skip to main contentskip to footer

Quick links

  • Athletics
  • Make a gift
  • Student portal
  • Job openings
  • Employee directory
  • Apply
  • Costs
  • Explore
Explore U of I
  • Visit and virtual tour
  • Student life
  • Find your degree
  • Get around campus
  • Meet Moscow
  • Join our email list
  • Events
  • Join ZeeMee
  • Athletics
Academics
  • Academic calendar
  • Find a major
  • Academic support
  • Undergrad research opportunities
  • Meet the colleges
  • Online learning
  • Explore in-demand careers
Admissions
  • Meet your counselor
  • Deadlines
  • First-year students
  • Graduate students
  • Law students
  • Online students
  • Transfer students
  • International students
  • Admitted students
Financial aid
  • Cost of attendance
  • Steps for financial aid
  • FAFSA information
  • Financial aid FAQs
  • In-state scholarships
  • Out-of-state and international scholarships
  • Connect with financial aid
More
  • Student life
  • Research
  • Recreational offerings
  • Student resources
  • Alumni
  • Parents
  • Newsroom
  • Events
  • Sustainability initiatives
Find your passion - Explore majors Become a Vandal - Start an application
  • Student portal
  • Make a gift
  • Athletics
  • Directory
Events
Get tickets to ‘Ride the Cyclone’
See the Theatre Arts department’s hilarious musical “Ride the Cyclone,” opening Feb. 26. Six choir teens in limbo tell their stories for a chance to return to life after a fatal roller coaster accident.
U of I Energy Symposium
Hear about energy, power, politics and innovation from author, journalist and film producer Robert Bryce, keynote speaker at the U of I Energy Institute’s first Energy Symposium March 4.
Step aboard for 'H.M.S. Pinafore'
The Lionel Hampton School of Music presents “H.M.S. Pinafore” March 6-7, featuring the LHSOM orchestra and Theatre Arts Department in a humorous, heartfelt performance.
Events
News
Army ROTC cadet Sophia Fischer is photographed inside the Memorial Gymnasium building on Tuesday, January 20, 2026. Fischer, a history and psychology major who grew up in Germany, serves as commander of the Chrisman Battalion and will be commissioned as an Army officer when she graduates in May.
Student joined Army ROTC leadership at U of I
UI Extension Master Food Safety Advisor Michael Mitchell demonstrates boiling water canning during an in-person Extension food safety and preservation program
Online food safety series expands statewide
News
Support a Vandal - Make a gift
  • Apply
  • Costs
  • Explore
  • Explore
  • Academics
  • Admissions
  • Financial Aid
  • Student life
  • Research
  • Recreational offerings
  • Student resources
  • Alumni
  • Parents
  • Newsroom
  • Events
  • Sustainability initiatives

System and information integrity

  • leadership
  • President's Office
  • Provost's Office
  • Finance and Administration
  • General Counsel
  • Administrative position searches
  • Information technology
    • leadership
    • President's Office
    • Provost's Office
    • Finance and Administration
    • General Counsel
    • Administrative position searches
    • Information technology
    leadership
    • President's Office
    • Provost's Office
    • Finance and Administration
    • General Counsel
    • Administrative position searches
    • Information technology
    1. Home/
    2. leadership/
    3. Information technology/
    4. IT standards/
    5. System and information integrity

    Overview

    This updated standard is to help align existing IT practices around System and Information Integrity to the requirements in NIST 800-171 (SI | 3.14.x) as well as industry best practices. This document does not give full coverage of 3.14.x controls within 171 due to existing limitations and other requirements that are specific to CUI.

    What is in this document:

    • Patching requirements
    • Requirement to report flaws to Office of Information Technology (OIT) Security
      AV configuration requirements

    What is NOT in this document:

    • Patching process (testing, deployment, logging)
    • System hardening requirements

    Policy Reference

    • APM 30.11 University Data Classification and Standards
    • APM 30.12 Acceptable Use of Technology Resources
    • APM 30.14 Cyber Incident Reporting and Response

    Purpose
    This Access Control standard supports APM 30.11 University Data Classification and Standards and other relevant university policies.

    Scope
    These standards are the minimum baseline for all managed and unmanaged systems that access, store or process University of Idaho data (see APM 30.14 C-6) or using University of Idaho technology resources (see APM 30.12 C-1) at the Low, Moderate- or High risk levels (see APM 30.11) not otherwise covered by an approved systems security plan.

    Standards

    U of I Office of Information Technology (OIT) is responsible for the content and management of these standards.

    To request an exception to this standard contact: oit-security@uidaho.edu 

    1. Flaw remediation

    To help ensure system and application flaws are detected and resolved in a reasonable timeframe:

    1. Apply security patches to address flaws in systems and applications automatically, or within 10 business days.
      1. Patches may be applied in a timeframe approved through a risk-based vulnerability assessment process approved by OIT Security and all affected data and system owners.
    2. U of I employees who discover flaws or vulnerabilities must report them to
      oit-security@uidaho.edu within 4 hours of discovery.
      1. Discovery does not include validation.
      2. Self-investigation of cybersecurity issues is discouraged, if you feel you need to investigate something prior to reporting to OIT Security, report it anyway.
    2. Malware prevention

    To help ensure malware is unable to establish, spread and impact systems:

    1. All capable systems with university data must have OIT-managed AV/EDR.
      1. Systems not capable of running OIT-managed AV/EDR must have mitigating controls approved by OIT Security
    2. Systems with malware detected must be reformatted or rebuilt unless otherwise approved by OIT Security.
      1. University technology resources must be reimaged by OIT or as specified by OIT.
    3. AV configuration requirements

    To help ensure malware is unable to establish, spread and impact systems:

    1. Updates to signatures need to be applied within 1 day of release.
    2. Full system scans must occur on at least a weekly basis unless an exception is documented by OIT Security.
    3. Real-time protection must be enabled unless an exception is documented by OIT Security.
    4. Security alerting

    OIT Security, as a part of participation in information sharing and analysis centers, vendor advisories and other alert feed tools, will respond to alerts with investigation under APM 30.14.

    Other references

    1. NIST SP800-171r2 (February 2020)
    2. NIST SP800-53r5 (September 2020)
    3. CMMC Glossary

    Definitions

    1. System flaws

      An issue within a system that may result in the system not working as intended. This may include process failures, software vulnerabilities or design gaps.

    2. Security patch

      Updates or fixes released by vendors to resolve a security vulnerability.

    3. Anti-Virus (AV)

      “A program that monitors a computer or network to identify all major types of malware and prevent or contain malware incidents.” (CMMC Glossary)

    4. Endpoint Detection and Response (EDR)

      Software that runs on endpoint that reviews system behavior for malicious activity and takes action accordingly.

    Revision history

    3/1/2024 — Minor updates

    • Minor formatting/wording/reference changes.

    6/23/2023 — Original standard

    • Full re-write to align with NIST 800-171r2

    Footer

    Ready to apply?

    Start your application
    Joe Vandal head illustration

    Footer Navigation

    Resources

    • Jobs
    • Privacy statement
    • Web accessibility
    • Title IX

    Campus

    • Directory
    • Map
    • Safety
    • Events

    Information For

    • Prospective students
    • Current students
    • Parents
    • Employees
    Logo

    University of Idaho

    875 Perimeter Drive, Moscow, ID 83844

    208-885-6111

    info@uidaho.edu

    Engage with U of I on Facebook. Get the latest U of I updates on X. Catch up with U of I on Instagram. Grow your professional network by connecting with U of I on LinkedIn. Interact with University of Idaho's video content on YouTube. Join the University of Idaho ZeeMee conversation.
    Support a Vandal - Make a gift
    • Athletics
    • News
    • Policies

    © 2026 University of Idaho