and timestamps to support after-the-fact investigations, forensic analysis, and compliance verification.
- Preservation methods ensure that records cannot be altered, deleted, or otherwise tampered with, maintaining accountability and traceability.
- Integration with Security Processes:
- Reduced audit datasets and generated reports feed into the audit review, incident response, continuous monitoring, and compliance reporting processes.
- Findings and reports are documented and maintained in the System Security Plan (SSP), Plan of Action and Milestones (POA&M), or institutional recordkeeping systems.
Note: This policy ensures that U. T. Austin can efficiently review and analyze audit data, generate actionable reports, and conduct thorough post-incident investigations while maintaining the integrity, completeness, and traceability of audit records across CRE systems.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversight and governance; Configure reduction/reporting tools; ensure content integrity; Review reduced records and reports |
| Technical Implementation | Controlled Research Support Program (CRSP) | Support report generation and record preservation |
| Program Authority | Office of Research Support and Compliance (ORSC) | Validate compliance with reporting and preservation requirements |
03.03.07 Time Stamps. (See IRUSP §17) U. T. Austin ensures that all audit records generated for systems processing, storing, or transmitting Controlled Unclassified Information CUI within the CRE include precise and consistent time stamps to support accountability, traceability, and forensic analysis in accordance with NIST SP 800-171 and the UT-Austin CRSP 3.0 CUI Governance Policy.
Key requirements include:
- Time Source and Generation:
- Internal system clocks are used to generate time stamps for all audit records.
- Systems synchronize clocks with authoritative time sources to maintain accuracy and consistency across all information systems.
- Granularity and Format:
- Audit records record time stamps with a granularity of one (1) second or finer to enable precise event sequencing and correlation.
- Time stamps are expressed in Coordinated Universal Time (UTC), or include a fixed local time offset from UTC, ensuring clarity in multi-time zone environments.
- Integration and Preservation:
- Time stamps are embedded within all audit logs, event records, and associated metadata.
- The accuracy and integrity of time stamps are preserved during audit record reduction, report generation, storage, and retrieval to support incident investigations, compliance assessments, and accountability reviews.
Note: This policy ensures that U. T. Austin maintains consistent, accurate, and verifiable time information across all audit records, supporting effective monitoring, forensic analysis, and compliance with federal and institutional CUI requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversight; Validate timestamp accuracy; Verify timestamps comply with policy |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure system clocks and audit records meet timestamp requirements |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure and maintain synchronized system clocks |
03.03.08 Protection of Audit Information. (See IRUSP §17) U. T. Austin ensures that all CRE audit records, audit logs, and associated audit logging tools are safeguarded against unauthorized access, modification, and deletion to maintain the integrity, confidentiality, and reliability of audit data in accordance with NIST SP 800-171 and the UT-Austin CRSP 3.0 CUI Governance Policy.
Key requirements include:
- Access Controls:
- Access to audit logs, audit records, and audit logging tools is restricted to authorized personnel with a defined need-to-know.
- Only a limited set of privileged roles, such as the Information System Security Officer (ISSO), IT Administrators, and designated Security Operations staff, may manage, configure, or administer audit logging functionality.
- Data Protection:
- Audit information is protected from unauthorized modification, deletion, or tampering through technical controls such as access control lists (ACLs), role-based access control (RBAC), encryption, and system permissions.
- Backup and redundancy mechanisms are employed to ensure audit data is recoverable in the event of accidental deletion or system failure.
- Monitoring and Enforcement:
- Systems regularly monitor attempts to access or modify audit information to detect potential unauthorized activity.
- Violations of audit information protection policies are logged, investigated, and escalated in accordance with the incident response program.
- Documentation and Compliance:
- All access and administrative actions related to audit logging functionality are logged and maintained for accountability.
- Audit protection practices are reviewed periodically to ensure ongoing compliance with institutional policies and federal requirements.
Note: This policy ensures the confidentiality, integrity, and availability of audit information and enforces strict access management to maintain a trustworthy and accountable audit environment for CRE systems.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee the protection of audit information and audit logging tools; ensure policies align with federal and institutional requirements; Manage and monitor audit logging tools; enforce access controls; review logs for unauthorized access attempts; Verify protection and integrity of audit records |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure audit information protection requirements are implemented for assigned systems; provide access for monitoring and verification; Follow institutional policies to avoid unauthorized access or manipulation of audit data |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement technical protections (RBAC, ACLs, encryption); perform backups and recovery testing; respond to alerts regarding unauthorized access or tampering |
| Program Authority | Office of Research Support and Compliance (ORSC) | Validate adherence to access and protection requirements |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides institutional authority and resources for CRE audit infrastructure; ensures leadership support for audit compliance activities. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Establishes audit policy; defines required event categories; oversees log protection requirements; implements and monitors audit mechanisms across CRE systems. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Deploys and maintains audit collection infrastructure, SIEM, and log protection controls; conducts periodic alert reviews and escalates anomalies. |
| Research Coordination | Research Security Office (RSO) | Reviews audit findings relevant to research personnel; coordinates with PIs on accountability matters and research-specific audit requirements. |
| System Owner | Project Participants (PP) / Principal Investigators | Confirms that CRE systems under their purview are generating and forwarding required audit events; supports audit review activities upon request. |
CRSP Standard 3.4: Configuration Management (CM)
NIST SP 800-171 Rev. 3, Family 3.4
U. T. Austin shall establish, document, and maintain secure configuration baselines for all CUI systems within the Controlled Research Environment, enforce least-functionality restrictions, and manage all changes through a formal process. CRE configuration management requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.4 Configuration Management (CM) Policy
03.04.01 Baseline Configuration. (See IRUSP §8; IRUSP §7) U. T. Austin develops, documents, and maintains baseline configurations for all information systems and components that store, process, or transmit CUI within the CRE. Baseline configurations include detailed specifications for hardware, software, firmware versions, standard security configurations, patch levels, and network topology necessary to ensure secure and consistent system operation.
U. T. Austin maintains all baselines under formal configuration control to ensure that only approved, authorized, and documented changes are implemented. Baseline configurations are reviewed and updated at least annually, and whenever system components are installed, upgraded, replaced, reconfigured, or otherwise modified in a way that could affect the system’s security posture.
U. T. Austin maintains a centralized, authoritative inventory of system components supporting baseline documentation. The inventory records include component type, manufacturer, model, serial number, physical or assigned logical location, installed software and versioning, licensing details, and network associations. For portable or mobile devices, the physical location documented is the primary workspace or office for the assigned user, regardless of temporary operational relocation during the workday.
Baseline documentation and inventories are maintained in alignment with NIST SP 800-128 and institutional configuration management procedures to ensure accuracy, traceability, and compliance with federal requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversees institutional strategy for configuration baselines and ensures alignment with NIST SP 800-171 and UT-Austin CRSP 3.0 CUI Governance Policy requirements.; Maintain baseline configuration documentation under configuration control; ensure centralized repository accuracy.; Document baseline configurations for developed or engineered systems and ensure secure configuration settings are applied. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Ensures baseline configurations are developed, documented, maintained, and approved for all systems under their authority.; Verifies baseline documentation and reviews for compliance with institutional and regulatory requirements.; Conduct audits of baseline configuration records and associated change control documentation.; Evaluate risks associated with outdated or incomplete baselines and ensure mitigation planning.; Ensure personnel under their supervision adhere to baseline configuration requirements and report deviations. |
| System Owner | Project Participants (PP) / Principal Investigators | Reviews baseline configurations for completeness and security alignment; validates updates following system modifications.; Confirms that research-related systems processing CRE CUI maintain approved baseline configurations that meet federal requirements. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Approve modifications to baseline configurations resulting from change requests; ensure updates remain under configuration control.; Implement and document baseline configurations for applicable systems; update baselines after component installation, modification, or removal.; Apply approved baselines to systems, monitor for configuration drift, and report deviations to ISSO and ISO.; Maintain network-related baseline configurations (topology, firewall rules, device configurations).; Ensures baseline configuration requirements are followed within the CRE and coordinates compliance activities. |
03.04.02 Configuration Settings. (See IRUSP §8; IRUSP §7) U. T. Austin establishes, documents, and enforces secure configuration settings for all information systems that store, process, or transmit CUI with the CRE. Configuration settings reflect the most restrictive mode consistent with operational requirements and are developed using authoritative sources, including the National Institute of Standards and Technology (NIST) National Checklist Program (NCP), DISA Security Technical Implementation Guides (STIGs), and CIS Benchmarks.
U. T. Austin applies configuration settings to operating systems, applications, firmware, network devices, and endpoint components to ensure security controls are implemented consistently across the CRE. Remote devices connecting to U. T. Austin systems must not establish simultaneous connections to external networks through unauthorized channels.
Any deviation from approved configuration settings must be identified, documented, justified, and formally approved through the established change control and configuration management processes. All configuration deviations must include rationale, risk assessment, and mitigation actions.
Note: This approach ensures configurations remain secure, standardized, and aligned with NIST SP 800-171, NIST SP 800-70, NIST SP 800-128, and the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Establishes institutional security configuration requirements and ensures alignment with NIST and UT-Austin CRSP 3.0 CUI Governance Policy.; Maintains configuration setting documentation, manages configuration control records, and ensures approved settings are current.; Confirms that configuration settings on research systems processing CRE CUI align with federal compliance expectations.; Conduct audits of configuration settings, deviations, and compliance with approved baselines. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Ensures configuration settings are defined, documented, implemented, and maintained for assigned systems; approves deviations.; Reviews configuration settings and deviation documentation for compliance with policy and regulatory requirements.; Develop secure configuration standards and advise on configuration hardening based on NIST NCP, STIGs, and CIS Benchmarks.; Reviews risks associated with configuration deviations and ensures appropriate mitigations are in place.; Ensure personnel adhere to configuration enforcement requirements and report unauthorized changes. |
| System Owner | Project Participants (PP) / Principal Investigators | Reviews configuration settings for compliance; validates deviations and ensures required documentation is completed. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Reviews and approves deviations from configuration settings; ensures changes consider security impacts.; Implement approved configuration settings across systems; remediate deviations and apply updates consistently.; Apply, monitor, and validate system configuration settings; report unauthorized changes or deviations.; Apply and maintain secure configuration settings for network devices and enforce restrictions on unauthorized connections.; Ensures configuration settings meet CRE CUI protection requirements; coordinates with ISO and ISSO on deviations. |
03.04.03 Configuration Change Control. (See IRUSP §8; IRUSP §7) U. T. Austin establishes and enforces a formal Configuration Change Control process for all systems that store, process, or transmit CUI within the CRE. U. T. Austin identifies and defines the types of changes subject to configuration control, including but not limited to modifications to hardware, software, firmware, operating system settings, security configurations, network architecture, and established baseline configurations.
All proposed configuration-controlled changes must be reviewed, assessed for security and operational impact, and approved by the Change Control Board (CCB) or an authorized change authority before implementation. U. T. Austin requires that all approved changes be documented, tested in a controlled environment when feasible, and implemented according to established change management procedures. Unauthorized changes are prohibited and will be investigated.
U. T. Austin monitors and reviews all configuration-controlled change activities to ensure changes are implemented as approved, logged in an auditable system, and evaluated for potential security implications. Configuration change artifacts—including change requests, test results, approvals, implementation records, and post-implementation reviews—are retained in accordance with institutional requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Establishes university-wide configuration change control strategy; ensures alignment with policy and federal requirements; reviews high-risk or critical changes; Evaluates proposed changes for security impact; monitors implementation; validates adherence to configuration management policies |
| System Owner | Project Participants (PP) / Principal Investigators | Defines configuration-controlled changes for assigned systems; approves or coordinates change requests; ensures changes align with baseline and security requirements; Provide input on data or CUI-related impacts of proposed changes within the CRE; ensure changes do not compromise data integrity or access; Approve configuration changes that impact research systems under their supervision; ensure research compliance with change control; Communicate personnel changes that affect access rights and roles to support accurate configuration control; Follow approved procedures when requesting or initiating configuration changes; report unauthorized changes or anomalies |
| Technical Implementation | Controlled Research Support Program (CRSP) | Reviews, evaluates, approves, or disapproves proposed configuration changes; considers operational and security impacts; maintains change logs; Implement approved configuration changes; document implementation details; test and validate changes; report deviations or incidents |
03.04.04 Impact Analyses. (See IRUSP §8; IRUSP §7) U. T. Austin conducts formal security impact analyses for all proposed changes to information systems that process, store, or transmit CUI within the CRE. These analyses evaluate the potential effects of changes on system confidentiality, integrity, and availability, ensuring that all security requirements defined in NIST SP 800-171 and UT-Austin CRSP 3.0 CUI Governance Policy continue to be satisfied.
Impact analyses are required prior to the implementation of any configuration-controlled change, including modifications to hardware, software, firmware, network configurations, and access controls. Analyses are documented and reviewed to verify that post-change systems maintain compliance with security baselines, approved configuration settings, and institutional policies. Any identified risks are addressed through mitigation measures or change adjustments before approval and implementation.
Note: This policy ensures that U. T. Austin maintains a secure, compliant, and resilient IT environment, minimizing the risk of unauthorized access, data compromise, or operational disruption resulting from system changes.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Review and oversee the security impact analysis process; ensure analyses address institutional policy, NIST SP 800-171, and UT-Austin CRSP 3.0 CUI Governance Policy requirements; Conduct detailed security impact analyses on proposed changes; assess effects on confidentiality, integrity, and availability; document findings and recommend mitigation |
| System Owner | Project Participants (PP) / Principal Investigators | Identify proposed system changes; coordinate with ISSO and other personnel to ensure all changes undergo impact analysis; verify that post-change systems meet security requirements; Provide input on how proposed changes may affect CUI or data handling within the CRE; validate that changes do not compromise data protection; Ensure that changes impacting research systems do not adversely affect compliance or data integrity; review analyses for systems under their supervision; Report issues or deviations observed after changes are implemented; provide feedback on operational impact |
| Technical Implementation | Controlled Research Support Program (CRSP) | Review impact analyses for proposed changes; approve or reject changes based on security and operational risks; Implement changes in accordance with impact analysis recommendations; support verification of security controls post-implementation |
03.04.05 Access Restrictions for Change. (See IRUSP §8; IRUSP §7) U. T. Austin establishes, documents, and enforces both physical and logical access restrictions for all configuration management functions related to systems that process, store, or transmit CUI within the CRE.
Access to configuration repositories, change control tools, and system configuration settings is limited to authorized personnel with a documented need-to-know, enforced through role-based access controls, multifactor authentication, and time-based or situational restrictions. Physical access to secure facilities or equipment housing configuration-critical components is controlled and monitored according to institutional policies.
All configuration-related activities are logged, and access privileges are reviewed periodically to ensure compliance with NIST SP 800-171 and UT-Austin CRSP 3.0 CUI Governance Policy. Unauthorized access attempts are investigated, and changes are permitted only during approved maintenance windows whenever feasible. This policy ensures that only qualified and authorized personnel can make or approve changes, maintaining system integrity, protecting CRE CUI, and reducing the risk of unauthorized modifications.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee access restrictions for configuration management functions; ensure alignment with institutional policy and compliance requirements; Implement and monitor logical access controls; review access logs for configuration management tools; investigate unauthorized access attempts; Monitor alerts related to unauthorized access attempts to configuration management systems |
| System Owner | Project Participants (PP) / Principal Investigators | Define access requirements for system changes; approve access for personnel involved in configuration activities; Confirm that personnel accessing configuration functions are authorized to handle associated CUI within the CRE; Ensure research team members adhere to approved access policies for systems under their supervision; Access configuration functions only when authorized; comply with access restrictions; report unauthorized access attempts |
| Technical Implementation | Controlled Research Support Program (CRSP) | Approve access for personnel performing configuration changes; ensure access is granted only to authorized individuals; Configure and maintain access controls to enforce logical restrictions; monitor and log configuration activity; support audits |
| Program Authority | Office of Research Support and Compliance (ORSC) | Communicate personnel changes affecting access privileges to system owners and administrators |
03.04.06 Least Functionality. (See IRUSP §8; IRUSP §7) U. T. Austin configures all systems that store, process, or transmit CUI within the CRE to provide only mission-essential capabilities. Systems are deployed with minimal functionality required for operational objectives, and all nonessential functions, ports, protocols, connections, and services are disabled or removed.
U. T. Austin employs a layered approach to enforce least functionality, including:
- Using endpoint protection, host-based intrusion detection systems, firewalls, and network monitoring tools to identify and prevent unauthorized functions, connections, or services;
- Conducting periodic reviews of system functions, services, and configurations to identify and remediate unnecessary or nonsecure components;
- Integrating least functionality principles into system design, development, and procurement to reduce attack surfaces and mitigate potential security risks.
Note: This policy ensures that only authorized and necessary capabilities are available on U. T. Austin systems, enhancing system integrity, reducing the risk of exploitation, and maintaining compliance with NIST SP 800-171 and UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee institutional enforcement of least functionality principles and review policy compliance; Monitor system configurations; validate that only authorized functions, ports, protocols, and services are enabled; coordinate remediation of nonessential components; Detect and alert on unauthorized functions, connections, or services using network and host monitoring tools |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure systems under their control are configured for least functionality; approve deviations for operational needs; Operate systems in accordance with approved functionality; report unauthorized or unexpected system behaviors; Communicate personnel or role changes that affect access to system functions |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement configuration changes to disable or remove unnecessary services, ports, protocols, and functions; verify enforcement of least functionality settings; Approve use of essential system functions and review proposed exceptions; Review and approve changes that may alter system functionality to ensure alignment with least functionality principles |
| Program Authority | Office of Research Support and Compliance (ORSC) | Ensure research team members adhere to least functionality principles when using systems under their supervision |
03.04.08 Authorized Software – Allow by Exception. (See IRUSP §8; IRUSP §7) U. T. Austin enforces strict controls over the execution of software on systems that store, process, or transmit CUI within the CRE. Only software explicitly identified and approved for use is authorized to execute on these systems.
U. T. Austin implements a deny-all, allow-by-exception approach to software execution using application control or whitelisting technologies. Key practices include:
- Maintaining an inventory of approved software programs authorized for execution;
- Validating approved software using cryptographic checksums or digital signatures to ensure integrity;
- Conducting integrity checks at system startup and/or during execution to detect unauthorized modifications;
- Reviewing and updating the list of authorized software programs at least quarterly or after any significant system or security event;
- Enforcing the policy across endpoints, servers, and other enterprise-managed systems to prevent execution of unauthorized or potentially harmful software.
Note: This policy ensures the integrity of systems processing CUI within the CRE, reduces the risk of malware or unauthorized applications, and supports compliance with NIST SP 800-171 and UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee enforcement of authorized software controls; review policy adherence across U. T. Austin CRE systems; Monitor and verify that only authorized software is executed; coordinate remediation of unauthorized software; Detect and alert on execution of unauthorized software; escalate incidents as required |
| System Owner | Project Participants (PP) / Principal Investigators | Approve software for execution on systems under their control; validate necessity for operational requirements; Approve use of authorized software in alignment with data classification and operational requirements; Ensure research team members comply with authorized software policies on systems under their supervision; Execute only approved software; report unauthorized or unexpected applications or behaviors |
| Technical Implementation | Controlled Research Support Program (CRSP) | Review and approve changes affecting software installation or execution policies to ensure alignment with deny-all, allow-by-exception controls; Implement application whitelisting or equivalent controls; enforce deny-all, allow-by-exception policy; verify cryptographic integrity of authorized software |
| Program Authority | Office of Research Support and Compliance (ORSC) | Communicate personnel changes that affect software execution permissions or roles |
03.04.10 System Component Inventory. (See IRUSP §8; IRUSP §7) U. T. Austin maintains a comprehensive inventory of all system components that store, process, or transmit CUI within the CRE. The inventory includes, at a minimum, hardware, software, firmware, network devices, and associated system components. For each component, the inventory records manufacturer, model, serial number, version, configuration, licensing information, primary physical or virtual location, and ownership or custodianship information.
The system component inventory is reviewed and updated at least quarterly and whenever system components are installed, removed, or updated. Updates are documented to maintain accuracy and traceability. This inventory supports configuration management, security assessments, auditing, and compliance with NIST SP 800-171 and UT-Austin CRSP 3.0 CUI Governance Policy by providing visibility into the university’s information system landscape and ensuring accountability for all components.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee institutional system component inventory management; ensure compliance with policy and NIST SP 800-171 and UT-Austin CRSP 3.0 CUI Governance Policy requirements; Maintain and verify the system component inventory; ensure updates reflect installations, removals, and system updates |
| System Owner | Project Participants (PP) / Principal Investigators | Approve inventory entries for systems under their control; validate completeness and accuracy; Verify that system components storing or processing CUI are correctly recorded and properly managed within the CRE; Confirm research-related system components are accurately documented and maintained within inventory; Report system component changes or discrepancies to administrators |
| Technical Implementation | Controlled Research Support Program (CRSP) | Ensure that proposed system component changes are reflected in inventory updates; Record new, removed, or modified system components in the inventory; maintain accurate configuration and location information |
| Program Authority | Office of Research Support and Compliance (ORSC) | Notify system administrators of personnel changes that affect system component custodianship |
03.04.11 Information Location. (See IRUSP §8; IRUSP §7) U. T. Austin identifies and documents the physical and logical locations of all CUI and the systems or system components within the CRE on which CUI is processed, stored, or transmitted. The locations include on-premises servers, cloud environments, network storage, endpoints, and portable devices.
Changes to the location of CUI or system components within the CRE are documented promptly to ensure that security, access controls, and compliance measures remain accurate and effective. Maintaining an up-to-date record of CRE CUI locations supports accountability, traceability, and compliance with NIST SP 800-171 and UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee institutional tracking of CUI locations; ensure compliance with policy and NIST SP 800-171 requirements; Maintain and verify records of CUI locations; ensure updates reflect system changes, migrations, or relocations |
| System Owner | Project Participants (PP) / Principal Investigators | Approve documentation of CUI locations for systems under their control; validate completeness and accuracy; Confirm CUI locations within the CRE are correctly documented and maintained; update records upon changes; Verify research-related CUI and system locations within the CRE are documented accurately within the inventory; Report changes to CUI locations within the CRE, system components, or access points to administrators |
| Technical Implementation | Controlled Research Support Program (CRSP) | Ensure proposed changes impacting CUI locations within the CRE are accurately documented and approved; Record system components and CUI locations within the CRE; implement updates in inventory and configuration management systems |
| Program Authority | Office of Research Support and Compliance (ORSC) | Notify system administrators of personnel changes affecting CUI custodianship or system access locations within the CRE |
03.04.12 System and Component Configuration for High-Risk Areas. (See IRUSP §8; IRUSP §7) U. T. Austin enforces strict configuration management for systems and components issued to personnel traveling to high-risk locations to prevent unauthorized access, processing, or storage of Controlled Unclassified Information (CUI) or Federal Contract Information (FCI). Systems issued for travel are configured to minimize risk and protect institutional data while ensuring operational continuity.
This is enforced through the following procedures:
- Travel System Issuance
- All systems issued for travel to high-risk locations are preconfigured with no CUI or FCI stored unless a formal exception is documented and approved by the Contracting Officer.
- Systems are deployed with:
- Only mission-essential software installed.
- Security configurations aligned with DISA STIGs, NIST SP 800-171, and UT-Austin baseline settings.
- Application whitelisting and endpoint protection enabled.
- Network restrictions preventing external or unauthorized connections.
- End users are provided instructions and training on system use, data handling restrictions, and reporting procedures during travel.
- During Travel
- Users must use only the approved system for travel.
- Unauthorized software installation, modification of security settings, or introduction of CUI/FCI is prohibited.
- Any anomalies, suspected compromise, or security incidents must be reported immediately to the ISSO and SOC.
- Post-Travel System Handling
- Upon return, the ISSO or designated personnel inspect the system for signs of physical tampering.
- Systems are then either:
- Purged and reimaged to baseline configurations, or
- Destroyed if determined to be high-risk or compromised.
- All actions, including inspections, purges, and reimaging, are documented in the configuration management records.
- Systems that contained authorized CUI or FCI exceptions are verified against documentation and stored securely or destroyed per policy.
- Operating System–Specific Implementation
- Windows: Use BitLocker encryption for storage, Group Policy Objects (GPO) to enforce restrictions, and endpoint protection tools to prevent unauthorized installations.
- Linux: Implement disk encryption (LUKS), SELinux/AppArmor policies, and package whitelisting.
- macOS: Use FileVault, MDM-enforced security profiles, and application whitelisting to enforce travel system configurations.
- DISA STIG Implementation
- Apply relevant STIGs for endpoint hardening, account restrictions, network configuration, and application control to all travel systems.
- Validate STIG compliance during pre-travel system provisioning and post-travel reimaging or inspection.
- Audit and Compliance
- Configuration management records for travel systems, including inspections, purges, reimages, and exceptions, are retained in the institutional CMDB for traceability and audit purposes.
- Exceptions to the no-CUI policy require documented approval and risk assessment prior to travel.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee travel-related system configuration policy; ensure compliance with NIST SP 800-171 and UT-Austin CRSP 3.0 CUI Governance Policy; Verify systems are properly configured for travel; inspect systems post-travel for signs of tampering or compromise |
| System Owner | Project Participants (PP) / Principal Investigators | Approve travel system configurations; ensure exceptions are documented and authorized; Confirm that no CRE CUI or FCI is present on travel-issued systems unless formally approved; Ensure personnel under their supervision comply with travel configuration requirements; Use only authorized systems during travel; report any suspected compromise or anomalies immediately |
| Technical Implementation | Controlled Research Support Program (CRSP) | Apply approved travel configurations; purge or restore systems after return; document all actions |
| Program Authority | Office of Research Support and Compliance (ORSC) | Notify relevant personnel and administrators of travel schedules affecting CRE systems |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides executive authority for CCB structure and resource allocation for configuration compliance activities. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Establishes configuration management policy, baseline standards, and CCB charter; oversees compliance scanning and deviation tracking. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Applies and enforces baselines; manages allowed-lists; conducts automated compliance scans; maintains the configuration inventory and change records. |
| Research Coordination | Research Security Office (RSO) | Reviews research-tool change requests for security and regulatory implications before CCB consideration. |
| System Owner | Project Participants (PP) / Principal Investigators | Submits and justifies change requests; acknowledges responsibility for CRE systems remaining in compliant configuration; reports unauthorized changes immediately. |
CRSP Standard 3.5: Identification and Authentication (IA)
NIST SP 800-171 Rev. 3, Family 3.5
U. T. Austin shall uniquely identify and authenticate all users, processes, and devices that access CUI systems within the Controlled Research Environment before granting access. CRE identification and authentication requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.5 Identification & Authentication (IA) Policy
03.05.03 Multifactor Authentication (MFA). (See IRUSP §6; IRUSP §5; IRUSP §4) U. T. Austin enforces multi-factor authentication (MFA) for all privileged and non-privileged accounts accessing systems that store, process, or transmit CUI within the CRE. U. T. Austin requires users to authenticate using at least two distinct factors, such as knowledge-based, possession-based, or biometric authenticators, before granting system access.
U. T. Austin prohibits the use of default, shared, or generic credentials in production environments and ensures all privileged access is managed, which mandates MFA for both local and remote administrative actions. Non-privileged users accessing enterprise or CRE-connected resources are subject to Conditional Access policies requiring MFA.
U. T. Austin ensures MFA is applied consistently across user accounts, sessions are bound to authenticated identities, and authenticator use is logged for auditing and accountability within the CRE. Device identity and endpoint security posture verification are implemented to further confirm trusted access to CRE systems.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve MFA policies and oversee enterprise-wide enforcement for privileged and non-privileged accounts.; Monitor MFA enforcement, validate proper application of MFA controls, review logs, and report non-compliance or issues.; Configure and maintain MFA mechanisms, integrate MFA with user accounts, and ensure endpoint verification is operational.; Ensure MFA processes comply with privacy regulations and do not expose sensitive user information during authentication.; Review test results to ensure compliance with federal regulations, NIST SP 800-171r3 and UT-Austin CRSP 3.0 CUI Governance Policy. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure MFA is enabled for all users accessing their systems; integrate MFA with Conditional Access policies and privileged accounts. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Assess risks associated with MFA implementation gaps; track and document mitigation strategies. |
03.05.04 Replay-Resistant Authentication. (See IRUSP §6; IRUSP §5; IRUSP §4) U. T. Austin implements replay-resistant authentication mechanisms for all privileged and non-privileged account access to systems that store, process, or transmit CUI within the CRE. U. T. Austin ensures authentication exchanges cannot be captured and reused by adversaries by enforcing the use of cryptographically protected challenge-response mechanisms, time-bound authentication codes, and secure session establishment protocols.
U. T. Austin requires all authentication transactions to be protected using approved cryptographic standards and mandates the use of time-based one-time passcodes (TOTPs), cryptographic tokens, or other replay-resistant authenticators as defined in NIST SP 800-63B. Authentication sessions are uniquely bound to user identities and validated using non-reusable, verifier-protected secrets to ensure resistance to credential replay or interception.
U. T. Austin ensures replay-resistant authentication is consistently applied for both administrative and non-administrative access to CRE systems, and all associated authenticator use is logged to support auditability, accountability, and detection of unauthorized access attempts.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve enterprise-wide replay-resistant authentication policies; ensure alignment with NIST SP 800-63B and institutional security requirements.; Ensure that all systems under their control enforce replay-resistant authentication for privileged and non-privileged accounts.; Configure and maintain replay-resistant authentication mechanisms (e.g., challenge-response, TOTPs, cryptographic tokens); enforce cryptographic protocols such as TLS 1.3.; Assess risks associated with authentication mechanisms; identify gaps in replay resistance and track mitigation plans.; Ensure replay-resistant authentication practices comply with privacy requirements and do not expose sensitive user information during authentication.; Use approved authentication methods for system access; protect authentication factors; report lost or compromised authenticators immediately. |
| System Owner | Project Participants (PP) / Principal Investigators | Monitor and validate that replay-resistant authentication is implemented correctly; review authentication logs for unauthorized attempts or anomalies. |
03.05.05 Identifier Management. (See IRUSP §6; IRUSP §5; IRUSP §4) U. T. Austin establishes and maintains a structured process for the assignment, management, and reuse prevention of identifiers for individuals, groups, roles, services, and devices that interact with systems processing, storing, or transmitting CUI within the CRE.
U. T. Austin requires that:
- Authorization for Assignment: Identifiers are assigned only after receiving proper authorization from designated organizational personnel or roles.
- Identifier Selection and Assignment: Each identifier is uniquely selected and assigned to represent a specific individual, group, role, service, or device to ensure clear accountability and traceability.
- Reuse Prevention: Identifiers shall not be reused for a minimum period of ten (10) years to maintain identity uniqueness, prevent audit confusion, and preserve the integrity of access and activity records.
- Individual Identifier Management: Each individual is uniquely identified based on organizational-defined characteristics, including classification as privileged or non-privileged users, contractors, foreign nationals, or non-organizational users.
Note: This policy ensures that identifier management practices support accountability, auditability, and traceability, and maintain compliance with NIST SP 800-171 Control Family 3.5 (Identification and Authentication) and the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve policies and procedures for identifier assignment, reuse prevention, and individual categorization.; Review identifier assignment and reuse processes; ensure auditability and traceability of identifiers for accountability.; Implement and maintain systems that assign, track, and prevent reuse of identifiers; ensure proper segregation of privileged and non-privileged accounts.; Verify that identifiers are properly authorized, assigned, and managed; maintain oversight of identifier lifecycle and compliance. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure that identifiers for systems under their control are assigned according to policy and that reuse prevention measures are enforced.; Provide input on identifier assignments for users or devices accessing specific datasets; ensure classification aligns with data stewardship roles.; Use assigned identifiers only for their intended purpose; report any discrepancies or unauthorized use. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Authorize identifiers for personnel; classify users by role, status, and organizational affiliation.; Oversee the identifier management program across UTA CUI systems; ensure personnel are trained on identifier assignment and reuse policies.; Ensure that identifier assignment and management practices protect personally identifiable information and comply with privacy regulations. |
03.05.07 Password Management. (See IRUSP §6; IRUSP §5; IRUSP §4) U. T. Austin establishes and maintains a structured Password Management program to ensure the secure creation, use, transmission, and storage of passwords for accounts accessing systems that process, store, or transmit CUI within the CRE.
U. T. Austin requires that:
- Password Blacklist Maintenance: A list of commonly-used, expected, or compromised passwords is maintained and updated at least quarterly, and immediately whenever organizational passwords are suspected of being compromised.
- Password Validation: Passwords are verified against the maintained blacklist to prevent use of passwords that are commonly known, expected, or compromised during account creation or updates.
- Secure Transmission: Passwords must only be transmitted over cryptographically protected channels to prevent interception.
- Secure Storage: Passwords are stored in a cryptographically protected form to prevent unauthorized disclosure.
- First-Use Requirement: Users must select a new password upon first use following account recovery or reset.
- Password Composition and Complexity: Passwords must adhere to defined complexity requirements:
- Minimum length of sixteen (16) characters.
- Passwords must not contain strings that include the user’s account name or full name.
Note: This policy supports U. T. Austin’s commitment to safeguarding CRE CUI, mitigating risks associated with unauthorized access, and ensuring compliance with NIST SP 800-171r3 Control Family 3.5 (Identification and Authentication) and the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | ORSC / ISO |
| Program Authority | Office of Research Support and Compliance (ORSC) | ORSC / PP; ORSC / ISO / ET; ORSC / ISO / PP |
03.05.11 Authentication Feedback. (See IRUSP §6; IRUSP §5; IRUSP §4) U. T. Austin implements mechanisms to obscure authentication feedback during the login process for systems that process, store, or transmit CUI within the CRE.
U. T. Austin requires that:
- Input Masking: Passwords and other sensitive authentication inputs are masked on-screen to prevent observation by unauthorized individuals.
- Vague Error Messages: Authentication failure messages are intentionally generic (e.g., “Invalid credentials”) and do not indicate whether the username, password, or other factor was incorrect, thereby preventing disclosure of system or account information.
- Consistent Feedback Controls: All authentication interfaces provide consistent feedback across systems to minimize information leakage and reduce the risk of unauthorized access.
Note: This policy supports U. T. Austin’s commitment to protecting CRE CUI, mitigating risks of unauthorized disclosure, and ensuring compliance with NIST SP 800-171r3 Control Family 3.5 (Identification and Authentication) and the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve enterprise authentication feedback policies and standards; ensure alignment with institutional security and CRE governance requirements.; Validate authentication feedback mechanisms are configured correctly; monitor logs for potential information disclosure events.; Implement input masking, vague error messages, and consistent feedback mechanisms across all authentication interfaces; update settings when systems are deployed or modified.; Review authentication feedback mechanisms to ensure no inadvertent disclosure of PII or sensitive information. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure systems under their control implement feedback controls that obscure authentication information according to policy.; Ensure feedback controls align with protection requirements for data under their stewardship.; Follow system authentication procedures and report any anomalies in feedback behavior or potential exposure. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Oversee adoption of consistent authentication feedback controls across CRE systems; support training and awareness initiatives.; Audit authentication feedback implementations to verify consistency and compliance with policy and regulatory requirements. |
03.05.12 Authentication Management. (See IRUSP §6; IRUSP §5; IRUSP §4) U. T. Austin establishes and maintains a structured program for the management of authenticators to ensure secure access to systems processing, storing, or transmitting CUI within the CRE.
U. T. Austin requires that:
- Identity Verification: The identity of any individual, group, role, service, or device receiving an authenticator is verified prior to initial distribution.
- Initial Authenticator Content: All authenticators issued by U. T. Austin are initialized with secure content according to institutional standards.
- Administrative Procedures: Formal procedures are implemented for the distribution of initial authenticators, and for the revocation, replacement, or recovery of lost, compromised, or damaged authenticators.
- Default Authenticator Changes: All default authenticators must be changed upon first use to prevent unauthorized access.
- Authenticator Refresh or Change: Authenticators are changed or refreshed in accordance with the organization-defined frequency:
- Passwords protected by MFA: not routinely changed.
- Hard tokens and identification badges: at least every five (5) years.
- All other authenticators: at least every three (3) years, or upon relevant security events, including suspected compromise or loss.
- Protection of Authenticator Content: All authenticators are protected against unauthorized disclosure, modification, or misuse throughout their lifecycle.
Note: This policy ensures that U. T. Austin maintains robust access control, mitigates risks associated with unauthorized use of authenticators, and supports compliance with NIST SP 800-171r3 Control Family 3.5 (Identification and Authentication) and the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | ORSC / ISO |
| Program Authority | Office of Research Support and Compliance (ORSC) | ORSC / PP; ORSC / ISO / ET |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides institutional authority and resources to enforce MFA and authentication requirements across all CRE-connected research systems. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Defines IA policy, MFA standards, password requirements, and authenticator lifecycle rules for CRE systems; ensures controls align with NIST SP 800-63B and CMMC L2. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Deploys and enforces MFA policies; manages identity providers; configures lockout and session controls; provisions and revokes authenticators on CRE systems. |
| Research Coordination | Research Security Office (RSO) | Coordinates IA requirements with research teams; advises on authenticator selection appropriate for research workflows. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensures all project personnel are enrolled in approved MFA and comply with CRE credential standards; reports credential compromise immediately. |
CRSP Standard 3.6: Incident Response (IR)
NIST SP 800-171 Rev. 3, Family 3.6
U. T. Austin shall establish and maintain an operational incident response capability for CUI systems that includes defined roles, documented response procedures, timely reporting to applicable authorities, and systematic post-incident review. CRE incident response requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.6 Incident Response (IR) Policy
03.06.01 Incident Response Capability. (See IRUSP §12) U. T. Austin shall maintain a fully operational, coordinated, and documented incident response capability for systems that store, process, or transmit CUI within the CRE. This capability shall align with the U. T. Austin Incident Response Plan and support all functional phases of incident handling, including:
- Preparation
- Detection and analysis
- Containment
- Eradication
- Recovery
- Documentation and reporting
- User communication and response support
- This capability applies to cybersecurity and physical security incidents that could adversely affect the confidentiality, integrity, or availability of CUI within the CRE.
- Incident-handling responsibilities are assigned based on defined CRE system ownership and service boundaries:
U. T. Austin Responsibilities: U. T. Austin is responsible for detection, response, documentation, containment, eradication, recovery, and escalation activities for CRE systems that are on-premises, internally managed, or deployed on U. T. Austin-owned endpoints within the CRE boundary.
Cloud Service Provider (CSP) Responsibilities: CSPs are responsible for incident detection and response activities within their contracted service boundary supporting CRE systems. U. T. Austin retains responsibility for incident escalation, coordination, sponsor notification, and regulatory reporting obligations related to CUI handled within the CRE.
U. T. Austin employs automated monitoring capabilities, alerting mechanisms, and structured response workflows to ensure timely triage and coordinated incident-handling activities for CRE systems. These activities include, but are not limited to:
- Investigating suspicious communications, anomalous user activity, and indicators of compromise affecting CRE systems
- Containing and eradicating threats, including malware, unauthorized access, data leakage, misconfiguration, or insider misuse involving CUI
- Supporting legal, regulatory, and contractual reporting obligations specific to CUI incidents
- Managing physical security incidents impacting CRE systems, such as theft of CUI-bearing devices or unauthorized access to controlled areas
- Analyzing alerts generated by SIEM platforms, endpoint detection and response (EDR) tools, and cloud-native monitoring services supporting CRE systems
- Documenting response actions, technical findings, lessons learned, and remediation measures in accordance with established procedures
- U. T. Austin ensures that CRE incident response processes remain current and effective by periodically reviewing and updating procedures to reflect:
- Changes in CRE technologies, system architecture, or service providers
- Emerging threats, vulnerabilities, or intelligence relevant to CUI environments
- Findings and corrective actions identified through incident investigations or exercises
- Updated federal, state, sponsor, or contractual requirements applicable to CUI
Note: This incident response capability ensures that U. T. Austin maintains a timely, coordinated, and compliant approach to detecting, containing, mitigating, and recovering from incidents affecting CUI within the CRE, in accordance with NIST SP 800-171, NIST SP 800-61, and the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee the implementation, performance, and continual improvement of the incident response capability; ensure alignment with the IR Plan, NIST SP 800-171r3, and UT-Austin CRSP 3.0 CUI Governance Policy.; Maintain incident response procedures; coordinate technical and administrative incident-handling actions; ensure documentation and reporting are completed.; Lead all phases of the incident response lifecycle; coordinate containment, eradication, and recovery; manage stakeholder communications; conduct post-incident reviews.; Advise on regulatory and contractual reporting obligations; ensure incident response activities satisfy institutional and federal requirements; support documentation review. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure systems under their responsibility maintain documented and operational incident-handling processes for preparation, detection, analysis, containment, eradication, recovery, and documentation.; Promptly report suspected or confirmed incidents through approved reporting channels; cooperate with investigation activities. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Monitor for anomalous activity; perform triage; execute containment and eradication; restore system functionality; and document all actions. |
03.06.02 Incident Monitoring, Reporting, and Response Assistance. (See IRUSP §12) U. T. Austin shall maintain a centralized incident tracking and reporting process to ensure that all security incidents affecting CUI within the CRE—including incidents involving information systems, physical security, or personnel—are properly recorded, investigated, and communicated in a timely manner.
U. T. Austin leverages automated tracking and reporting systems for cloud-based CRE environments, as well as appropriate digital or manual logging mechanisms for non-cloud and on-premises CRE systems. Each incident record shall include, at a minimum:
- Event type and classification
- Date and time of detection
- Systems, applications, and CUI data impacted
- Actions taken and response measures
- Final resolution, lessons learned, and any follow-up actions
- Incident Reporting Requirements:
- Initial reporting: All suspected or confirmed incidents affecting CRE systems or CUI must be reported as near real-time as possible, and no later than one business day upon discovery, to the U. T. Austin Incident Response Team.
- Notification: Incident details shall be communicated to all applicable personnel and stakeholders in accordance with contractual obligations, the Incident Response Plan, and UT-Austin CRSP 3.0 CUI Governance Policy notification guidelines.
- Documentation: All incidents shall be fully documented using the Initial Intake Response Form within one business day of detection, ensuring compliance with federal, state, and institutional requirements.
- U. T. Austin enforces documented escalation procedures that define roles, notification timelines, and communication protocols to guarantee timely reporting to responsible officials, senior management, and, when applicable, external agencies.
- All personnel are trained to recognize and promptly report suspected or confirmed security incidents, including but not limited to:
- Data breaches or unauthorized access attempts involving CUI
- System anomalies, suspicious activity, or unexpected behavior in CRE systems
- Lost, stolen, or compromised devices containing CUI
- Physical intrusions into restricted areas or locations where CUI is stored
- For incidents involving CUI, U. T. Austin shall ensure that required reports are submitted to federal agencies in compliance with DFARS 252.204-7012, relevant federal regulations, and the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee the implementation and effectiveness of the incident response capability; ensure alignment with the IR Plan, NIST SP 800-171 and UT-Austin CRSP 3.0 CUI Governance Policy.; Maintain and oversee the centralized incident tracking system; ensure all incidents are properly logged, documented, and classified.; Receive, review, and triage reported incidents; provide guidance and assistance to system users on incident handling and reporting.; Provide guidance on regulatory and contractual reporting obligations; support coordination with external authorities; review incident documentation for compliance.; Report incident information to internal and external authorities as required by institutional policy, contracts, federal regulations, and UT-Austin CRSP 3.0 CUI Governance Policy. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure incidents impacting assigned systems are escalated, documented, and remediated in coordination with the IRT.; Recognize, document, and promptly report suspected or confirmed incidents via established reporting channels. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Assist in monitoring, collecting, and analyzing incident data; provide technical support and containment measures as directed by the IRT. |
03.06.03 Incident Response Testing. (See IRUSP §12) U. T. Austin ensures that the effectiveness of its incident response capability within the CRE is evaluated at least annually through structured testing and exercises. These activities include tabletop exercises, simulations, role-based walkthroughs, and, where appropriate, live incident simulations.
Testing and exercises are designed to validate:
- The readiness and competency of personnel assigned to incident response roles;
- The adequacy and functionality of technical controls supporting CRE systems that store, process, or transmit Controlled Unclassified Information (CUI);
- The effectiveness of incident response procedures covering detection, analysis, containment, eradication, recovery, and reporting of security incidents affecting CRE CUI.
- All test results are formally documented, analyzed, and used to update the Incident Response Plan, supporting procedures, and staff training programs. This ensures continuous improvement of U. T. Austin’s incident response program and alignment with organizational risk management, federal compliance requirements, and the UT-Austin CRSP 3.0 CUI Governance Policy.
- Additional testing is conducted as necessary following significant system changes, major security incidents, or updates to policies, regulations, or compliance obligations.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee the planning and execution of incident response tests, including tabletop exercises, simulations, and live drills.; Coordinate the logistics of testing, ensure participation of relevant personnel, and document test activities and results.; Conduct incident response exercises, evaluate detection, analysis, containment, and recovery processes, and provide feedback for improvement.; Review test results to ensure compliance with federal regulations, NIST SP 800-171r3 and UT-Austin CRSP 3.0 CUI Governance Policy. |
| System Owner | Project Participants (PP) / Principal Investigators | Participate in testing to validate system-specific incident response procedures and provide input on effectiveness.; Engage in role-based exercises to practice incident detection, reporting, containment, and recovery actions. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Support testing of technical controls, monitoring systems, alerts, and response mechanisms. |
03.06.04 Incident Response Training. (See IRUSP §12) U. T. Austin ensures that all personnel assigned incident response (IR) responsibilities within CRE receive training appropriate to their roles in protecting CUI and supporting the institution’s incident response program.
U. T. Austin provides IR training according to the following schedule:
- Privileged users: Within ten (10) days of assuming an IR role or responsibility or acquiring system access.
- All other personnel: Within thirty (30) days of assuming an IR role or responsibility or acquiring system access.
- All personnel: When required due to significant system changes, procedural updates, or modifications affecting assigned roles and responsibilities.
- Recurring training: At least every twelve (12) months thereafter to ensure ongoing proficiency and awareness.
- Training content is reviewed and updated at least annually and additionally following significant, novel incidents or substantial changes in risk. Updates reflect system modifications, evolving threat landscapes, lessons learned from incidents, audit findings, and changes to federal or institutional policies.
U. T. Austin maintains comprehensive records of completed training and communicates updates promptly to all relevant personnel. This ensures personnel remain knowledgeable about current incident response procedures, reporting requirements, and best practices for the effective detection, analysis, containment, and recovery of security incidents impacting CRE CUI.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee the development, approval, and maintenance of the incident response plan (IRP), ensuring alignment with organizational structure, mission, and regulatory requirements.; Draft, review, and update the IRP to reflect current systems, roles, and responsibilities; ensure plan addresses reportable incidents, information sharing, and designated responsibilities.; Receive and acknowledge IRP; review for understanding of responsibilities and escalation procedures; provide feedback on applicability and clarity.; Distribute copies of the IRP to designated personnel and organizational units; ensure access is restricted to authorized individuals.; Test and validate the IRP during exercises or real incidents; update the plan based on lessons learned or problems encountered. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Ensure protection of the IRP from unauthorized access or disclosure through controlled storage and access mechanisms. |
| System Owner | Project Participants (PP) / Principal Investigators | Provide system-specific input for plan content, including system roles, resources, and recovery procedures; ensure plan distribution to system-level personnel. |
03.06.05 Incident Response Plan. (See IRUSP §12) U. T. Austin develops, maintains, and enforces a formal Incident Response Plan (IRP) to guide the implementation and execution of the university’s incident response capabilities within the CRE. The IRP provides a structured roadmap for responding to security incidents affecting CUI and other sensitive institutional data, detailing the organization, roles, responsibilities, and integration of incident response activities across U. T. Austin systems and operations.
The IRP includes:
- Definitions of reportable security incidents and incident classifications;
- Criteria for escalation, notification, and information sharing;
- Assignment of clear responsibilities to designated organizational entities, personnel, and roles;
- Distribution of the IRP to all identified incident response personnel and relevant organizational units, ensuring that stakeholders understand their roles and obligations during incidents.
- The IRP is reviewed and updated to reflect changes in system architecture, organizational structure, regulatory or contractual requirements, and lessons learned from exercises, tests, or actual incidents. U. T. Austin ensures the IRP is protected from unauthorized access or modification through controlled storage and access mechanisms.
Note: By maintaining a current, comprehensive, and accessible IRP, U. T. Austin reinforces its commitment to a structured, coordinated, and effective response to cybersecurity incidents, supporting compliance with NIST SP 800-171 and the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop and maintain incident response training content aligned with U. T. Austin policies, federal regulations, and NIST SP 800-171r3 requirements.; Coordinate delivery of incident response training to personnel with assigned incident response roles.; Update training records and maintain evidence of completion in the Training and Certification Tracker. |
| System Owner | Project Participants (PP) / Principal Investigators | Verify personnel have completed required incident response training prior to authorizing access to systems containing CUI.; Complete incident response training consistent with assigned roles and responsibilities. |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides institutional authority for federal reporting decisions; serves as escalation point for Tier 2 and Tier 3 CUI incidents. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Maintains CRE-specific Incident Response Plan; coordinates incident detection, analysis, and response; oversees mandatory reporting obligations to federal sponsors. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Executes containment and eradication actions; preserves forensic evidence; restores CRE systems following incident resolution. |
| Research Coordination | Research Security Office (RSO) | Coordinates with federal sponsors and research stakeholders during CUI incidents; supports IRP testing and post-incident reviews. |
| System Owner | Project Participants (PP) / Principal Investigators | Reports suspected incidents immediately upon discovery; preserves evidence; cooperates with investigation and remediation activities. |
CRSP Standard 3.7: Maintenance (MA)
NIST SP 800-171 Rev. 3, Family 3.7
U. T. Austin shall ensure that all maintenance performed on CUI systems within the Controlled Research Environment is authorized, controlled, monitored, and documented. CRE maintenance requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.7 Maintenance (MA) Policy
03.07.04 Maintenance Tools. (See IRUSP §19) U. T. Austin establishes requirements to ensure that system maintenance tools, media, and equipment used within the CRE are properly approved, controlled, and monitored to protect CUI in accordance with NIST SP 800-171r3 and the UT-Austin CRSP 3.0 CUI Governance Policy.
U. T. Austin ensures that maintenance tools and equipment used on systems operating within the CRE are managed in a secure and controlled manner through the following practices:
- Approval, Control, and Monitoring of Maintenance Tools
- All system maintenance tools—including diagnostic software, administrative utilities, monitoring tools, and physical maintenance equipment—must be formally approved, inventoried, and controlled prior to use within the CRE.
- Only authorized personnel may use approved maintenance tools in accordance with established maintenance procedures and access control requirements. Tool usage must be logged, monitored, and periodically reviewed to prevent unauthorized system modification, data access, or configuration changes that could affect the confidentiality, integrity, or availability of CUI.
- Media Verification for Malicious Code
- All removable media, diagnostic utilities, firmware images, and test programs used during maintenance must be scanned and verified to be free of malicious code prior to introduction into any system operating within the CRE.
U. T. Austin requires the use of approved anti-malware, antivirus, and integrity verification mechanisms to validate the security of maintenance media. Media that fails security verification shall not be used within the CRE and must be reported to appropriate security personnel for further investigation.
- Protection and Disposal of Maintenance Equipment Containing CUI: Maintenance equipment that may store or process CUI—including laptops, portable diagnostic devices, maintenance workstations, and removable storage devices—shall not be removed from the CRE unless it has been verified that no CUI remains on the equipment.
If CUI cannot be verified as removed, one of the following actions must occur:
- The equipment is sanitized using approved media sanitization procedures to remove all CUI;
- The equipment is destroyed in accordance with institutional media destruction procedures; or
- The equipment is retained within the CRE under controlled storage and access conditions.
Note: These measures ensure that CRE CUI confidentiality, integrity, and availability are preserved during and after maintenance activities.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve system maintenance tools, including diagnostic software, administrative utilities, and maintenance equipment used within the CRE.; Monitor and review maintenance tool usage logs and verify compliance with maintenance procedures and security requirements. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure only authorized and approved maintenance tools are used within CRE systems and environments.; Confirm that no CUI remains on maintenance equipment prior to removal from the CRE or ensure sanitization or destruction procedures are applied.; Ensure secure retention of maintenance equipment containing CUI when removal from the CRE is not permitted. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Use only authorized maintenance tools and follow approved procedures when performing maintenance activities.; Scan and verify removable media, firmware images, and diagnostic/test programs for malicious code prior to introduction into CRE systems. |
03.07.05 Nonlocal Maintenance. (See IRUSP §19) U. T. Austin establishes requirements to ensure that nonlocal (remote) maintenance and diagnostic activities performed within the CRE are conducted securely and in a manner that protects CUI in accordance with NIST SP 800-171r3 and the UT-Austin CRSP 3.0 CUI Governance Policy.
U. T. Austin ensures that remote maintenance activities are authorized, securely established, actively monitored, and properly terminated to reduce the risk of unauthorized access or misuse of systems operating within the CRE.
- Approval and Monitoring of Nonlocal Maintenance: All nonlocal maintenance and diagnostic activities must be formally approved in advance by the System Owner (SO) or a designated authority before remote access to CRE systems is granted.
Remote maintenance sessions must be actively monitored or logged to ensure adherence to approved procedures and to verify that maintenance personnel access only authorized systems and resources. Unauthorized or unsupervised nonlocal maintenance access to CRE systems is strictly prohibited.
- Secure Session Establishment: Nonlocal maintenance sessions must be established using secure authentication and communication mechanisms designed to prevent unauthorized access and session interception.
U. T. Austin requires that:
- Multi-factor authentication (MFA) is used to authenticate personnel initiating nonlocal maintenance sessions.
- Replay-resistant authentication mechanisms are implemented to prevent session hijacking or credential replay attacks.
- Encrypted communication protocols are used to protect data transmitted during remote maintenance sessions.
- Access is restricted to authorized personnel with an approved operational need to perform maintenance activities.
Note: These measures ensure that remote maintenance connections to CRE systems maintain appropriate levels of identity assurance and communication security.
- Session Termination and Network Control: Upon completion of nonlocal maintenance or diagnostic activities, all remote sessions and associated network connections must be immediately terminated.
Any temporary access accounts, remote credentials, or elevated privileges granted to facilitate maintenance must be revoked or disabled following completion of the maintenance activity.
Maintenance session logs must be preserved and reviewed in accordance with U. T. Austin logging, monitoring, and auditing procedures to ensure accountability and detect potential security anomalies.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| System Owner | Project Participants (PP) / Principal Investigators | Approve all nonlocal maintenance and diagnostic sessions prior to initiation and ensure authorization aligns with system risk and CUI protection requirements.; Validate that CUI remains protected during nonlocal maintenance and confirm no unauthorized data access, modification, or transfer occurred. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Perform nonlocal maintenance only through approved access methods and documented procedures designed to protect CUI within the CRE.; Revoke temporary access accounts, remote credentials, and elevated privileges used during nonlocal maintenance activities. |
| Policy Owner | Information Security Office (ISO) | Monitor nonlocal maintenance sessions for compliance with security requirements, verify use of MFA and encrypted connections, and ensure sessions are terminated after completion. |
03.07.06 Maintenance Personnel. (See IRUSP §19) U. T. Austin establishes requirements to ensure that personnel performing maintenance on systems within the CRE are properly authorized, supervised when necessary, and capable of performing maintenance activities without compromising the confidentiality, integrity, or availability of CUI.
These requirements align with NIST SP 800-171r3 and the UT-Austin CRSP 3.0 CUI Governance Policy, ensuring that maintenance personnel are vetted, authorized, and monitored before interacting with systems operating within the CRE.
- Maintenance Personnel Authorization Process: U. T. Austin establishes and maintains a formal authorization process for all internal personnel, contractors, and third-party service providers who perform maintenance on systems within the CRE.
Authorization includes verification of:
- Required system and facility access authorizations
- Role-based qualifications and technical competency
- Completion of required security training
- Completion of personnel screening requirements, when applicable
- Compliance with institutional security policies governing the protection of CUI
- Only individuals who have completed the required authorization process may perform maintenance on CRE systems.
- List of Authorized Maintenance Personnel and Organizations
- U. T. Austin maintains a current list of authorized maintenance personnel and approved maintenance organizations that are permitted to perform maintenance activities within the CRE.
- This list includes:
- Authorized personnel names or vendor organization identifiers
- Access authorization level and approved systems
- Verification of required training and screening status
- Date of authorization approval
- The list is maintained by designated administrative or security personnel and is reviewed periodically to ensure accuracy and continued authorization.
- Verification of Access Authorization for Non-Escorted Personnel
- Personnel performing maintenance on CRE systems without escort or direct supervision must possess all required access authorizations prior to performing maintenance activities.
- Prior to each maintenance activity, responsible personnel must verify that:
- Maintenance personnel appear on the approved authorization list
- Access permissions align with the maintenance activity being performed
- Personnel possess the appropriate security clearances or institutional approvals
- Individuals who do not possess required authorizations must not be granted unescorted access to CRE systems or facilities.
- Supervision of Unauthorized Maintenance Personnel
- When maintenance must be performed by personnel who do not possess the required access authorizations, U. T. Austin designates authorized and technically qualified personnel to supervise those activities.
- Designated supervisors must:
- Possess the necessary system access authorizations
- Have sufficient technical competence to oversee maintenance tasks
- Ensure maintenance activities do not expose or compromise CUI
- Ensure maintenance tools, media, and equipment are used in accordance with institutional procedures
- Supervision ensures that maintenance tasks are completed safely while maintaining the security posture of systems operating within the CRE.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve maintenance personnel, including internal staff and third-party service providers, prior to granting maintenance access to CRE systems.; Ensure personnel performing maintenance are authorized or are supervised by designated personnel with required access and technical expertise.; Verify that non-escorted maintenance personnel possess required access authorizations and comply with CRE security requirements.; Review maintenance personnel authorization records and oversight activities to ensure compliance with CRE security requirements and institutional policy. |
| System Owner | Project Participants (PP) / Principal Investigators | Maintain and update the list of authorized maintenance personnel and organizations; verify screening, training, and authorization status. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Supervise maintenance activities performed by personnel lacking required access authorizations and ensure protection of CUI during maintenance operations. |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides institutional oversight for maintenance activity governance and authorization frameworks. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Establishes CRE maintenance policy; approves maintenance tools; reviews maintenance logs for compliance; enforces session recording requirements. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Executes and documents maintenance activities; enforces session recording and access revocation timelines; manages approved maintenance tool inventory. |
| Research Coordination | Research Security Office (RSO) | Advises on scheduling maintenance activities to minimize research impact while meeting security requirements. |
| System Owner | Project Participants (PP) / Principal Investigators | Authorizes maintenance activities on systems under their purview; ensures CUI is protected and appropriately handled during maintenance windows. |
CRSP Standard 3.8: Media Protection (MP)
NIST SP 800-171 Rev. 3, Family 3.8
U. T. Austin shall protect all media containing CUI throughout its lifecycle — including during use, storage, transport, and disposal — from unauthorized access, modification, disclosure, or destruction. CRE media protection requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.8 Media Protection (MP) Policy
03.08.01 Media Protection. (See IRUSP §11) U. T. Austin ensures that all system media containing CUI within the CRE, including digital and non-digital media, are physically controlled and securely stored to prevent unauthorized access, disclosure, or compromise.
U. T. Austin requires that:
- All CUI media be stored in secure locations, including locked containers, controlled-access rooms, or monitored media libraries within the CRE.
- Access to media storage areas is limited to authorized personnel with a documented operational need for access.
- Storage procedures maintain accountability and traceability for all CUI media.
- Media is protected from environmental hazards, theft, tampering, and unauthorized removal from secure areas.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce CRE media storage policies and procedures.; Audit adherence to CRE media storage controls and recommend corrective actions. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure all CUI media within the CRE are stored in secure locations (locked containers, controlled-access rooms, monitored media libraries); Limit access to media storage areas to authorized personnel with documented operational need; Maintain accountability and traceability records for all CUI media; Implement environmental, theft, tampering, and unauthorized removal protections for stored media.; Comply with access, handling, and storage procedures for CUI media within the CRE. |
03.08.02 Media Access. (See IRUSP §11) U. T. Austin restricts access to CUI stored on system media within the CRE to authorized personnel or roles. This ensures that media containing CUI is protected from unauthorized disclosure, modification, or loss.
U. T. Austin requires that:
- Access to CUI media within the CRE is granted only to personnel with a documented operational need, based on their role, responsibility, or assigned duties.
- Access permissions are reviewed and updated regularly to reflect personnel changes, role transfers, or terminations.
- Procedures are in place to log and monitor access to CUI media to detect and respond to unauthorized access attempts.
- Any exceptions to access restrictions are formally documented, justified, and approved by the System Owner (SO) and Chief Information Security Officer (CISO).
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce media access policies for the CRE.; Implement and maintain access controls for all CUI media within the CRE; Grant access to CUI media only to personnel with documented operational need based on role, responsibility, or assigned duties; Review and update access permissions to reflect personnel changes, role transfers, or terminations; Log and monitor access to CUI media to detect and respond to unauthorized access attempts.; Review, document, and approve any exceptions to media access restrictions.; Audit adherence to CRE media access control procedures and recommend corrective actions. |
| System Owner | Project Participants (PP) / Principal Investigators | Follow assigned access permissions and report unauthorized access attempts. |
03.08.03 Media Sanitization. (See IRUSP §11) U. T. Austin ensures that all system media containing CUI within the CRE are sanitized prior to disposal, release outside organizational control, or reuse. This prevents unauthorized disclosure, data recovery, or compromise of sensitive research information.
U. T. Austin requires that:
- Media sanitization is performed using approved methods, consistent with NIST Special Publication 800-88 Revision 1, including techniques such as cryptographic erase, degaussing, shredding, or incineration, based on media type and sensitivity of the CUI.
- Media is verified to be free of residual CUI following sanitization before disposal, reuse, or transfer.
- Sanitization procedures are documented, and the process is auditable to demonstrate compliance with CRE security policies and regulatory requirements.
- Personnel performing sanitization are trained, authorized, and supervised when necessary, and their actions are logged for accountability and traceability.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce CRE media sanitization policies and procedures.; Implement and oversee media sanitization procedures for all CUI-containing media within the CRE; Ensure media sanitization methods comply with NIST SP 800-88 Rev. 1 (e.g., cryptographic erase, degaussing, shredding, incineration); Verify media is free of residual CUI prior to disposal, reuse, or transfer; Document and maintain auditable records of all media sanitization activities; Ensure personnel performing media sanitization are trained, authorized, and their actions are logged for accountability.; Audit sanitization processes, verify compliance, and recommend corrective actions. |
| System Owner | Project Participants (PP) / Principal Investigators | Perform sanitization according to approved procedures and log all actions. |
03.08.04 Media Marking. (See IRUSP §11) U. T. Austin ensures that all system media containing Controlled Unclassified Information (CUI) within the Controlled Research Environment (CRE) are properly marked to indicate distribution limitations, handling caveats, and applicable CUI designations throughout the media lifecycle.
U. T. Austin requires that:
- All media, digital and non-digital, containing CUI are labeled in accordance with federal CUI guidelines, including the applicable CUI category, dissemination restrictions, and handling instructions.
- Labels and markings are clear, durable, and remain visible during storage, transport, use, and any other handling of media within the CRE.
- Media received from external sources is reviewed and marked per U. T. Austin standards before introduction into organizational systems or CRE environments.
- Personnel handling marked media are trained on interpreting and enforcing CUI marking requirements, and any media lacking proper markings are reported and appropriately managed.
- Procedures for media marking are documented and auditable to ensure compliance with regulatory, federal, and institutional requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce CRE media marking policies and procedures.; Implement and oversee media marking procedures for all CUI-containing media within the CRE; Ensure media sanitization methods comply with NIST SP 800-88 Rev. 1 (e.g., cryptographic erase, degaussing, shredding, incineration); Review and mark media received from external sources before introduction into CRE systems; Maintain auditable records of media marking activities and verify compliance; Ensure personnel handling marked media are trained and understand labeling requirements.; Audit media marking processes, verify compliance, and recommend corrective actions. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Apply, interpret, and comply with all CUI media markings; report improperly marked media. |
03.08.05 Media Transport. (See IRUSP §11) U. T. Austin ensures that all system media containing CUI within the CRE are protected, controlled, and tracked during transport outside secure or controlled areas.
U. T. Austin requires that:
- All media containing CUI transported outside secure facilities or CRE-controlled areas must be physically secured using approved methods, including locked containers, tamper-evident packaging, or encrypted transport for digital media.
- Accountability for media is maintained throughout the transport process, with responsible personnel tracking custody, handling, and delivery to authorized recipients.
- Transport activities are documented, including date, time, origin, destination, personnel involved, and verification of receipt, creating a fully auditable record of media movement.
- Personnel involved in transporting CUI media are trained on secure handling, transport procedures, and reporting obligations to prevent unauthorized access, loss, or compromise.
- Procedures for transporting CUI media are reviewed and updated periodically to reflect regulatory guidance, operational requirements, or changes in threat conditions affecting the CRE.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce the Media Transport policy and associated procedures.; Implement and oversee secure transport procedures for all CUI-containing media within the CRE; Approve transport methods and ensure physical and technical controls (locked containers, tamper-evident packaging, encryption) are applied; Maintain accountability logs documenting date, time, origin, destination, personnel, and verification of receipt.; Audit transport procedures and records to verify adherence to UT-Austin CRSP 3.0 CUI Governance Policy requirements. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Provide training to personnel on secure transport, accountability, and reporting requirements for CUI media. |
| System Owner | Project Participants (PP) / Principal Investigators | Securely transport media according to approved methods, maintain custody, and ensure protection of CUI during transport; Accurately document media movement, custody, and delivery verification |
03.08.07 Media Use. (See IRUSP §11) U. T. Austin establishes controls over the use of system media containing CUI within the CRE to prevent unauthorized access, loss, or compromise.
U. T. Austin requires that:
- The use of specific types of system media is restricted or prohibited as defined by organizational policy. This includes, but is not limited to, removable media, portable storage devices, or external drives that pose a security risk to CUI within the CRE.
- Removable system media containing CUI must have a clearly identifiable owner responsible for its security, and the use of unassigned, untracked, or unmanaged media is prohibited.
- All personnel handling CUI media receive training on authorized media types, ownership requirements, and secure handling protocols for media use.
- Procedures are in place to track, monitor, and audit media usage, ensuring compliance with access restrictions and ownership assignments.
- Policy and procedures are reviewed periodically and updated to reflect changes in technology, regulatory guidance, or operational requirements affecting CRE systems.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce the Media Use policy and associated procedures for the CRE.; Define authorized and restricted/prohibited types of system media containing CUI in the CRE; Implement procedures to track ownership of removable media and ensure each item is assigned to a responsible owner.; Audit media usage to verify compliance with approved media types, ownership assignments, and security controls in the CRE. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Provide personnel training on approved media types, ownership requirements, and secure handling procedures. |
| System Owner | Project Participants (PP) / Principal Investigators | Use only approved media types and ensure assigned media is protected according to policy and CRE requirements; Immediately report unassigned, lost, or unauthorized media to the appropriate security personnel. |
03.08.09 System Backup – Cryptographic Protection. (See IRUSP §11) U. T. Austin ensures that all backup copies of CUI within the CRE are protected against unauthorized access, disclosure, or compromise.
U. T. Austin requires that:
- The confidentiality of all backup information containing CUI is maintained through appropriate security controls, including access restrictions, monitoring, and secure handling.
- Cryptographic mechanisms approved by institutional and federal standards are applied to secure backup data at rest and during transfer to backup storage locations. This includes encryption of backup media, secure key management, and adherence to cryptographic best practices.
- Only authorized personnel with a defined business or operational need are permitted to access backup media containing CUI.
- Backup procedures, cryptographic protections, and key management are reviewed periodically to ensure alignment with changes in technology, regulatory guidance, or risk assessments.
- All backup activities are documented, including encryption methods used, storage locations, responsible personnel, and verification of confidentiality protections.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce backup protection policy, including cryptography standards; Define and approve backup policies, including cryptographic protection requirements for CUI within the CRE; Ensure backup procedures include approved cryptographic mechanisms and secure key management.; Audit backup processes, encryption implementation, access logs, and adherence to policy |
| Technical Implementation | Controlled Research Support Program (CRSP) | Encrypt backup media, manage cryptographic keys securely, and store backups in approved locations; Document backup activities, including encryption methods, storage locations, responsible personnel, and verification of confidentiality protections; Encrypt backup media, manage cryptographic keys securely, and store backups in approved locations. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Train personnel on cryptographic requirements, secure handling, and access procedures for backup media |
| System Owner | Project Participants (PP) / Principal Investigators | Access backup media only when necessary and in accordance with defined roles and operational need |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides institutional authority for CUI media governance; escalation point for unauthorized media removal incidents. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Maintains media protection policy; approves removable media for CRE use; ensures sanitization standards are current; enforces endpoint controls blocking unauthorized media. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Manages approved media inventory; enforces endpoint controls blocking unauthorized media; performs or verifies sanitization before media reuse or disposal. |
| Research Coordination | Research Security Office (RSO) | Advises PIs on media handling requirements specific to contract CUI categories and authorized sharing scenarios. |
| System Owner | Project Participants (PP) / Principal Investigators | Authorizes media removal from CRE areas; ensures all project personnel understand CUI media handling, transport, and sanitization requirements. |
CRSP Standard 3.9: Personnel Security (PS)
NIST SP 800-171 Rev. 3, Family 3.9
U. T. Austin shall screen individuals before granting access to CUI systems, ensure that CRE access is promptly revoked upon personnel separation or role change, and conduct security debriefings to reinforce ongoing obligations upon termination. CRE personnel security requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.9 Personnel Security (PS) Policy
03.09.01 Personnel Security Screening. (See IRUSP §2; IRUSP §1) U. T. Austin conducts comprehensive personnel security screening to evaluate the trustworthiness of individuals prior to granting access to systems, facilities, or environments within the CRE that store, process, or transmit CUI.
Screening activities assess factors including conduct, integrity, judgment, loyalty, reliability, and stability, and are conducted in accordance with applicable federal laws, directives, institutional policies, and the UT-Austin CRSP 3.0 CUI Governance Policy. Screening criteria are tailored to the level of access required for assigned positions to ensure effective risk management.
In addition to initial screening, U. T. Austin requires rescreening of personnel under organization-defined conditions, which may include, but are not limited to:
- Changes in job roles or responsibilities that grant higher levels of access to CRE CUI;
- Reassignment, promotion, or transition to sensitive or privileged positions;
- Periodic rescreening intervals defined by U. T. Austin based on risk assessment, regulatory requirements, or compliance obligations;
- Following adverse incidents, security concerns, or other events indicating potential risk to CUI or institutional systems.
- Personnel screening and rescreening activities are conducted in compliance with NIST SP 800-171r3 Control Family 3.9 (Personnel Security) and the UT-Austin CRSP 3.0 CUI Governance Policy, ensuring that all individuals with access to CRE CUI maintain an appropriate level of trustworthiness, reliability, and accountability throughout their tenure at U. T. Austin.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| System Owner | Project Participants (PP) / Principal Investigators | Verify suitability of personnel for system-specific access; confirm rescreening requirements are met prior to granting elevated or sensitive access.; Coordinate initial personnel screening and rescreening processes; collect, verify, and document background screening information; ensure compliance with UT-Austin CRSP 3.0 and applicable federal requirements.; Identify personnel changes (promotions, transfers, role changes) that may trigger rescreening; report personnel events requiring rescreening; ensure staff complete required security training and assessments. |
| Policy Owner | Information Security Office (ISO) | Review screening and rescreening results for individuals requiring CRE CUI system access; approve access based on risk assessment; maintain screening records in the personnel security system or Training and Certification Tracker. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Audit and monitor adherence to screening and rescreening procedures; identify compliance gaps; provide guidance on corrective actions. |
03.09.02 Personnel Termination and Transfer. (See IRUSP §2; IRUSP §1) U. T. Austin protects CUI within the CRE during personnel changes by enforcing timely revocation, modification, and validation of system access and credentials. These actions ensure the confidentiality, integrity, and availability of CUI in compliance with NIST SP 800-171r3 Control Family 3.9 and the UT-Austin CRSP 3.0 CUI Governance Policy.
Termination of Employment When an individual’s employment or affiliation with U. T. Austin is terminated, the following actions are taken:
- System Access Revocation: All logical and physical access to information systems, networks, and facilities is disabled within 4 hours upon notification or sooner if security risk dictates.
- Authenticator and Credential Termination: All authenticators, including hardware tokens, passwords, smart cards, and digital certificates, are revoked or terminated immediately.
- Retrieval of Security-Related Property: All system-related and security property—including identification badges, hardware tokens, system manuals, keys, and building passes—is collected and accounted for.
- Exit interviews are conducted whenever feasible to reinforce ongoing security obligations, including nondisclosure agreements and employment-related restrictions. When exit interviews are not possible, compensating controls are applied to maintain protection of CUI.
- Reassignment or Transfer of Personnel When individuals are reassigned or transferred to new roles or positions within U. T. Austin, the following measures are implemented:
- Access Review: Current logical and physical access authorizations are reviewed and validated to ensure alignment with the individual’s ongoing operational need for access to systems, data, and facilities.
- Access Modification: Access rights and privileges are modified as appropriate to reflect the new operational role, ensuring that personnel retain only the minimum necessary access required for their updated responsibilities.
Note: These measures ensure that CUI remains protected throughout personnel lifecycle events, including terminations, reassignments, and transfers, in compliance with federal, state, and institutional security requirements, including TAC 202 and DIR security control guidance.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| System Owner | Project Participants (PP) / Principal Investigators | Review and authorize system-specific access removal or modification; ensure access aligns with updated operational needs.; Notify IT and security teams of personnel terminations, reassignments, or transfers; coordinate exit interviews; ensure return of physical property and assets.; Collect and account for physical security items, including badges, keys, hardware tokens, and system manuals.; Confirm operational need for system access during transfers; communicate changes to HRO, ISSO, and ISO; ensure personnel comply with return of credentials and property. |
| Policy Owner | Information Security Office (ISO) | Validate timely revocation of system access and credentials; approve modifications of access for reassigned personnel; maintain records of access changes. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Disable system accounts, revoke authenticators (passwords, smart cards, tokens, digital certificates); modify access privileges for reassigned personnel. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Review adherence to access revocation, modification, and property retrieval procedures; provide corrective actions if gaps are identified. |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Coordinates with Human Resources and legal counsel on background screening requirements and separation workflows. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Establishes CRE personnel security policy; defines screening levels; oversees termination revocation procedures and security debriefing requirements. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Executes CRE access revocation within required timelines; ensures all accounts and credentials are disabled upon separation notification. |
| Research Coordination | Research Security Office (RSO) | Conducts security debriefings at termination; advises on contract-specific screening requirements; monitors insider threat indicators. |
| System Owner | Project Participants (PP) / Principal Investigators | Initiates access requests and termination notifications; responsible for notifying ISO within the required timeframe upon personnel separation or role change. |
CRSP Standard 3.10: Physical Protection (PE)
NIST SP 800-171 Rev. 3, Family 3.10
U. T. Austin shall restrict physical access to CUI systems and the CRE secure areas in which they reside to authorized individuals, monitor and log physical access, and manage visitors under continuous escort. CRE physical protection requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.10 Physical Protection (PP) Policy
03.10.01 Physical Access Authorization. (See IRUSP §16) U. T. Austin enforces strict physical access authorizations to all facilities and areas housing systems that store, process, or transmit CUI within the CRE. Access is granted only to individuals explicitly authorized through a formal approval process and based on their assigned roles and operational need.
Authorized personnel are issued credentials such as university-issued smart cards, badges, physical keys, or biometric authentication devices, and access is restricted to designated areas consistent with job responsibilities. Sensitive areas, including data centers, communication closets, and research laboratories, are secured using multi-layered access control measures.
U. T. Austin maintains a centralized access authorization list, which is reviewed and updated at least annually, or whenever there are significant security incidents or changes to organizational risk. Individuals who no longer require access—due to separation, transfer, or role change—have their credentials revoked within one business day to prevent unauthorized access.
U. T. Austin employs monitoring, logging, and periodic auditing to ensure compliance with access authorization requirements and to detect and respond to any unauthorized attempts to access controlled areas.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Provides oversight for enforcement of physical access policies in research environments.; Approves and maintains access authorization policies; ensures compliance with federal and institutional requirements.; Issue and control physical access credentials; enforce entry procedures; maintain logs of access activity. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensures access lists for systems containing CUI are accurate and updated; approves additions or removals.; Notify ISO and Facilities Personnel of personnel changes affecting access; ensure access aligns with role assignments.; Comply with assigned access privileges; report any suspected unauthorized access. |
03.10.02 Monitoring Physical Access. (See IRUSP §16) U. T. Austin monitors physical access to facilities and areas housing systems that store, process, or transmit CUI within the CRE to detect and respond to unauthorized access or other physical security incidents.
Physical access monitoring is implemented using a combination of video surveillance, access logs, motion detection, intrusion alarms, and security personnel. Critical infrastructure areas, including data centers, server rooms, communication closets, and research laboratories, are secured using controlled entry points and monitored continuously.
Access logs and monitoring data are reviewed at least every 45 days and immediately following significant, novel, or high-risk security events to identify and respond to unauthorized activity. Any suspicious or unauthorized access detected triggers follow-up actions, including investigation, remediation, and reporting in accordance with U. T. Austin incident response procedures.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Provides oversight for the monitoring of physical access to CRE facilities.; Ensures monitoring strategies comply with federal and institutional physical security requirements; approves procedures.; Monitors physical access alerts and logs; coordinates with facilities and security teams to investigate anomalies.; Maintain and operate access control systems, surveillance, and logging; escalate incidents to ISSO and ISO as needed.; Report any observed unauthorized access or physical security concerns. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensures access logs for systems processing CRE CUI are collected, maintained, and reviewed.; Investigates incidents detected through monitoring and ensures appropriate response and documentation. |
03.10.06 Alternate Work Site. (See IRUSP §16) U. T. Austin establishes and enforces requirements for alternate work sites to ensure the security of CRE CUI when accessed outside primary U. T. Austin facilities. Alternate work sites must provide adequate security comparable to organizational standards, where practical, and comply with institutional policies covering physical protection, information handling, and environmental safeguards.
Employees accessing CRE CUI remotely or at alternate locations must use U. T. Austin-managed devices with full disk encryption, secure virtual private networks (VPNs), strong authentication mechanisms, and automatic screen lock or session timeout features. CRE CUI must not be stored, printed, or viewed in unsecured or public areas. Personnel must receive training on security requirements for remote work, acknowledge responsibilities, and obtain pre-authorization prior to accessing CRE CUI at alternate work sites.
Security compliance at alternate work sites is monitored, and incidents are reported and addressed according to U. T. Austin incident response procedures.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Provides oversight of alternate work site security compliance for CRE personnel.; Approves alternate work site security requirements; ensures alignment with institutional and federal guidance.; Monitors adherence to security requirements at alternate work sites; coordinates training and guidance. |
| System Owner | Project Participants (PP) / Principal Investigators | Authorizes and documents approved alternate work sites; ensures systems used at alternate sites comply with security requirements.; Access CRE CUI only at approved alternate work sites; follow all security requirements and report incidents. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Ensure remote access solutions, device security, and VPNs are configured according to policy. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Provide training on security requirements for alternate work sites; maintain training records. |
03.10.07 Physical Access Control. (See IRUSP §16) U. T. Austin enforces strict physical access control measures to protect facilities housing systems that store, process, or transmit CUI within the CRE. Access to these facilities is restricted to authorized personnel only, and all individuals must present approved credentials and be verified prior to entry.
Physical access points, including entry and exit doors, gates, and secure workspaces, are controlled through badge readers, biometric systems, staffed security posts, or other approved mechanisms. Access is logged and monitored continuously to detect and respond to unauthorized access attempts.
Visitors are escorted at all times, and visitor activity is documented and monitored to ensure compliance with facility security requirements. Keys, combinations, and other physical access devices are secured and managed to prevent misuse. Physical access to output devices containing or processing CRE CUI is controlled to prevent unauthorized individuals from obtaining sensitive information.
Audit logs of all access events are maintained and reviewed periodically to detect anomalies, enforce accountability, and support investigations in the event of security incidents.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Provides oversight for physical access control compliance in CRE facilities.; Approves physical access control strategies and ensures alignment with institutional and federal requirements.; Monitors access logs, reviews anomalies, and coordinates with facilities/security teams to enforce physical access controls.; Operate and maintain access control systems, secure keys and devices, monitor ingress/egress points, and escort visitors.; Support monitoring of physical access events for potential security incidents. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Coordinates physical access control implementation within research environments; ensures visitor escort procedures are followed.; Authorizes personnel access lists; reviews and approves facility access levels; ensures access aligns with operational requirements. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Ensure output devices are physically secured and monitor access to critical CRE systems. |
| System Owner | Project Participants (PP) / Principal Investigators | Use access credentials properly, follow entry/exit procedures, and report any suspicious or unauthorized access attempts. |
03.10.08 Access Control for Transmission. (See IRUSP §16) U. T. Austin implements physical access controls to protect system distribution and transmission lines that carry CUI within CRE facilities. All cabling, wiring closets, network distribution panels, and other transmission infrastructure are secured against unauthorized physical access, tampering, or accidental disruption.
Access to transmission lines and network distribution points is restricted to authorized personnel only, with entry controlled through locks, badge readers, or other approved physical security mechanisms. Audit logs and monitoring systems are maintained to detect unauthorized access, cable tampering, or environmental incidents that could compromise the confidentiality, integrity, or availability of CUI within the CRE.
Personnel are trained to follow secure handling practices when accessing or maintaining transmission infrastructure, and any changes or interventions are documented and approved in accordance with configuration and change management policies.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approves security strategies for transmission line protection and ensures compliance with institutional and federal requirements.; Monitors access to network transmission points; reviews logs for unauthorized access; coordinates remediation actions.; Operate and maintain physical controls on wiring closets and network distribution panels; verify access credentials; secure keys and entry devices.; Monitor physical access events to network infrastructure; analyze anomalies and support incident response. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Coordinates protection of transmission infrastructure in research areas; ensures compliance with access control procedures.; Authorizes personnel access to transmission lines; reviews physical protection measures and ensures security requirements are met. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Ensure that access to transmission lines is restricted and changes are documented; implement monitoring and detection tools.; Maintain secure configurations for network distribution systems; enforce access controls on critical transmission infrastructure. |
| System Owner | Project Participants (PP) / Principal Investigators | Access transmission infrastructure only when authorized; follow approved procedures and report any security concerns. |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides institutional authority for CRE facility security requirements and coordinates with Facilities Services on physical controls. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Establishes physical protection policy for CRE areas; reviews physical access logs; oversees visitor management procedures and anti-tailgating controls. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Manages electronic access control systems for CRE areas; maintains access device inventory; provisions and revokes physical access credentials. |
| Research Coordination | Research Security Office (RSO) | Advises on physical security requirements for research labs handling CUI; coordinates foreign visitor reviews with appropriate authorities. |
| System Owner | Project Participants (PP) / Principal Investigators | Controls physical access authorizations for research personnel in CRE areas; initiates visitor requests and provides or designates escorts. |
CRSP Standard 3.11: Risk Assessment (RA)
NIST SP 800-171 Rev. 3, Family 3.11
U. T. Austin shall periodically assess the risks to CUI systems and the information they contain, perform vulnerability scanning at defined intervals, and remediate identified vulnerabilities according to defined timelines based on risk severity. CRE risk assessment requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.11 Risk Assessment (RA) Policy
03.11.01 Risk Assessment. (See IRUSP §10) The University of Texas at Austin (U. T. Austin) establishes and maintains a structured Risk Assessment Policy to identify, evaluate, and manage risks associated with the processing, storage, and transmission of Controlled Unclassified Information (CUI) within the Controlled Research Environment (CRE), including risks arising from the supply chain.
U. T. Austin shall:
- Conduct Systematic Risk Assessments – Identify threats, vulnerabilities, and potential impacts to CUI within CRE systems and processes. Assessments shall include risks introduced by third-party service providers, vendors, or other supply chain dependencies affecting the CRE.
- Update Assessments – Review and update risk assessments at least annually, or whenever significant changes occur to CRE systems, processes, technologies, or the threat environment.
- Integrate Risk Findings – Use risk assessment results to inform the selection and implementation of security controls, resource allocation, and mitigation strategies for CRE systems and CUI.
- Document and Report – Maintain comprehensive documentation of risk assessment activities, results, and mitigation actions for CRE systems, ensuring accountability, traceability, and compliance with federal, state, and institutional requirements.
Note: This policy reinforces U. T. Austin’s commitment to protecting CUI within the CRE, mitigating risks of unauthorized disclosure, and ensuring compliance with NIST SP 800-171r3 and the UT-Austin CRSP 3.0 CUI Governance Policy.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Accountable for the enterprise-wide risk assessment program within the CRE; approve methodology, scope, and frequency; Support system-level risk assessments within the CRE; identify vulnerabilities and recommend remediation actions |
| System Owner | Project Participants (PP) | Conduct or coordinate system-level risk assessments for CRE systems; integrate findings into risk management decisions; Report identified risks affecting CRE research systems or CUI; ensure research activities comply with risk management requirements |
| Technical Implementation | Controlled Research Support Program (CRSP) | Identify risks specific to CUI under their stewardship; provide input on system-level threats and vulnerabilities |
| Program Authority | Office of Research Support and Compliance (ORSC) | Coordinate risk assessment activities within research units; ensure CRE risk assessment practices align with sponsor requirements |
03.11.02 Vulnerability Monitoring and Scanning. (See IRUSP §10) U. T. Austin establishes and maintains a structured Vulnerability Monitoring and Risk Response Program to identify, assess, and remediate risks to CUI and associated systems within the CRE. This program ensures vulnerabilities are detected, prioritized, and addressed in a timely manner, consistent with NIST SP 800-171r3 and the UT-Austin CRSP 3.0 CUI Governance Policy.
All vulnerability monitoring and scanning activities support the confidentiality, integrity, and availability of CUI while integrating with enterprise risk management, continuous monitoring, and compliance processes.
Key Requirements:
- Perform Regular Vulnerability Scans – Conduct vulnerability scans at least monthly, after significant incidents or operational changes, and whenever new vulnerabilities are identified affecting CRE systems.
- Maintain Up-to-Date Scan Data – Update vulnerability signatures and configurations no more than 24 hours prior to scanning and immediately upon release of new authoritative vulnerability information.
- Remediate Vulnerabilities by Risk Level – Identified vulnerabilities are remediated according to severity:
- High-risk (critical and high): within 30 days from discovery
- Moderate-risk: within 90 days from discovery
- Low-risk: within 180 days from discovery
- Integration with Risk Management – Review scan results and remediation actions; incorporate findings into enterprise risk management processes and Plan of Action and Milestones (POA&M) for CRE systems.
- Documentation and Oversight – Maintain records of scan results, remediation actions, and updates to support compliance, audit, and governance requirements.
- This policy demonstrates U. T. Austin’s commitment to protecting CUI in the CRE, mitigating security risks, and maintaining compliance with federal, state, and institutional requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Accountable for the CRE Vulnerability Monitoring and Risk Response Program; approve risk response strategies, remediation prioritization, and timelines.; Review CRE system vulnerabilities, recommend remediation actions, and monitor mitigation progress; verify resolution aligns with policy.; Support research unit compliance with CRE vulnerability remediation requirements; coordinate risk response for research systems. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure CRE system vulnerabilities are addressed; approve and implement mitigation measures; validate effectiveness of remediation.; Report observed risks affecting CRE research systems or CUI; ensure remediation actions are applied within research operations.; Report observed risks or incidents that could affect CUI in CRE; participate in remediation activities as directed. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Execute remediation measures including patching, configuration updates, and system changes on CRE systems; verify and document fixes. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Provide input on the impact of CRE system vulnerabilities on data confidentiality, integrity, and availability; support mitigation planning and execution.; Coordinate risk response activities for CRE systems; maintain risk register; track remediation status and prioritize based on institutional risk tolerance. |
03.11.04 Risk Response. (See IRUSP §10) U. T. Austin establishes and maintains a structured Risk Response Program to ensure that findings from security assessments, monitoring, audits, and other risk evaluation activities are effectively addressed within the CRE. This program ensures that risks to CUI and associated CRE information systems are identified, assessed, prioritized, and mitigated according to institutional risk tolerance, timelines, and compliance requirements.
The Risk Response Program aligns with NIST SP 800-171r3 and the UT-Austin CRSP 3.0 CUI Governance Policy, reinforcing U. T. Austin’s commitment to safeguarding the confidentiality, integrity, and availability of CUI in the CRE.
U. T. Austin shall:
- Assess Findings – Review all findings from risk assessments, vulnerability monitoring, audits, and security evaluations to determine potential impacts to CUI within the CRE.
- Prioritize Risks – Evaluate findings based on severity, likelihood, and potential operational or compliance impact to ensure that resources are applied effectively.
- Remediate, Mitigate, or Accept Risks – Implement documented and approved risk response actions, including remediation, mitigation, or acceptance, according to institution-defined timelines.
- Integrate with Governance – Incorporate risk response activities into enterprise risk management workflows, system security planning, and continuous monitoring programs for CRE systems.
- Document and Track Actions – Maintain comprehensive records of all findings, risk response decisions, and mitigation activities to support audit, oversight, and compliance reporting.
Note: This policy supports U. T. Austin’s commitment to maintaining the security of CUI within the CRE, mitigating threats, and ensuring compliance with federal, state, and institutional requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve risk response strategies; ensure alignment with institutional, state, and federal security requirements; oversee enterprise-wide CRE risk response efforts.; Coordinate system-level CRE risk response; track findings; recommend remediation or mitigation actions; document and monitor responses.; Report observed vulnerabilities, incidents, or suspicious activity affecting CRE systems; follow guidance for remediation and mitigation. |
| System Owner | Project Participants (PP) / Principal Investigators | Oversee and implement risk response actions for CRE systems under their control; ensure findings from assessments, monitoring, and audits are addressed. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Execute technical remediation measures (e.g., patch deployment, configuration updates, system changes) on CRE systems; validate effectiveness of implemented actions. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Support prioritization of risk responses based on enterprise CRE risk assessment results; maintain the institutional risk register; integrate responses into enterprise risk management processes. |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides institutional oversight for CRE risk posture; ensures risk assessment activities are resourced and findings acted upon. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Establishes risk assessment methodology, scanning schedule, and remediation timelines; approves risk acceptance requests jointly with system owners; maintains CRE risk register. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Executes vulnerability scans; reports findings; tracks remediation; maintains scan records in the CRE POA&M; implements approved risk response actions. |
| Research Coordination | Research Security Office (RSO) | Incorporates research-specific threat intelligence into risk assessments; communicates risk findings to PIs in the context of research obligations. |
| System Owner | Project Participants (PP) / Principal Investigators | Provides system context for risk assessments; accepts or escalates residual risks; prioritizes remediation within project resources. |
CRSP Standard 3.12: Security Assessment (CA)
NIST SP 800-171 Rev. 3, Family 3.12
U. T. Austin shall assess the security controls implemented in CUI systems to determine control effectiveness, document assessment findings, develop Plans of Action and Milestones (POA&M) to address deficiencies, and maintain current System Security Plans. CRE security assessment requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.12 Security Assessment (CA) Policy
03.12.01 Security Assessment. (See IRUSP §10; IRUSP §3) The University of Texas at Austin (U. T. Austin) ensures that all information systems processing, storing, or transmitting Controlled Unclassified Information (CUI), including systems within the Controlled Research Environment (CRE), undergo security assessments at least every 12 months, or whenever significant incidents, system changes, or risk-altering events occur. These assessments verify that security requirements are effectively implemented, operating as intended, and aligned with federal, state, and institutional compliance obligations.
U. T. Austin maintains a structured Security Assessment Program to evaluate the adequacy and effectiveness of technical, administrative, and physical safeguards, and to identify deficiencies or vulnerabilities that could impact the confidentiality, integrity, or availability of CUI.
- Key Requirements: Assessment Scope: All system components, configurations, and operational environments supporting CUI are included in security assessments. This includes on-premises and cloud-based infrastructure, applications, databases, and supporting services, as well as CRE-specific research systems.
Assessment Frequency: Security assessments are conducted at least annually, upon significant incidents, or when changes to systems, processes, or the threat environment occur. Frequency may be adjusted based on organizational risk tolerance, system criticality, or regulatory mandates.
Assessment Methodology: Assessments follow defined procedures, including control testing, evidence collection, and compliance verification, in alignment with NIST SP 800-171, the UT-Austin CRSP 3.0 CUI Governance Policy, and other applicable federal and institutional standards.
Documentation and Reporting: Results—including findings, deficiencies, and associated risks—are documented and used to update the System Security Plan (SSP) and Plan of Action and Milestones (POA&M) to maintain a current, accurate security posture.
Continuous Improvement: Assessment outcomes inform risk mitigation strategies, procedural updates, and continuous monitoring activities to maintain and enhance the security posture of all CUI systems.
Note: This policy ensures a repeatable, evidence-based approach to assessing system security and supports compliance with NIST SP 800-171, UT-Austin CRSP 3.0 CUI Governance Policy, and other applicable federal and institutional requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee the Security Assessment Program; ensure alignment with institutional policy, NIST SP 800-171 and UT-Austin CRSP 3.0 CUI Governance Policy; Coordinate assessments, maintain schedules and records, track remediation actions, ensure findings are addressed |
| System Owner | Project Participants (PP) / Principal Investigators | Prepare systems for assessment, provide documentation, support assessors, and validate system-specific security controls; Review assessment results; ensure corrective actions are tracked in POA&Ms; confirm compliance with federal and institutional requirements; Provide required information and access for assessments; implement system-specific security guidance as directed |
| Program Authority | Office of Research Support and Compliance (ORSC) | Conduct objective evaluation of system controls, review evidence, and verify compliance |
| Technical Implementation | Controlled Research Support Program (CRSP) | Support assessment activities by providing access to systems, logs, configurations; assist in implementing recommendations |
03.12.02 Plans of Action and Milestones (POA&M). (See IRUSP §10; IRUSP §3) U. T. Austin develops, maintains, and enforces a structured Plan of Action and Milestones (POA&M) process for all information systems processing, storing, or transmitting CUI within the CRE.
The POA&M provides a documented roadmap for remediating security weaknesses and reducing or eliminating system vulnerabilities identified through security assessments, audits, or continuous monitoring activities.
- Key Requirements: Development:
- Document all planned remediation actions to correct deficiencies identified during security assessments.
- Track actions taken to reduce or eliminate known system vulnerabilities.
- Updating:
- Review and update the POA&M following findings from security assessments, audits, or continuous monitoring activities.
- Ensure updates reflect current risk posture, system changes, and regulatory requirements.
- Documentation and Reporting:
- Maintain POA&M items with assigned responsibility, milestones, and expected completion dates.
- Use POA&M results to inform risk management decisions and support compliance with NIST SP 800-171, UT-Austin CRSP 3.0 CUI Governance Policy, and other applicable federal and institutional requirements.
Note: This policy ensures a repeatable, accountable, and evidence-based approach to identifying, tracking, and remediating security weaknesses across all CRE-relevant systems.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee the POA&M process; ensure alignment with institutional policy, Federal and State regulatory requirements; Maintain and monitor the POA&M; track progress of remediation efforts; verify closure of completed actions; update POA&M records; Validate that POA&M items are appropriately addressed; confirm corrective actions are implemented and deficiencies remediated |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure POA&M entries for systems under their control are accurate, actionable, prioritized, and resourced; coordinate remediation activities; Review POA&M items to ensure compliance with federal, state, and institutional requirements; support prioritization and risk management decisions; Execute assigned remediation tasks as documented in the POA&M; report status to system owners or ISSO |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement corrective actions as documented in POA&M; support verification of remediation; provide evidence of mitigation activities |
03.12.03 Continuous Monitoring. (See IRUSP §10; IRUSP §3) U. T. Austin develops, implements, and maintains a comprehensive Continuous Monitoring Strategy (CMS) for all information systems that process, store, or transmit CUI within the CRE.
The CMS ensures ongoing evaluation of security controls, timely identification of vulnerabilities, threats, and changes in risk posture, and supports the continuous protection of CUI in accordance with NIST SP 800-171, UT-Austin CRSP 3.0 CUI Governance Policy, and applicable federal and institutional requirements.
- Key Requirements: Strategy Development:
- Establish a system-level continuous monitoring program defining scope, processes, tools, and personnel responsibilities.
- Integrate monitoring with security assessments to evaluate control effectiveness, detect security events, and identify emerging risks.
- Implementation:
- Continuously monitor system components, configurations, and operational environments supporting CUI, including on-premises and cloud infrastructure.
- Employ automated tools, alerts, and dashboards to detect anomalies, vulnerabilities, or unauthorized activity in near real-time.
- Coordinate monitoring activities with security assessments, audits, and incident response procedures to maintain a cohesive security posture.
- Documentation and Reporting:
- Document monitoring procedures, findings, and results to support risk management and continuous improvement.
- Integrate monitoring outcomes with System Security Plans (SSPs), Plan of Action and Milestones (POA&M), and ongoing security assessments.
Note: This policy ensures that U. T. Austin maintains a proactive, risk-based approach to continuously assess and improve the security posture of all systems handling CUI, supporting compliance with NIST SP 800-171, UT-Austin CRSP 3.0 CUI Governance Policy, and federal cybersecurity requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee the CMS; ensure alignment with institutional security goals; report findings to executive leadership; Ensure their systems are incorporated into the CMS; provide required system access and data; support remediation actions |
| System Owner | Project Participants (PP) / Principal Investigators | Manage monitoring tools and dashboards; track findings; coordinate remediation; maintain documentation of monitoring activities; Ensure CMS activities meet regulatory and institutional requirements; review monitoring reports for compliance and risk mitigation; Report anomalies or suspicious activity detected in day-to-day operations |
| Technical Implementation | Controlled Research Support Program (CRSP) | Execute technical monitoring tasks; analyze alerts; respond to anomalies; escalate incidents per procedures |
| Program Authority | Office of Research Support and Compliance (ORSC) | Validate that continuous monitoring controls are effective; review CMS documentation and outcomes |
03.12.05 Information Exchange. (See IRUSP §10; IRUSP §3) U. T. Austin establishes and maintains formal procedures to govern the exchange of CUI between U. T. Austin systems and external or internal systems, including those operating within or interfacing with the CRE.
All information exchanges involving CUI must be formally approved, documented, and monitored to ensure that CUI is protected in accordance with NIST SP 800-171, the UT-Austin CRSP 3.0 CUI Governance Policy, and other applicable federal, state, and institutional requirements.
Key Requirements
- Approval and Management: All exchanges of CUI must be approved prior to implementation using formal agreements such as:
- Interconnection Security Agreements (ISA)
- Information Exchange Security Agreements (IESA)
- Memoranda of Understanding or Agreement (MOU/MOA)
- Service-Level Agreements (SLA)
- User Agreements
- Non-Disclosure Agreements (NDA)
- Other organization-defined agreements as appropriate.
- Agreements must clearly define the type, scope, and purpose of the information exchange, as well as security requirements and responsibilities for each participating system or organization.
- Documentation
- Interface characteristics, system interconnections, data flows, and security requirements must be documented for every exchange involving CUI.
- Documentation must include roles, responsibilities, encryption or protection requirements, data handling expectations, and incident reporting procedures.
- All documentation must be maintained in a version-controlled repository and made available for audits, security assessments, and incident investigations.
- Review and Updates
- Exchange agreements must be reviewed and updated at least annually, or more frequently when significant changes occur including:
- System architecture or configuration changes
- Changes in data sensitivity or classification
- Regulatory or contractual requirement updates
- Organizational risk posture changes
- Updated agreements must be reapproved by authorized officials and communicated to all affected stakeholders.
- Continuous Oversight and Improvement
- Monitoring of CUI exchanges and periodic agreement reviews are integrated into risk management processes, security assessments, continuous monitoring activities, and Plan of Action and Milestones (POA&M) tracking to ensure continued protection of CUI.
Note: This policy ensures that U. T. Austin consistently enforces secure, documented, and compliant exchanges of CUI, protecting the confidentiality, integrity, and availability of information while maintaining adherence to federal, state, and institutional governance requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve CUI exchange agreements; ensure compliance with institutional policies, federal regulations, TAC, and DIR standards; Maintain records of approved exchanges; coordinate reviews and updates; verify enforcement of security requirements |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure systems under their control comply with approved exchange agreements; provide documentation; implement required security controls; Review exchange agreements for regulatory compliance; oversee governance and ensure procedures are followed; Follow established procedures for handling and transmitting CUI; report suspected breaches, policy violations, or non-compliance |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement and maintain technical configurations supporting secure CUI exchanges; monitor interfaces and system connections; report deviations or incidents |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides authority for CMMC certification decisions; ensures institutional resources are available to resolve POA&M deficiencies. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Owns the CRE assessment program; maintains SSP templates; oversees POA&M status; coordinates third-party assessment engagements. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Executes technical control assessments; collects assessment evidence; maintains continuous monitoring data and POA&M tracking records. |
| Research Coordination | Research Security Office (RSO) | Advises on assessment scope for research-specific systems; coordinates with federal sponsors on assessment evidence sharing obligations. |
| System Owner | Project Participants (PP) / Principal Investigators | Reviews and approves SSP content for systems under their authority; owns POA&M remediation items within project scope. |
CRSP Standard 3.13: System and Communications Protection (SC)
NIST SP 800-171 Rev. 3, Family 3.13
U. T. Austin shall monitor, control, and protect communications at the external and key internal boundaries of CUI systems, encrypt CUI at rest and in transit using validated cryptographic mechanisms, and enforce boundary protections that prevent unauthorized access to the CRE. CRE system and communications protection requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.13 System and Communications Protection (SC) Policy
03.13.01 Boundary Protection. (See IRUSP §13; IRUSP §11) U. T. Austin employs a multi-layered Boundary Protection Framework to monitor, control, and secure communications at system boundaries, ensuring the confidentiality, integrity, and availability of CUI within the CRE.
Key components include:
- Enterprise Firewalls: Configured with default-deny policies, permitting only explicitly authorized ports, protocols, and IP addresses; applied at external and internal network boundaries.
- Intrusion Detection and Prevention Systems (IDS/IPS): Deployed to detect, alert, and respond to anomalous or unauthorized network activity.
- Internal Segmentation: VLANs and internal segmentation firewalls isolate sensitive environments, including research networks and CUI systems, from general university networks.
- Centralized Logging and Alerting: Firewall and IDS/IPS events are aggregated into security monitoring tools for continuous review, analysis, and incident response.
- Configuration Management and Review: Boundary protection rules, device configurations, and access policies are regularly reviewed and updated to reflect operational changes, emerging threats, or compliance requirements.
Note: This framework ensures all communications into, out of, and within U. T. Austin systems are controlled, monitored, and safeguarded against unauthorized access or exfiltration of CUI. The policy aligns with NIST SP 800-171, Control Family 3.13, the UT-Austin CRSP 3.0 CUI Governance Policy, and federal cybersecurity standards.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce boundary protection policies; approve configuration standards; Monitor boundary devices, review alerts, report anomalies, and verify compliance with policy; Review logs, alerts, and incident reports from network monitoring tools; escalate issues as needed; Aggregate, analyze, and monitor security events; coordinate incident response with ISSO and ISO |
| System Owner | Project Participants (PP) / Principal Investigators | Implement and maintain boundary protections for assigned CRE CUI systems; ensure proper firewall and IDS/IPS configurations |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure, deploy, and maintain firewalls, IDS/IPS, and network devices according to approved standards |
| Program Authority | Office of Research Support and Compliance (ORSC) | Audit boundary protection controls, configurations, and monitoring effectiveness; recommend corrective actions; Provide training on boundary protection policies, device handling, and monitoring procedures to relevant personnel |
03.13.04 Information in Shared System Resources. (See IRUSP §13; IRUSP §11) U. T. Austin implements controls to prevent unauthorized or unintended disclosure of CUI through shared system resources within the CRE. Shared resources include network drives, file shares, databases, printers, virtualized environments, and other multi-user systems.
U. T. Austin requires that:
- Access Control: Only authorized personnel may access shared resources containing CUI. Access is granted based on role, operational need, and the principle of least privilege.
- Segregation of CUI: CUI must be separated from non-sensitive or public information using directories, permissions, and other system-level controls to prevent accidental or unauthorized exposure.
- Configuration and Permissions Management: System configurations, file permissions, and access rights are reviewed and updated regularly to ensure compliance with security policies.
- Monitoring and Auditing: Shared resources are continuously monitored and periodically audited to detect potential unauthorized transfers or leakage of CUI.
- Personnel Training: Users with access to shared resources containing CUI receive training on secure access practices, acceptable use, and procedures for reporting suspected unauthorized access or information transfer.
- Policy Documentation and Review: Procedures for managing shared resources are documented, maintained, and reviewed periodically to ensure compliance with UT-Austin CRSP 3.0 CUI Governance Policy, federal requirements, and institutional security standards.
Note: This policy ensures that shared system resources are controlled, monitored, and managed to reduce the risk of unauthorized disclosure, accidental leakage, or compromise of CUI within the CRE.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| System Owner | Project Participants (PP) / Principal Investigators | Implement access controls, separation, and permissions for shared resources containing CRE CUI; Access shared resources only according to approved permissions; report suspected unauthorized activity |
| Policy Owner | Information Security Office (ISO) | Monitor shared resources, detect potential unauthorized access or data leakage, and report findings; Audit shared resource configurations and access controls; recommend corrective actions |
| Technical Implementation | Controlled Research Support Program (CRSP) | Enforce system-level permissions, resource segmentation, and virtualization isolation; maintain configuration baselines |
03.13.06 Network Communications – Deny by Default – Allow by Exception. (See IRUSP §13; IRUSP §11) U. T. Austin enforces a “deny by default, allow by exception” approach to network communications within the CRE to protect CUI.
All network traffic is denied unless explicitly authorized based on documented business needs, risk assessments, and compliance with institutional and federal cybersecurity standards. Exceptions must be formally requested, reviewed, approved, documented, and periodically reevaluated to ensure ongoing compliance with operational and security requirements.
Note: This policy ensures that network communications are proactively controlled, minimizing risks of unauthorized access, data exfiltration, or compromise of CUI, and enforces strict governance over all communications within CRE systems.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve all network communication exceptions; review exception requests for operational necessity and risk; ensure alignment with institutional and federal cybersecurity standards; Monitor network traffic for unauthorized or anomalous communications; review logs and alerts from exception rules; report findings to CISO and ISO |
| System Owner | Project Participants (PP) / Principal Investigators | Request and justify exceptions; validate necessity for system operations; coordinate implementation with IT/Network Administrators; Ensure any requested network communications requiring exception are submitted through proper channels; follow institutional guidance regarding authorized communications |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure firewalls, routers, and other network devices to enforce deny-by-default rules; implement approved exceptions; maintain logs and monitor exception traffic; Review and approve changes to network communication rules affecting exceptions; ensure risk assessment and impact analysis are documented |
| Program Authority | Office of Research Support and Compliance (ORSC) | Audit exception approvals, configuration enforcement, and monitoring processes; verify compliance with UT-Austin CRSP 3.0 CUI Governance Policy and federal standards |
03.13.08 Transmission Confidentiality. (See IRUSP §13; IRUSP §11) U. T. Austin enforces the use of FIPS-validated cryptographic mechanisms to ensure the confidentiality of CRE CUI during transmission and storage.
All CRE CUI transmitted outside physically protected boundaries or across shared, untrusted, or public networks must be protected using approved cryptographic protocols in accordance with federal and institutional requirements.
For CRE CUI stored on information systems, removable media, portable devices, or backup repositories:
- Encryption using FIPS-validated modules is required to prevent unauthorized access or disclosure.
- Where Protected Distribution Systems (PDS) or other dedicated physical protections are deployed, compensating controls and justifications must be documented in the System Security Plan (SSP).
- U. T. Austin enforces key management controls—covering generation, distribution, rotation, storage, revocation, and destruction—through the institutional its Key Management Standard, ensuring the confidentiality, integrity, and authorized use of CUI both in transit and at rest.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce cryptographic policy for transmission and storage of CUI; Monitor cryptographic controls; verify proper key usage; report anomalies |
| System Owner | Project Participants (PP) / Principal Investigators | Implement and maintain encryption mechanisms for all systems handling CUI; Use encrypted channels for transmitting or storing CUI; adhere to handling guidelines |
| Technical Implementation | Controlled Research Support Program (CRSP) | Encrypt data in transit and at rest; manage cryptographic keys per policy; apply updates to cryptographic modules |
| Program Authority | Office of Research Support and Compliance (ORSC) | Audit encryption practices, key management processes, and system adherence to policy; Provide role-specific training on encryption usage, handling procedures, and key management |
03.13.09 Session Termination. (See IRUSP §13; IRUSP §11) U. T. Austin enforces automated session termination for all systems within the CRE to ensure communications sessions are promptly disconnected either at session end or after no more than 15 minutes of inactivity.
All network devices, VPN concentrators, application gateways, and supporting security services within the CRE are configured to apply idle-timeout and hard session-termination controls in alignment with NIST SP 800-171 and the UT-Austin CRSP 3.0 CUI Governance Policy.
Upon session termination or timeout:
- Session tokens, TCP/IP ports, and related cryptographic materials are invalidated or released to prevent unauthorized reuse of dormant or abandoned sessions.
- These controls are incorporated into CRE configuration baselines and validated through continuous monitoring and security assessment activities.
- This ensures that network communications within the CRE involving CUI are protected from unauthorized access due to inactive or abandoned sessions.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve policies and procedures for identifier assignment, reuse prevention, and individual categorization.; Review identifier assignment and reuse processes; ensure auditability and traceability of identifiers for accountability. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure that identifiers for systems under their control are assigned according to policy and that reuse prevention measures are enforced.; Authorize identifiers for personnel; classify users by role, status, and organizational affiliation. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement and maintain systems that assign, track, and prevent reuse of identifiers; ensure proper segregation of privileged and non-privileged accounts.; Provide input on identifier assignments for users or devices accessing specific datasets; ensure classification aligns with data stewardship roles. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Use assigned identifiers only for their intended purpose; report any discrepancies or unauthorized use. |
03.13.10 Cryptographic Key Establishment and Management. (See IRUSP §13; IRUSP §11) U. T. Austin establishes and manages cryptographic keys for all systems within the CRE in accordance with institutional and federal guidance. All cryptographic key activities—generation, distribution, storage, access, rotation, and destruction—are designed to maintain the confidentiality, integrity, and availability of CUI.
Key management procedures are:
- Documented, auditable, and regularly reviewed to ensure compliance with institutional policies and federal regulations.
- Integrated into CRE system security plans (SSPs), monitoring, and incident response workflows to maintain continuous protection of CUI.
- Accessible only to authorized personnel with defined operational or business need; all access is recorded and auditable.
- U. T. Austin requires that:
- Cryptographic keys are handled using FIPS 140-3 validated modules or other federally approved standards.
- Key lifecycle management covers generation, distribution, activation, use, rotation, archival, and destruction.
- Keys are rotated or retired based on expiration schedules or upon compromise, consistent with institutional key management procedures.
- Procedures are reviewed and updated regularly to address emerging threats, regulatory changes, and organizational requirements.
- All personnel handling cryptographic keys within the CRE are trained, authorized, and follow secure handling procedures.
- This ensures that all CUI within CRE systems is protected during storage, transmission, and processing using approved cryptographic mechanisms.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce cryptographic key management policies for CRE systems; Monitor CRE key management activities; verify compliance and report anomalies |
| System Owner | Project Participants (PP) / Principal Investigators | Implement cryptographic key generation, distribution, storage, and destruction procedures for CRE systems; Access and use cryptographic keys only as authorized within CRE systems; follow secure handling procedures |
| Technical Implementation | Controlled Research Support Program (CRSP) | Manage cryptographic keys for CRE systems securely; rotate and retire keys as required |
| Program Authority | Office of Research Support and Compliance (ORSC) | Audit CRE key management processes and adherence to policy; recommend corrective actions; Provide training on cryptographic key handling, storage, and destruction for CRE personnel |
03.13.11 FIPS‑Validated Encryption. (See IRUSP §13; IRUSP §11) U. T. Austin enforces the use of FIPS-validated cryptographic mechanisms to protect the confidentiality of CUI at rest and in transit within all systems and communications in the CRE.
All cryptographic implementations—including encryption algorithms, protocols, and key lengths—comply with FIPS standards and institutional guidance. Protections are applied to:
- CUI stored on CRE systems, backup repositories, or portable media.
- CUI transmitted across internal or external networks supporting CRE systems.
- Cryptographic key and certificate operations per U. T. Austin Key Management Standards.
Note: These measures ensure confidentiality, integrity, and secure handling of cryptographic materials in the CRE and across all applicable CUI systems.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce cryptographic protection policies and procedures in alignment with FIPS standards for CRE systems; Implement cryptography for CRE network communications and system storage; monitor cryptographic compliance and perform vulnerability checks; Monitor CRE systems for encryption failures, unauthorized access attempts, or cryptography-related incidents |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure CRE systems implement FIPS-validated cryptography for data at rest and in transit; validate adherence to institutional key management practices; Ensure CRE CUI under their control is encrypted per FIPS standards; coordinate with ISO and IT teams for cryptographic requirements; Use CRE systems in accordance with cryptographic requirements; do not circumvent encryption or handle keys in an unauthorized manner |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure, deploy, and maintain cryptographic mechanisms on CRE systems, including encryption protocols, secure key storage, and certificate management |
| Program Authority | Office of Research Support and Compliance (ORSC) | Provide training on cryptographic policies, FIPS standards, and secure handling of CUI for CRE personnel; Review CRE cryptographic implementation and usage; verify compliance with policies, FIPS standards, and CRSP CUI Governance |
03.13.12 Collaborative Device Controls. (See IRUSP §13; IRUSP §11) U. T. Austin restricts the remote activation of collaborative computing devices and applications within the CRE to prevent unauthorized access, inadvertent data exposure, and compromise of CUI.
Remote activation of such devices is allowed only under strictly defined and justified exceptions, documented in the System Security Plan (SSP), when operationally critical and no alternative exists.
U. T. Austin enforces that:
- Remote activation of collaborative computing devices in the CRE is prohibited unless approved exceptions exist.
- Remote “auto-answer” or “auto-activate” features on cameras, microphones, and smart whiteboards connected to CRE systems are disabled by default.
- Physical indicators (LED lights) or on-screen notices provide explicit notification of device use to all users physically present.
- Device group policies enforce local-user approval prior to activation, and all activity is logged for audit and review.
- This ensures CRE devices cannot be accessed or activated without user consent, preserving confidentiality and integrity of CUI.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce policies governing remote activation of collaborative devices; approve CRE-specific exceptions in SSP; Monitor CRE collaborative device activity for unauthorized remote activation; report anomalies |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure CRE collaborative computing devices implement controls to prohibit unauthorized remote activation; document exceptions in SSP; Approve operationally critical exceptions for CRE collaborative devices involving CUI; verify proper usage indicators are in place; Ensure CRE collaborative devices are used only in accordance with policy; respect device usage indications |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure CRE devices and applications to enforce remote activation restrictions; implement indicators of device use |
| Program Authority | Office of Research Support and Compliance (ORSC) | Provide training to all CRE personnel on CRE-specific policies, approved exceptions, and secure usage practices for collaborative computing devices; Review CRE collaborative device configurations, exception justifications, and usage indicators for compliance |
03.13.13 Mobile Code Management. (See IRUSP §13; IRUSP §11) U. T. Austin enforces controls over the use of mobile code within all systems and communications in the Controlled Research Environment (CRE) to ensure the confidentiality, integrity, and availability of Controlled Unclassified Information (CUI).
All mobile code execution in the CRE must comply with institutional and federal requirements, including:
- Only approved types of mobile code may be executed.
- Mobile code must be authorized, monitored, and executed in secure environments (e.g., sandboxing, secure browsers, endpoint protection).
- Execution and monitoring of mobile code must prevent unauthorized access, code injection, or unintended data disclosure.
- Logs of mobile code execution must be maintained and reviewed to detect anomalies or policy violations.
- This ensures that mobile code does not introduce vulnerabilities or compromise CUI in the CRE.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce mobile code policies and associated procedures specific to CRE; Review logs and monitor mobile code activity in CRE for anomalies; report potential security incidents; Audit CRE mobile code usage, authorization, and monitoring controls; recommend corrective actions |
| System Owner | Project Participants (PP) / Principal Investigators | Define approved mobile code types and technologies for CRE systems; implement controls for authorization, monitoring, and execution; Execute only approved mobile code in CRE systems; report any unauthorized or suspicious code |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure secure environments for mobile code execution (e.g., secure browser settings, whitelisting, endpoint protection); monitor and log CRE mobile code activity; Ensure mobile code used in CRE applications complies with approved standards; submit server-side mobile code for review and authorization |
| Program Authority | Office of Research Support and Compliance (ORSC) | Train CRE personnel, who will use mobile code, on approved mobile code usage, security requirements, and reporting procedures |
03.13.15 Session Authenticity Protection. (See IRUSP §13; IRUSP §11) U. T. Austin enforces session authenticity controls within all CRE systems and communications to ensure the confidentiality, integrity, and availability of CUI.
Session authenticity protections ensure that all communications sessions in the CRE are verified, authorized, and resistant to impersonation, hijacking, or tampering. Controls include:
- Mutual authentication mechanisms such as mutual TLS, digital certificates, or signed tokens for all CUI systems in the CRE.
- Monitoring and validation of session tokens and credentials to prevent unauthorized session use.
- Logging and review of session activity to detect anomalies, failed authentication attempts, or suspicious session behavior.
- Integration with incident response procedures to respond to suspected session compromise.
Note: These measures ensure that communications sessions in the CRE maintain authenticity, prevent unauthorized access, and protect CUI from interception or tampering.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop, review, and enforce policies governing remote activation of collaborative devices; approve CRE-specific exceptions in SSP; Monitor CRE collaborative device activity for unauthorized remote activation; report anomalies |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure CRE collaborative computing devices implement controls to prohibit unauthorized remote activation; document exceptions in SSP; Approve operationally critical exceptions for CRE collaborative devices involving CUI; verify proper usage indicators are in place; Ensure CRE collaborative devices are used only in accordance with policy; respect device usage indications |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure CRE devices and applications to enforce remote activation restrictions; implement indicators of device use |
| Program Authority | Office of Research Support and Compliance (ORSC) | Provide training to all CRE personnel on CRE-specific policies, approved exceptions, and secure usage practices for collaborative computing devices |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides institutional authority for CRE network architecture decisions and resources for encryption infrastructure. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Establishes encryption standards and boundary protection policy; approves cryptographic module use; enforces protocol deprecation timelines. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configures and enforces boundary protections, VPN policies, and encryption on CRE systems; monitors boundary traffic for anomalies; manages cryptographic keys. |
| Research Coordination | Research Security Office (RSO) | Reviews proposed external connections for research collaboration; advises on protocol requirements for data sharing with federal sponsors. |
| System Owner | Project Participants (PP) / Principal Investigators | Identifies required external connections; ensures research systems under their authority use approved encryption; requests interconnection authorizations. |
CRSP Standard 3.14: System and Information Integrity (SI)
NIST SP 800-171 Rev. 3, Family 3.14
U. T. Austin shall identify and remediate CUI system flaws in a timely manner, deploy and maintain protection against malicious code on all CRE endpoints, and monitor systems to detect attacks and unauthorized activity. CRE system and information integrity requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.14 System and Information Integrity (SI) Policy
03.14.01 Flaw Remediation. (See IRUSP §9; IRUSP §8) U. T. Austin ensures that all information systems processing, storing, or transmitting Controlled Unclassified Information (CUI) undergo structured flaw remediation processes to maintain system integrity, prevent exploitation of vulnerabilities, and reduce security risks.
Key requirements include:
- Identification: SOs, ISSOs, and IT personnel proactively identify system flaws, vulnerabilities, and misconfigurations through routine scanning, monitoring, and assessment activities.
- Reporting: Identified flaws are documented, reported promptly to the ISSO and relevant stakeholders, and prioritized based on risk impact to CUI confidentiality, integrity, and availability.
- Correction and Remediation:
- Security-relevant software, firmware, and configuration updates are applied according to risk-based timelines:
- High-risk flaws (critical and high): within 30 days of release
- Moderate-risk flaws: within 90 days of release
- Low-risk flaws: within 180 days of release
- Remediation actions are tracked through the Plan of Action and Milestones (POA&M) or similar tracking mechanisms to ensure timely closure.
- Documentation and Reporting: All flaw remediation activities, including identified vulnerabilities, applied updates, and verification results, are documented and integrated into the system security documentation to support compliance and audit readiness.
- Continuous Improvement: Lessons learned from flaw identification and remediation activities are incorporated into system security procedures, vulnerability management processes, and risk assessments to prevent recurrence.
Note: This policy ensures a proactive, repeatable, and risk-based approach to identifying, reporting, and remediating system flaws, supporting compliance with NIST SP 800-171, the UT-Austin CRSP 3.0 CUI Governance Policy, and other applicable federal requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Identify system flaws and vulnerabilities; ensure remediation actions are planned and executed; provide access for assessments and verification; Apply security-relevant software, firmware, and configuration updates according to risk-based timelines (High: 30 days, Moderate: 90 days, Low: 180 days); verify successful installation; Report observed flaws, misconfigurations, or anomalous system behavior to ISSO or IT personnel |
| System Owner | Project Participants (PP) / Principal Investigators | Receive and document reported flaws; prioritize remediation based on risk; track remediation progress in POA&M; validate corrective actions |
| Technical Implementation | Controlled Research Support Program (CRSP) | Review remediation activities to ensure compliance with federal and institutional requirements; integrate findings into risk management and reporting |
03.14.02 Malicious Code Protection. (See IRUSP §9; IRUSP §8) U. T. Austin establishes a structured Malicious Code Protection Program to ensure that all information systems processing, storing, or transmitting Controlled Unclassified Information (CUI) are safeguarded from viruses, malware, ransomware, and other malicious software that could compromise system integrity, availability, or confidentiality.
Key requirements include:
- Implementation:
- Deploy and maintain malicious code protection mechanisms at all system entry and exit points, including endpoints, servers, network gateways, and cloud services supporting CUI.
- Ensure protection mechanisms detect, block, and eradicate malicious code in real time and during scheduled scans.
- Updates:
- Regularly update malicious code definitions, signatures, and protection software in accordance with configuration management policies to address newly identified threats.
- Apply updates promptly to ensure continued effectiveness of malware defenses.
- Configuration and Scanning:
- Conduct system-wide scans at least weekly.
- Perform real-time scanning of files from external sources at endpoints or system entry/exit points as files are downloaded, opened, or executed.
- Configure systems to automatically block, quarantine, or otherwise mitigate detected malicious code.
- Documentation and Reporting:
- Document all malware detection events, remediation actions, and software updates.
- Integrate findings into System Security Plans (SSPs), Plan of Action and Milestones (POA&M), and continuous monitoring records to support risk management and compliance.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve enterprise malicious code protection policy; ensure alignment with NIST SP 800-171 and institutional security standards; Monitor and validate operational effectiveness of malicious code protections; coordinate incident reporting and response |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure assigned systems incorporate malicious code protections; verify compliance with scanning and update requirements; Ensure data under their stewardship is protected from malicious code risks; support verification of malware protection compliance; Follow institutional guidance for safe computing; avoid unapproved software; report suspicious activity or malware detection immediately |
| Technical Implementation | Controlled Research Support Program (CRSP) | Deploy, configure, and update anti-malware software; perform system scans; monitor alerts; respond to threats; validate remediation actions |
| Program Authority | Office of Research Support and Compliance (ORSC) | Support SI control implementation for research systems handling CUI; ensure malware protections meet federal and institutional standards; Oversee implementation of malicious code protection program across CUI systems; track compliance and effectiveness; Ensure malware detection and remediation activities do not inadvertently expose PII or sensitive information |
03.14.03 Security Alerts, Advisories, and Directives. (See IRUSP §9; IRUSP §8) U. T. Austin establishes a structured program for the ongoing receipt, review, and dissemination of system security alerts, advisories, and directives to ensure that all information systems processing, storing, or transmitting Controlled Unclassified Information (CUI) remain protected against emerging threats and vulnerabilities.
Key requirements include:
- Receipt of External Alerts:
- Continuously monitor trusted external sources, including federal agencies (e.g., CISA, NIST, US-CERT), software and hardware vendors, and industry threat intelligence feeds for security alerts, advisories, and directives relevant to U. T. Austin systems.
- Assess the relevance and potential impact of received advisories on U. T. Austin information systems and CUI.
- Internal Dissemination:
- Generate and distribute internal security alerts, advisories, and directives to appropriate stakeholders, including system owners, IT administrators, ISSOs, and other personnel responsible for system and information integrity.
- Provide guidance for implementing mitigation measures, patches, or procedural changes in response to identified risks.
- Roles and Responsibilities:
- Documentation and Reporting:
- Maintain records of received alerts, advisories, directives, and corresponding actions taken to mitigate associated risks.
- Integrate findings into the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and continuous monitoring program to support ongoing risk management and compliance.
Note: This policy ensures that U. T. Austin maintains a proactive, informed, and responsive approach to emerging security threats, supporting the protection of CUI in compliance with NIST SP 800-171, the UT-Austin CRSP 3.0 CUI Governance Policy, and applicable federal cybersecurity standards.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee the system monitoring program; ensure alignment with institutional policy; report monitoring results and threats to executive leadership; Manage monitoring activities; review alerts and logs; coordinate investigations of suspicious activity; document responses |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure assigned systems are incorporated into monitoring programs; provide access to system logs and metrics; support mitigation actions; Report observed suspicious or anomalous system behavior to ISSO or designated authorities |
| Technical Implementation | Controlled Research Support Program (CRSP) | Operate monitoring tools; review alerts; investigate anomalies; escalate incidents; implement technical mitigations |
| Program Authority | Office of Research Support and Compliance (ORSC) | Ensure monitoring practices meet federal, state, and institutional requirements; review monitoring reports for compliance and risk mitigation |
03.14.08 Information Management and Retention. (See IRUSP §9; IRUSP §8) U. T. Austin establishes and enforces information management and retention practices to ensure that all Controlled Unclassified Information (CUI) is securely maintained, appropriately retained, and properly disposed of in accordance with applicable federal and state laws, Executive Orders, regulations, institutional policies, and operational requirements. These practices ensure the confidentiality, integrity, and availability of CUI throughout its lifecycle.
Key requirements include:
- CUI Storage and Management:
- All CUI, whether stored in on-premises systems, cloud environments, or portable media, must be protected with controls that enforce access restrictions, encryption, and data integrity checks.
- Ensure that system-generated CUI output (reports, exports, or other artifacts) is managed according to the same retention and protection standards as the originating data.
- Retention Requirements:
- CUI must be retained for the period required by applicable federal and state regulations, institutional policies, or operational directives.
- Retention periods must be documented and enforced for each data type and system.
- Access and Use Controls:
- Only authorized personnel may access, modify, or disseminate CUI, in alignment with the principle of least privilege and role-based access controls.
- All actions related to CUI management, including storage, retrieval, and transfer, must be auditable and logged for compliance and accountability.
- Disposition and Destruction:
- Upon reaching the end of the retention period, CUI must be securely destroyed or declassified using approved methods that prevent recovery or unauthorized disclosure.
- Destruction procedures must comply with federal, state, and institutional guidance.
- Documentation and Compliance:
- Retention schedules, management procedures, and audit logs must be maintained and readily available for review by internal and external auditors.
- Regular reviews must be conducted to ensure retention schedules align with updated regulations, policies, and operational requirements.
Note: This policy ensures that U. T. Austin systematically manages the lifecycle of CUI, preserving compliance, operational effectiveness, and the confidentiality, integrity, and availability of sensitive information in accordance with NIST SP 800-171, the UT-Austin CRSP 3.0 CUI Governance Policy, and all applicable legal and regulatory mandates.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversee institutional CUI management and retention practices; ensure compliance with federal, state, and institutional requirements; Monitor and validate compliance with CUI retention policies; maintain records of retention and disposal activities |
| System Owner | Project Participants (PP) / Principal Investigators | Implement and enforce retention policies for systems under their control; ensure secure storage and handling of CUI and system outputs; Ensure secure storage, access control, and proper disposition of CUI; verify data integrity throughout retention lifecycle; Follow retention, handling, and secure disposal procedures for CUI; report discrepancies or potential violations |
| Technical Implementation | Controlled Research Support Program (CRSP) | Configure systems to enforce retention schedules, backup, archival, and secure destruction of CUI; support system-level retention processes |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Ensures institutional resources are available for timely remediation; escalation authority for patch exceptions affecting CUI systems. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Establishes patch management policy, EDR standards, and monitoring requirements; reviews threat intelligence and disseminates applicable alerts to CRE system owners. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Deploys and manages EDR and SIEM; applies patches within required timelines; responds to malware alerts and quarantine events; maintains integrity monitoring. |
| Research Coordination | Research Security Office (RSO) | Advises on scheduling patching activities to minimize research disruption; communicates integrity-related risks to PI teams. |
| System Owner | Project Participants (PP) / Principal Investigators | Accepts patch windows as coordinated by ET/ISO; ensures research activities accommodate required maintenance timelines; reports suspected integrity violations. |
CRSP Standard 3.15: Planning (PL)
NIST SP 800-171 Rev. 3, Family 3.15
U. T. Austin shall develop, document, and maintain a System Security Plan (SSP) for each CUI system within the Controlled Research Environment, establish and maintain a Continuous Monitoring Plan, and ensure that all CRE users understand and acknowledge their security obligations. CRE planning requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.15 Planning (PL) Policy
03.15.01 Policy and Procedures. (See IRUSP §3) U. T. Austin establishes and maintains a comprehensive set of security and privacy policies and procedures to ensure the protection of CUI within the CRE and across all organizational systems, personnel, and processes. These policies and procedures define the requirements, responsibilities, and operational practices necessary to safeguard CUI in accordance with federal regulations, NIST SP 800-171r3, FedRAMP Moderate, and institutional standards.
Key elements of this policy include:
- Development and Documentation: U. T. Austin shall develop and document policies and procedures that address all security requirements necessary to protect CUI. Documentation shall clearly define roles, responsibilities, processes, and controls required to meet federal, state, and institutional compliance obligations within the CRE.
- Dissemination: Policies and procedures shall be formally communicated to all personnel or organizational roles responsible for CRE CUI. Dissemination ensures that individuals are aware of applicable requirements, understand expected behaviors, and have access to guidance necessary to implement security controls effectively.
- Review and Updates: Policies and procedures shall be reviewed and updated at least annually, or whenever significant changes occur to systems, operations, or regulatory requirements. Updates shall ensure continued alignment with NIST SP 800-171r3, FedRAMP Moderate, UT-Austin CRSP 3.0 CUI Governance Policy, and institutional governance standards.
- Governance and Accountability: The Chief Information Security Officer (CISO) is accountable for the development, approval, and periodic review of policies and procedures. System Owners (SOs), Information System Security Officers (ISSO), and designated policy owners are responsible for implementing, maintaining, and enforcing these policies within their respective systems and organizational areas.
- This policy establishes a structured, repeatable, and auditable approach for managing security and privacy requirements across U. T. Austin CRE systems. It ensures that all personnel and organizational units operate in a consistent manner to protect the confidentiality, integrity, and availability of CUI, while supporting compliance with federal, state, and institutional security standards.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve development and periodic review of all security and privacy policies and procedures; ensure alignment with NIST SP 800-171r3, FedRAMP Moderate, and institutional standards.; Develop, document, and update policies and procedures; ensure alignment with compliance requirements and institutional governance.; Support development and dissemination of policies; verify enforcement and adherence within CRE systems; provide input for updates. |
| System Owner | Project Participants (PP) / Principal Investigators | Implement and enforce policies and procedures within their CRE systems; ensure system-specific processes comply with organizational standards.; Read, understand, and follow applicable policies and procedures; acknowledge receipt if required. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Ensure personnel receive policy awareness training and acknowledge applicable policies; track compliance. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Provide technical input for procedural implementation; ensure system configurations and operations align with policies. |
03.15.02 System Security Plan. (See IRUSP §3) U. T. Austin establishes and maintains a System Security Plan (SSP) for all information systems within the CRE that process, store, or transmit CUI. The SSP provides a comprehensive overview of the system’s security posture, operational environment, and implemented controls to protect CRE CUI, in alignment with federal and state requirements, NIST SP 800-171, FedRAMP Moderate, and the UT-Austin CRSP 3.0 CUI Governance Policy.
Key elements of this policy include:
- Development and Documentation: U. T. Austin shall develop a detailed SSP for each system that includes:
- Definition of constituent system components.
- Identification of information types processed, stored, and transmitted.
- Description of threats to the system relevant to the organization.
- Overview of the operational environment and dependencies on other systems or components.
- Summary of applicable security requirements.
- Description of safeguards in place or planned to meet security requirements.
- Identification of individuals fulfilling system roles and responsibilities.
- Any other relevant information necessary for the protection of CUI.
- Review and Updates: The SSP shall be reviewed and updated at least annually or whenever significant changes occur to the system, environment, or regulatory requirements. Updates ensure the SSP remains accurate, current, and reflective of implemented security controls.
- Protection of the SSP: The SSP shall be protected from unauthorized disclosure. Access is limited to personnel with a legitimate need-to-know, consistent with the system’s security classification and organizational access controls.
- Governance and Accountability: The Chief Information Security Officer (CISO) is accountable for the overall development, approval, and periodic review of SSPs. System Owners (SOs) and Information System Security Officers (ISSO) are responsible for maintaining the SSP, ensuring accuracy, and enforcing access controls to protect the plan from unauthorized disclosure.
- This policy establishes a structured, repeatable, and auditable approach to documenting system security and operational details. It ensures all systems processing CRE CUI are comprehensively planned, monitored, and secured, supporting the confidentiality, integrity, and availability of CUI within the U. T. Austin environment.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Approve SSP development, ensure alignment with NIST SP 800-171, FedRAMP Moderate, and UT-Austin CRSP 3.0 CUI Governance Policy; review periodic updates.; Assist in developing the SSP; verify accuracy of security controls and safeguards; enforce protection measures for the SSP. |
| System Owner | Project Participants (PP) / Principal Investigators | Develop and maintain the SSP for their system; ensure system components, information types, threats, operational environment, security requirements, safeguards, and roles are accurately documented.; Access the SSP only per assigned roles; comply with confidentiality and access controls. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Ensure personnel assigned to system roles understand responsibilities and access limitations documented in the SSP. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Provide technical input for system architecture, dependencies, and security control implementation. |
03.15.03 Rules of Behavior. (See IRUSP §3) U. T. Austin establishes and enforces Rules of Behavior (RoB) for all personnel accessing information systems that process, store, or transmit CUI within the CRE. The RoB defines the responsibilities, expected conduct, and security obligations required to protect CUI and ensure compliance with federal, state, and institutional requirements, including NIST SP 800-171r3.
Key elements of this policy include:
- Establishment of Rules: U. T. Austin shall define clear, enforceable rules describing acceptable and expected behaviors for system use, CUI handling, and protection. Rules shall address security, privacy, and compliance obligations applicable to all users of CRE systems.
- Communication and Acknowledgment: RoB shall be communicated to all personnel and other individuals requiring access to CRE systems containing CUI. Individuals must provide documented acknowledgment indicating they have read, understand, and agree to abide by the RoB before being granted access.
- Review and Updates: RoB shall be reviewed and updated at least annually or whenever operational, regulatory, or security changes necessitate revisions. Updates ensure rules remain current, enforceable, and aligned with institutional and federal security requirements.
- Governance and Accountability: The Chief Information Security Officer (CISO) is accountable for the development, dissemination, and periodic review of RoB. System Owners (SOs) and Information System Security Officers (ISSO) are responsible for ensuring that users acknowledge the rules, that compliance is monitored, and that violations are addressed according to institutional policies.
- This policy establishes a structured and auditable approach to ensuring that all users understand and accept their security responsibilities. It supports the protection of CUI, promotes consistent compliance, and strengthens the overall security posture of the U. T. Austin CRE.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Develop and maintain the RoB policy; approve updates and revisions.; Monitor user compliance with RoB; report violations and recommend corrective actions. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure all system users acknowledge and comply with the RoB before access is granted.; Read, understand, and formally acknowledge the RoB. |
| Program Authority | Office of Research Support and Compliance (ORSC) | Distribute RoB documentation to new hires and personnel with system access; track acknowledgment forms. |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides institutional authority for CRE planning requirements; ensures SSPs are produced for all covered research systems. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Develops and maintains SSP templates, Rules of Behavior documentation, and Continuous Monitoring Plan frameworks; maintains the SSP repository. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Contributes technical content to SSPs; executes continuous monitoring activities; tracks Rules of Behavior completion and flags overdue acknowledgements. |
| Research Coordination | Research Security Office (RSO) | Coordinates with PIs on SSP development for research-specific systems; ensures research collaboration connections are appropriately authorized and documented. |
| System Owner | Project Participants (PP) / Principal Investigators | Reviews, approves, and signs SSPs for CRE systems under their authority; ensures all project personnel complete Rules of Behavior acknowledgement before access. |
CRSP Standard 3.16: System and Services Acquisition (SA)
NIST SP 800-171 Rev. 3, Family 3.16
U. T. Austin shall incorporate security requirements into the acquisition of information systems, components, and services that will process, store, or transmit CUI, and shall require external service providers to demonstrate compliance with applicable security standards. CRE system and services acquisition requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.16 System & Services Acquisition (SA) Policy
03.16.01 System and Services Acquisition Policy and Procedures. (See IRUSP §22; IRUSP §21) U. T. Austin enforces the application of formally defined systems security engineering principles throughout the lifecycle of all information systems, system components, and system services that process, store, or transmit CUI within the CRE.
These principles ensure that security and privacy requirements are incorporated from initial development through deployment, modification, integration, and operational use, and that all systems meet the UT-Austin CRSP 3.0 CUI Governance Policy risk management, operational, and compliance objectives.
U. T. Austin Security Engineering Principles Include:
- Documented Guidance: Provide clear, actionable instructions for CRE system users and administrators describing the implementation, operation, and maintenance of security controls.
- Configuration Requirements: Define CRE system settings specifying allowed functions, ports, protocols, and services to enforce secure system operation.
- Acceptance Criteria: Establish consistent CRE standards for approving systems, components, and services, aligned with institutional acquisition, procurement, and risk management policies.
- Integration of Risk Response: Design systems to maintain confidentiality, integrity, and availability of CRE CUI, consistent with U. T. Austin risk tolerance and operational expectations.
- Secure Development Practices: Apply secure coding standards, code reviews, testing, and validation procedures during CRE system development, modifications, or integrations.
- All CRE systems and system components must comply with U. T. Austin-defined security engineering principles as a condition of system acceptance and operational approval.
- Documentation demonstrating compliance—including user and administrator guidance, configuration baselines, and acceptance testing results—must be maintained according to institutional record retention policies.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Accountable for overall application of security engineering principles; approve system acceptance based on compliance with documented security requirements.; Validate implementation of security principles during system design, deployment, and operation; review configuration baselines; provide guidance on secure system operation. |
| System Owner | Project Participants (PP) / Principal Investigators | Ensure all system development, acquisition, or modifications comply with U. T. Austin-defined security engineering principles; approve system/component acceptance.; Apply security engineering principles during system design, development, integration, and deployment; maintain documentation supporting system security and acceptance criteria.; Implement secure development practices; apply STIGs, secure coding standards, testing, and validation procedures; ensure software components meet security and integrity requirements.; Define data protection requirements for CRE CUI; ensure that systems or services acquired for storing or processing CRE CUI meet organizational confidentiality, integrity, and availability standards. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Support technical evaluation of acquired or modified systems; validate that systems meet security configuration requirements; assist with integration, testing, and acceptance processes. |
03.16.02 Unsupported System Components. (See IRUSP §22; IRUSP §21) U. T. Austin enforces the management of unsupported system components within the CRE to maintain the confidentiality, integrity, and availability of CUI. This policy ensures that unsupported components within CRE systems are identified, mitigated, or replaced in a timely and auditable manner.
Key Policy Requirements:
- Replacement of Unsupported Components:
- System components within the CRE that are no longer supported by the original developer, vendor, or manufacturer must be identified and replaced with supported alternatives as soon as practicable.
- Replacement decisions must ensure continued compliance with NIST SP 800-171, including controls for system and communications protection, configuration management, and risk mitigation, as well as the UT-Austin CRSP 3.0 CUI Governance Policy.
- Risk Mitigation for Non-Replacable Components:
- For unsupported components within CRE systems that cannot be immediately replaced, U. T. Austin must implement compensating controls or mitigation strategies to protect CUI.
- Mitigation strategies may include:
- Isolating unsupported components from networks and critical systems.
- Implementing additional monitoring, logging, or intrusion detection controls.
- Applying virtual patching or configuration hardening to reduce vulnerabilities.
- Identifying alternative sources of support, including extended vendor support contracts or community-supported updates.
- Documentation and Approval:
- All unsupported components within the CRE, associated risks, and applied mitigation strategies must be documented, reviewed, and approved by the System Owner (SO) and Information System Security Officer (ISSO).
- Inventory Management and Monitoring:
- U. T. Austin maintains a comprehensive inventory of all CRE systems and components, including support status, and periodically reviews this inventory to ensure unsupported components are promptly identified and addressed.
- Noncompliance or delays in managing unsupported components within the CRE are escalated to the CISO and ISO for corrective action
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Provide executive oversight for unsupported component management within the CRE; approve escalation actions; ensure institutional compliance and alignment with risk management objectives.; Validate proposed mitigation strategies for unsupported components within CRE systems; ensure controls adequately protect CUI; confirm compliance with institutional security requirements.; Assist in sourcing supported alternatives or extended support options; review vendor contracts for lifecycle support commitments; coordinate with ISO/ISSO on acquisition decisions for CRE systems. |
| System Owner | Project Participants (PP) / Principal Investigators | Identify unsupported system components within CRE systems; review and approve replacement or risk mitigation strategies; ensure documentation aligns with U. T. Austin policies and compliance requirements (NIST SP 800-171r3, CRSP 3.0 CUI Governance Policy). |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement approved mitigation controls (e.g., isolation, monitoring, virtual patching, hardening) for CRE systems; monitor unsupported components for vulnerabilities; support replacement planning and execution. |
03.16.03 External System Services. (See IRUSP §22; IRUSP §21) U. T. Austin enforces a risk-based approach for the use of external system services that process, store, or transmit CUI within the CRE. This policy ensures that all external service engagements:
- Incorporate defined security requirements,
- Assign clear roles and responsibilities, and
- Include continuous monitoring to maintain compliance and mitigate risk.
- Requirements for External Service Providers:
- External service providers (e.g., cloud, SaaS, IaaS, infrastructure vendors) supporting CRE CUI must:
- Comply with U. T. Austin security and privacy requirements, including:
- NIST SP 800-171,
- UT-Austin CRSP 3.0 CUI Governance Policy,
- Applicable federal standards, including DFARS 252.204-7012 and FIPS.
- Implement baseline security controls as defined by U. T. Austin CRE and in accordance with UT-Austin CRSP 3.0 CUI Governance Policy:
- Access control and identity management,
- Audit logging and reporting,
- Data encryption at rest and in transit,
- Incident response support and notification,
- Physical security safeguards for CUI storage or processing.
- Execute binding agreements (contracts, SLAs) that explicitly define security requirements, shared responsibilities, and CRE CUI protection obligations.
- Ongoing Compliance Monitoring:
- U. T. Austin employs multiple methods to ensure external providers remain compliant:
- Security questionnaires and third-party risk assessments during acquisition and contract renewal.
- Review of FedRAMP authorizations, SOC 2 reports, ISO 27001 certifications, or equivalent attestations.
- Continuous monitoring of service performance, audit reports, incident notifications, and vulnerability disclosures.
- Annual re-validation of provider compliance and contractual CRE CUI protection requirements.
- Documentation of non-compliance and enforcement of corrective actions where required.
Note: This policy ensures a chain of trust with external system service providers, enabling:
Control inheritance,
Risk visibility, and
Accountability
while maintaining the confidentiality, integrity, and availability of CUI in CRE systems in compliance with institutional, state, and federal requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Oversees SCRM policies; ensures supply chain requirements are integrated into acquisition and procurement; approves vendor security requirements and mitigation plans.; Reviews supplier security disclosures, incident reports, and mitigation plans; ensures SCRM baseline controls are applied; supports monitoring and assessment.; Incorporate SCRM control requirements into contracts, SLAs, and purchase orders; verify vendors provide disclosure of significant vulnerabilities and incidents.; Review and approve contract language to ensure enforceable SCRM obligations, including reporting of incidents and vulnerabilities.; Conduct ongoing vendor monitoring and risk assessments; ensure supplier compliance with SCRM requirements; escalate non-compliance to CISO/ISO. |
| System Owner | Project Participants (PP) / Principal Investigators | Identifies supply chain risks for systems under their control; ensures acquisition and vendor engagements comply with SCRM controls; approves mitigation strategies.; Ensure procurement and integration activities adhere to SCRM policies; document identified risks and mitigation actions; coordinate with ISO and ISSO for vendor assessments.; Report vendor/component concerns, weaknesses, or suspected supply chain issues; follow guidance regarding authorized suppliers and approved systems. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implement technical mitigation controls for identified supply chain risks; validate vendor-provided system components meet SCRM requirements; monitor deployed systems. |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Coordinates with Procurement and Legal to ensure DFARS clauses are incorporated into relevant contracts and subcontracts. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Establishes security requirements for CRE acquisitions; reviews procurement packages for CUI-related systems; approves new CRE components. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Evaluates security of proposed CRE components; validates FedRAMP authorization for cloud services; assesses supply chain risk for new software and hardware. |
| Research Coordination | Research Security Office (RSO) | Advises on foreign-sourced hardware/software risks for CRE acquisitions; reviews vendor due diligence for research-specific tools. |
| System Owner | Project Participants (PP) / Principal Investigators | Initiates acquisition requests for research tools; provides justification for CRE component additions; ensures research procurements route through proper approval channels. |
CRSP Standard 3.17: Supply Chain Risk Management (SR)
NIST SP 800-171 Rev. 3, Family 3.17
U. T. Austin shall establish and maintain a supply chain risk management process to identify, assess, and mitigate risks arising from hardware, software, and services introduced into CUI systems by external parties. CRE supply chain risk management requirements supplement applicable university-wide standards; where CRSP requirements are more restrictive than those standards, the CRSP requirements govern.
3.17 Supply Chain Risk Management (SR) Policy
03.17.01 Supply Chain Risk Management. (See IRUSP §22) U. T. Austin enforces a formal Supply Chain Risk Management (SCRM) Plan to identify, assess, mitigate, and monitor risks arising from the research, development, design, manufacturing, acquisition, delivery, integration, operation, maintenance, and disposal of information systems, system components, and services supporting CUI within the CRE.
U. T. Austin shall:
- Develop and Maintain a Documented SCRM Plan: Define the strategy, processes, roles, responsibilities, and risk mitigation activities necessary to manage supply chain threats across the system lifecycle. The plan must address both internal and external suppliers, third-party services, and any component affecting CUI security in the CRE.
- Periodic Review and Updates: Review and update the SCRM Plan at least annually, or whenever significant incidents or changes occur, including updates to threat landscapes, federal regulations, institutional priorities, or supplier/technology changes. Updates shall ensure alignment with NIST SP 800-171 SR controls, DFARS 252.204-7012, and the UT-Austin CRSP 3.0 CUI Governance Policy.
- Protection of the SCRM Plan: Protect the SCRM Plan from unauthorized access, disclosure, modification, or distribution by implementing access controls, encryption, and need-to-know restrictions consistent with U. T. Austin security policies and CUI safeguarding requirements.
Note: This policy ensures that supply chain risk considerations are fully integrated into procurement, engineering, vendor management, and lifecycle processes to maintain the confidentiality, integrity, and availability of CUI within the CRE while supporting compliance with federal and institutional requirements.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Provides executive oversight for the SCRM Plan; approves plan content, updates, and risk mitigation strategies; ensures alignment with institutional and federal requirements.; Reviews the SCRM Plan for completeness and compliance with NIST SP 800-171, DFARS, and institutional requirements; validates risk assessments and mitigation measures.; Develops, maintains, and updates the documented SCRM Plan; identifies and assesses supply chain risks; recommends mitigation strategies; ensures plan reflects current threat landscape and supplier information.; Coordinates with SCRM personnel to integrate supply chain risk considerations into procurement processes and vendor agreements; ensures suppliers are evaluated according to plan requirements.; Ensures contracts and agreements reflect supply chain risk requirements; supports plan enforcement through legal and regulatory compliance mechanisms.; Integrates supply chain risk incidents into incident response procedures; coordinates investigations and reporting related to supply chain events. |
| System Owner | Project Participants (PP) / Principal Investigators | Oversees implementation of the SCRM Plan for systems under their purview; ensures supply chain risks are assessed, documented, and mitigated; approves updates to the plan for their systems.; Adhere to access controls for SCRM documentation; report unauthorized access, misuse, or discrepancies. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Implements technical controls to protect the SCRM Plan from unauthorized access or disclosure; monitors access logs and ensures compliance with security measures. |
03.17.02 Acquisition Strategies, Tools, and Methods. (See IRUSP §22) The University of Texas at Austin (U. T. Austin) enforces acquisition strategies, contract tools, and procurement methods designed to identify, protect against, and mitigate supply chain risks associated with the acquisition and use of systems, system components, and system services that store, process, or transmit Controlled Unclassified Information (CUI) within the Controlled Research Environment (CRE).
U. T. Austin shall:
- Integrate Supply Chain Risk Considerations: Ensure all procurement and acquisition activities require identification and evaluation of supplier, component, and service risks prior to approval or procurement.
- Use Standardized Acquisition Tools and Methods: Apply pre-procurement assessments, vendor questionnaires, contract language, and risk screening processes to ensure suppliers meet institutional, federal, and contractual security requirements.
- Incorporate Mandatory Security Clauses: Include DFARS 252.204-7012 and other applicable safeguarding and incident reporting requirements in all contracts for CUI systems or services.
- Ensure Risk Evaluation by Authorized Personnel: Require Procurement Officers, System Owners (SOs), the Chief Information Security Officer (CISO), and other authorized personnel to evaluate supply chain risks as part of the acquisition approval process.
- Use Trusted Procurement Channels: Prefer validated suppliers to reduce exposure to counterfeit components, compromised software, or high-risk vendors.
- Leverage Risk Assessment Tools: Apply supply chain risk assessment tools, market research, vendor integrity checks, and due-diligence activities to detect and mitigate potential risks across the system lifecycle.
- Comply with Standards and Guidance: Ensure acquisition strategies and contract tools align with NIST SP 800-171 Rev. 3, NIST SP 800-161, federal supply chain risk guidance, and UT-Austin CRSP 3.0 CUI Governance Policy requirements.
- Review and Update Procedures: Periodically update acquisition strategies and procurement methods to address emerging risks, evolving threat environments, and changes to regulatory requirements.
Note: This policy supports U. T. Austin’s commitment to protecting the confidentiality, integrity, and availability of CUI in the CRE by embedding supply chain risk management into institutional acquisition processes.
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Policy Owner | Information Security Office (ISO) | Provides executive oversight of acquisition strategies and procurement methods; approves supply chain risk management requirements in acquisition processes; ensures alignment with institutional, federal, and contractual obligations.; Reviews acquisition packages for compliance with supply chain risk requirements; validates mitigation measures for high-risk components, services, or vendors; supports risk assessment documentation.; Implements standardized acquisition tools and methods (e.g., contracts, vendor questionnaires, pre-procurement assessments); ensures mandatory security clauses and due diligence are applied; maintains records of supplier evaluations.; Ensures contracts and SLAs include supply chain risk clauses, DFARS 252.204-7012 requirements, and incident reporting obligations; reviews legal compliance of acquisition documents.; Conducts supplier validation, integrity checks, and due-diligence activities; identifies high-risk vendors and recommends mitigation strategies; monitors ongoing supplier performance. |
| System Owner | Project Participants (PP) / Principal Investigators | Evaluates supply chain risks for systems under their responsibility; approves acquisition decisions and ensures risk considerations are incorporated into procurement; coordinates with Procurement Officers to verify supplier compliance.; Ensures acquisition and development activities incorporate supply chain risk assessments; documents approval and risk mitigation decisions; coordinates with SOs, ISSOs, and procurement teams.; Follow procurement approval and supply chain risk policies; report procurement anomalies or use of unapproved vendors or systems. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Supports technical evaluation of acquired components/services; validates vendor-provided system security measures; assists with integration and configuration checks for CUI systems. |
Accountability
| Role | Office | Responsibility |
|---|---|---|
| Executive Oversight | Office of Research Support and Compliance (ORSC) | Provides institutional authority for SCRM program governance; coordinates with Procurement and Legal on supply chain risk requirements in contracts. |
| Policy Owner / Security Oversight | Information Security Office (ISO) | Establishes SCRM policy and assessment criteria; reviews supply chain risk assessments for CRE components; tracks vendor compliance status. |
| Technical Implementation | Controlled Research Support Program (CRSP) | Evaluates hardware and software component integrity; validates component provenance; manages approved supplier lists and monitors for supply chain compromise indicators. |
| Research Coordination | Research Security Office (RSO) | Advises on supply chain risks specific to research equipment and software dependencies; coordinates with federal program offices on supplier restrictions. |
| System Owner | Project Participants (PP) / Principal Investigators | Identifies and discloses supply chain dependencies for research systems; ensures research procurements follow SCRM assessment processes before CRE introduction. |
Controlled Research Environment (CRE) - The centrally managed secure enclave operated by U. T. Austin for the processing, storage, and transmission of CUI in support of sponsored research activities.
Controlled Unclassified Information (CUI) - Information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. Designated in accordance with the NARA CUI Registry.
Controlled Research Support Program (CRSP) - The University of Texas at Austin program that implements the policies, procedures, and controls required to protect CUI in sponsored research activities, including operation of the CRE and compliance with NIST SP 800-171.
Least Privilege - The security principle of granting users, processes, and devices only the minimum access rights and permissions needed to perform their authorized functions.
Principal Investigator (PI) - The individual designated by the university as the lead researcher responsible for the conduct of a sponsored research project, including compliance with applicable security requirements.
System Security Plan (SSP) - A formal document that describes the system boundary, security requirements, and implementation of controls for a CUI information system, as required by NIST SP 800-171.
Revision History
Review Cycle: Every 3 years, or as needed
| Date | Description |
|---|---|
| July 2026 | Initial draft — NIST SP 800-171 Rev. 3 aligned; developed in coordination with NCC consulting group Approved by the Information Security Office (ISO), Office of Research Support and Compliance (ORSC), and Controlled Research Support Program (CRSP) |
Questions or comments about this policy should be directed to: security@utexas.edu.