Brief Description

Approved By: MSU Denver President

Purpose: This policy establishes Metropolitan State University of Denver’s commitment to maintaining a comprehensive information security program as required by the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (16 C.F.R. Part 314), the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, the Payment Card Industry Data Security Standard (PCI DSS), the Family Educational Rights and Privacy Act (FERPA),  applicable Colorado statutes, and other federal and state laws and regulations governing the protection of sensitive information.

This policy authorizes the creation and maintenance of a Written Information Security Program (WISP) (located in the ITS Policy Hub SharePoint Site)   and delegates operational authority to the Chief Information Security Officer (CISO) as the Qualified Individual under the GLBA Safeguards Rule.

Scope:This policy applies to all institutional data in any form (electronic, paper, verbal) and all information systems owned, leased, or managed by or on behalf of MSU Denver. It applies to all members of the University community, including employees, faculty, staff, student workers, contractors, consultants, volunteers, and third-party service providers who access University information or systems.

Contact: Information Technology Services, ITS Webpage, 303-605-7000

Read the full policy statement, by clicking the following link:

Information Security Program Policy 6.2026