Skip to main content

4 posts tagged with "cyber"

View All Tags

Public Disclosure Program

· One min read
Nick McLarty
Nick McLarty
Deputy Chief Information Security Officer

As part of our implementation of security control standard RA-05(11), Public Disclosure Program, today we implemented a consolidated public reporting system for vulnerabilities of Texas A&M system information resources. Information regarding the program and the vulnerability reporting form is available at https://www.cyber.tamus.edu/vulnerability-disclosure-policy/.

We have also released the first version of a TAMUS standardized security.txt, a file format to aid in security vulnerability disclosure specified by RFC 9116. This file is published at https://www.cyber.tamus.edu/.well-known/security.txt and is also available for members to use on their respective institution websites.

Revised System Regulation 29.01.03

· One min read
Nick McLarty
Nick McLarty
Deputy Chief Information Security Officer

A revised System Regulation 29.01.03, Information Security, was released today. This revision:

  • adds or clarifies language to reflect the reorganization of the Security Operations Center (SOC) to Texas A&M University System Cybersecurity,
  • clarifies the purpose of the Texas A&M System Security Control Standards Catalog and eliminates duplicative or redundant reference to the Texas DIR Security Control Standards Catalog,
  • adds supporting language that references system requirements to Texas statute or administrative rule,
  • establishes a required frequency for performing risk assessments based on the impact of the system being assessed,
  • moves detailed guidance for data center consolidation to the A&M System Security Control Standards Catalog, and
  • eliminates guidance for member CIO approval of commodity IT services

The revised regulation is available at https://policies.tamus.edu/29-01-03.pdf.