IT0001-HSC-A Standard on UTHSC Information Technology Standards and Practices

Responsible Office: Vice Chancellor for Information Technology/CIO

Last Review: 03/01/2025

Next Review: 03/01/2027

Contact: Dan Harder

Phone: 901.448.2500

Email: dharder@uthsc.edu

Purpose

To establish authority and process for drafting, maintaining, and approving Information Technology Standards and Practices at the University of Tennessee Health Science Center (UTHSC), and grant and control exceptions for unusual operational, technical, or administrative circumstances. University of Tennessee Health Science Center Information Technology Standards and Practices are developed, revised, and issued in response to new guidelines and changes in UT-wide Standards and Practices, internal Standard as well as state and federal laws, regulations, and statutory requirements.

Scope

This standard applies to the development of all UTHSC Information Technology (IT) Standards and Practices.

Definitions

Practice – supporting documentation with a more detailed explanation of how a Standard should be executed.

Standard – supporting documentation at the campus level for a UT-system policy.

Responsibilities

The Executive Leadership of ITS has the responsibility for developing UTHSC Information Technology Standards, Practices, Procedures, and Guidance specific to UTHSC campuses, colleges, or institutes conformant with UT-wide IT Policies and Standards to accompany and supplement individual information technology Standards and Practices.

The UTHSC Office of Cybersecurity and the Chief Information Security Officer (CISO) has the responsibility for developing Standards, Practices, Procedures, and Guidance specific to security-related topics conformant with UT-wide Security Policies and Standards.

Standard

  1. Development
    1. The Office of the CIO and/or CISO coordinates the IT Standard development function for UTHSC, with responsibility for development, and maintenance; The Office of the CIO and/or CISO maintains a complete repository of UTHSC IT Standards, Practices, Procedures, and Guidelines.
    2. The process for Standard and Practice development will be as outlined in IT0001-HSC-A.01-Framework for developing UTHSC IT Standards and Practices.
    3. UTHSC Standards and Practices must align with UT-Wide IT policies and standards and can only be more restrictive than applicable UT-Wide policies and standards.
  2. Exceptions
    1. The Office of the CIO, CISO, or designee is authorized to grant exceptions to UT IT Policies and UTHSC IT Standards and Practices.
    2. Exceptions shall be granted in accordance with IT0003-HSC-A.02– Security exceptions and Exemptions to ITS Standards Practices & Controls.
    3. No exceptions to Federal or State laws or regulations will be granted.

Policy History

Version #
Effective Date
1
03/18/2016
2
03/14/2018
3
04/17/2022
4
01/10/2023
5
03/01/2025 – new naming convention

References

  1. IT0001-General Statement on Information Technology Policy
  2. IT0001-HSC-A.01-Framework for developing UTHSC IT Standards and Practices
  3. IT0003-HSC-A.02-Security Exceptions and Exemptions to ITS Standards Practices & Controls
  4. University of Tennessee Policies (http://policy.tennessee.edu/ )

IT0001-HSC-A Standard on UTHSC Information Technology Standards and Practices
Version: 5 // Effective: 03/17/2016
PDF icon Downloadable PDF