This policy outlines the ETSU Cybersecurity Awareness and Training Program (CSAT Program). The CSAT Program is implemented by the Office of Information Technology Services (ITS) to inform and educate all employees of their information security obligations, and to reduce the security risks to ETSU systems and data.
Section 5 of the policy discussed non-compliance and states that ITS will cut off access to university systems pending completion of training. I recognize that ITS needs to have some compliance “sticks” (although one could argue carrots are better), but here are some concerns I have:
This policy needs a procedures section to address the non-compliance and explain notification, requesting extension, and other questions raised.
Are there any exemptions or alternate requirements for part-time, seasonal, or adjunct employees who may have limited system access or irregular schedules. It’s not clear if the training timeline or access restrictions apply differently for these roles.
Additionally, how are training deadlines handled in cases of extended leave, such as FMLA, medical leave, or sabbaticals? Is there a defined process for pausing compliance requirements in these situations?