Skip to Content

Policy 801: Information Security & Data Protection Policy

Operational Policy
Policy Number: 801
Adopted: August 2026

Purpose

Grays Harbor College is committed to protecting its information technology resources and institutional data. This policy establishes the College’s overarching governance framework for information security and data protection. It defines institutional expectations, assigns responsibility, and provides the foundation for supporting security standards, procedures, and guidelines. This policy supports compliance with applicable federal and state law, applicable contractual obligations, and Washington Technology Solutions (WaTech) security requirements.

Scope

This policy applies to all members of the Grays Harbor College community, including employees, students, contractors, volunteers, affiliates, and other authorized users of college technology resources or institutional data.

This policy applies to college-owned, college-managed, leased, hosted, or contracted technology resources and services, including but not limited to:

  • Computing devices and endpoints,
  • Servers, networks, and telecommunications systems,
  • Cloud services and software-as-a-service platforms,
  • Applications and systems that store, process, transmit, or provide access to institutional data, and
  • Third-party environments that access, host, or manage Grays Harbor College information.

Policy

Information security and data protection are shared responsibilities at Grays Harbor College. The College will maintain an information security program designed to protect the confidentiality, integrity, and availability of institutional information and technology resources. The College will establish, maintain, and enforce supporting standards and procedures that address data classification, identity and access management, data handling and sharing, platform security, incident response, and related security requirements.

Grays Harbor College will align its information security program with applicable WaTech security policies and standards, including current requirements related to security awareness training, access control, data sharing, data classification, encryption, and information security risk management.

The College will classify institutional data and apply safeguards appropriate to the data’s sensitivity, legal requirements, and operational use. Detailed requirements for classification, access, storage, transmission, sharing, and system configuration are defined in supporting standards and procedures.

The College will take risk-based steps to reduce cybersecurity risk, support continuity of operations, and protect information resources from unauthorized access, disclosure, alteration, destruction, or disruption.

The retention, disposition, and destruction of College records, including electronic records, must follow the current approved Washington State records retention schedules. Records designated for permanent or archival retention must not be destroyed and must be managed in accordance with Washington State Archives requirements. Destruction must be suspended when records are subject to a legal hold, reasonably anticipated litigation, audit requirement, or active public records request.

Roles and Responsibilities

College Leadership

College leadership supports the information security program by providing institutional oversight, assigning authority, and supporting compliance with applicable laws, regulations, contractual obligations, and state requirements.

Information Technology

The Information Technology department is responsible for administering and supporting the College’s information security program, developing and maintaining supporting standards and procedures, implementing reasonable administrative, technical, and physical safeguards, coordinating incident response activities, and advising the College on information security risk.

Data Owners / Data Stewards

Data owners or stewards are responsible for helping identify the appropriate classification and protection requirements for institutional data under their authority, consistent with College standards and applicable law.

Users

All users of Grays Harbor College technology resources and institutional data are responsible for complying with this policy and related standards, completing required security awareness training, protecting credentials and devices under their control, and promptly reporting suspected security incidents or policy violations.

Compliance, Risk Management, and Review

Grays Harbor College will maintain supporting documentation, processes, and records necessary to demonstrate alignment with applicable security requirements and to support risk management, audit readiness, and continuous improvement. The College will assess and address cybersecurity risk in a manner appropriate to its environment, systems, and data.

This policy will be reviewed at least annually, and more frequently as needed to reflect changes in law, regulation, contractual requirements, WaTech policy, business operations, or technology.

Incident Reporting

Suspected or confirmed information security incidents must be reported promptly to Information Technology in accordance with established College incident response procedures.

Related Standards and Procedures

This policy is supported by related standards and procedures, including:

  • Data Classification Standard
  • Identity & Access Management Standard
  • Data Management & Sharing Standard
  • M365 Security Standard
  • Other related security procedures, guidelines, and operational standards adopted by the College

Related Laws and Other Resources

Policy Review History

Reviewed: N/A
Revised: N/A

Review and Revision refers to the College’s cyclical process for evaluating and updating all institutional policies and procedures. At minimum, each policy or procedure will undergo review once every five years to ensure accuracy, relevance, and alignment with current practices and regulatory requirements. If the scheduled review results in no changes, the date of that review will be recorded in the Reviewed field. If updates or edits are made, the date will be recorded in the Revised field. This process maintains transparency regarding the history of each policy or procedure and ensures the College remains responsive to evolving needs and standards.

Related Procedures

  • No related procedures