Minimum Standards

hand using a pencil noting on notepad

Why Minimum Standards Matter

Minimum Standards establish a common cyber security baseline for protecting University systems, services, and data. They translate responsibilities into required auditable actions.

Responsibilities explain who is accountable, Minimum Standards define what must be done, and Guides and Playbooks explain how to do it in practice.

 

Getting Started

  1. Determine your role.
  2. Determine the Risk Classification for the data and/or services you use or manage.
  3. Review the standards relevant for your role.
    • Custodians need to review the additional standards for systems, services and technology assets.

Community Members Minimum Standards

These standards apply to Community Members who use University data, systems, or other digital resources. For a complete role description, see Community Member Responsibilities.

Detailed implementation guides are linked within the sections below.

System or Service Custodians (Custodians) Minimum Standards

Custodians must meet the Community Member Minimum Standards when using University resources, as well as the standards below when supporting IT resources used for University business. The Custodian remains accountable for ensuring these standards are met, including when implementation is performed by another Harvard team, vendor, or service provider. For a complete role description, see System or Service Custodian Responsibilities.

Implementation help:

For guidance on how to meet the Custodian Minimum Standards:

All Systems and Services

These standards apply to all systems and services you manage or support, regardless of technology or hosting model.

Technology Assets

In addition to the All Systems and Services standards above, these standards must be applied to specific types of technology assets.

Beyond the Basics: Privacy & Regulated Data

Protecting sensitive data takes more than following the Minimum Standards for IT security. Information such as student records, health details, and financial files demands custom steps to comply with legal and contractual rules. If you work with these data types, check the resources below to learn more.

Privacy Principles

Standard practices for collecting, storing, and sharing personal data.

Regulated & Contractual Data

Rules for handling HIPAA, PCI, GDPR, and data sourced from providers.

Equivalents and Exceptions

Schools may use varying technologies and techniques to meet the expected outcomes of the Minimum Standards.

Equivalents

An equivalent technology or implementation technique may be used when it meets or exceeds the required security outcome. Using an equivalent is not an exception and does not require a formal exception request.

Exceptions

If the required outcome cannot be met:

  • A formal exception must be requested and approved by the Chief Information Security and Data Privacy Officer (CISO/DPO) or designee.
  • Vulnerability exceptions and false positives must also follow the applicable University-wide Vulnerability Management (UWVM) process.
  • Expired exception approvals require immediate action. 

Submit a formal exception for consideration.

Related Resources

Use these resources to take the next step, find University guidance, or explore trusted external references.