{"id":43481,"date":"2020-06-15T09:31:45","date_gmt":"2020-06-15T16:31:45","guid":{"rendered":"https:\/\/policies.wsu.edu\/prf\/?page_id=43481"},"modified":"2026-08-25T12:52:16","modified_gmt":"2026-08-25T19:52:16","slug":"bppm-87-40","status":"publish","type":"page","link":"https:\/\/policies.wsu.edu\/prf\/index\/manuals\/business-policies-and-procedures-manual\/bppm-87-40\/","title":{"rendered":"87.40 System and Information Integrity"},"content":{"rendered":"\n<h1 class=\"wp-block-heading wsu-font-size--xxmedium\">University Policies and Procedures Manual<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">System and Information Integrity<\/h2>\n\n\n<div class=\"wsu-row wsu-row--single\" >\r\n    \n<div class=\"wsu-column\"  style=\"\">\r\n\t\n\n<p><strong>UPPM 87.40<\/strong><\/p>\n<p><strong>For more information contact:<\/strong><br>&nbsp; &nbsp;<a href=\"https:\/\/its.wsu.edu\/how-can-we-help-contact-its\/\">Information Technology Services<\/a><\/p>\n<hr>\n<div id=\"toc_container\">\n<h3>Contents<\/h3>\n<ul class=\"toc_list\">\n<li><a href=\"#One_0\">1.0 &nbsp;&nbsp; Overview and Purpose<\/a>\n<ul class=\"toc_list\">\n<li><a href=\"#One_1\">1.1 &nbsp;&nbsp; Information Assurance Policies Generally<\/a><\/li>\n<li><a href=\"#One_2\">1.2 &nbsp;&nbsp; Specific Policy Overview and Purpose<\/a><\/li>\n<\/ul>\n<\/li>\n<li><a href=\"#Two_0\">2.0 &nbsp;&nbsp; Applicability<\/a><\/li>\n<li><a href=\"#Three_0\">3.0 &nbsp;&nbsp; Roles and Responsibilities<\/a>\n<ul class=\"toc_list\">\n<li><a href=\"#Three_1\">3.1 &nbsp;&nbsp; Chief Information Officer<\/a><\/li>\n<li><a href=\"#Three_2\">3.2 &nbsp;&nbsp; Information Owners<\/a><\/li>\n<li><a href=\"#Three_3\">3.3 &nbsp;&nbsp; Office of Information Security and Assurance (OISA)<\/a><\/li>\n<\/ul>\n<\/li>\n<li><a href=\"#Four_0\">4.0 &nbsp;&nbsp; Requirements<\/a>\n<ul class=\"toc_list\">\n<li><a href=\"#Four_1\">4.1 &nbsp;&nbsp; General Requirements<\/a><\/li>\n<li><a href=\"#Four_2\">4.2 &nbsp;&nbsp; Moderate- and High-Impact Systems<\/a><\/li>\n<li><a href=\"#Four_3\">4.3 &nbsp;&nbsp; High-Impact Systems<\/a><\/li>\n<\/ul>\n<\/li>\n<li><a href=\"#Five_0\">5.0 &nbsp;&nbsp; Training<\/a><\/li>\n<\/ul>\n<\/div>\n<h3 id=\"One_0\">1.0 Overview and Purpose<\/h3>\n<h4 id=\"One_1\">1.1 Information Assurance Policies Generally<\/h4>\n<p>The purposes of the information assurance policies in UPPM Chapter 87: Information Technology and Security are to:<\/p>\n<ul>\n<li>Set requirements to ensure the privacy, confidentiality, integrity, and availability of Washington State University (WSU) data;<\/li>\n<li>Support institutional goals and strategies with appropriate methods for administratively, technically, and operationally protecting data; and<\/li>\n<li>Define the criteria WSU follows to meet requirements for protecting data, which are determined by Information Owners.<\/li>\n<\/ul>\n<p>The policies in this chapter comply with Federal Information Processing Standards (<a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/fips\/nist.fips.199.pdf\">FIPS 199<\/a>), which are intended to help organizations achieve a common level of quality and interoperability in information technology (IT) by requiring categorization of systems as low-impact, moderate-impact, or high-impact for the stated security objectives of confidentiality, integrity, and availability. To determine the potential consequence of a loss event, the Federal Information Processing Standards:<\/p>\n<ul>\n<li>Define WSU Information Owners\u2019 impact categorization rating (Low, Moderate, or High);<\/li>\n<li>Dictate which security controls are mandatory based upon the categorization level;<\/li>\n<li>Define the strength, frequency, and formalization of those controls; and<\/li>\n<li>Influence audit burden and continuous monitoring rigor.<\/li>\n<\/ul>\n<p>See <a href=\"https:\/\/policies.wsu.edu\/prf\/index\/manuals\/business-policies-and-procedures-manual\/bppm-87-01\/\">UPPM 87.01<\/a> for definitions, general information, and violations related to this policy, as well as additional information regarding roles and responsibilities.<\/p>\n<h4 id=\"One_2\">1.2 Specific Policy Overview and Purpose<\/h4>\n<p>Ensuring that WSU\u2019s systems and information are protected helps maintain a secure and reliable IT environment that supports WSU\u2019s academic, research, and administrative missions. This policy establishes the requirements to prevent, detect, and correct vulnerabilities across WSU\u2019s systems.<\/p>\n<h3 id=\"Two_0\">2.0 Applicability<\/h3>\n<p>This policy applies to all WSU system users who have contact with, or potentially may have contact with, WSU data, applications, and computing resources.<\/p>\n<p>Security control exceptions to policy statements in UPPM Chapter 87 are managed and maintained in accordance with <a href=\"https:\/\/policies.wsu.edu\/prf\/index\/manuals\/business-policies-and-procedures-manual\/bppm-87-23\/\">UPPM 87.23<\/a>.<\/p>\n<h3 id=\"Three_0\">3.0 Roles and Responsibilities<\/h3>\n<h4 id=\"Three_1\">3.1 Chief Information Officer<\/h4>\n<p>The Chief Information Officer (CIO) of WSU, or designee, is responsible for administering this policy and reviewing it on an annual basis.<\/p>\n<h4 id=\"Three_2\">3.2 Information System Owners<\/h4>\n<p>WSU Information System Owners, or their delegates, are responsible and accountable for developing appropriate Standard Operating Procedures (SOPs) for this policy&#8217;s implementation.<\/p>\n<h4 id=\"Three_3\">3.3 Office of Information Security and Assurance (OISA)<\/h4>\n<p>WSU\u2019s Office of Information Security and Assurance (OISA) shall maintain the <a href=\"https:\/\/its.wsu.edu\/documents\/2026\/01\/system-and-information-integrity-standard.pdf\">standard (PDF)<\/a> associated with this policy and provide guidance for the associated procedures for the implementation of this policy (<a href=\"https:\/\/its.wsu.edu\/documents\/2026\/01\/system-and-information-integrity-procedure.pdf\/\">see examples (PDF)<\/a>).<\/p>\n<p><strong>Note:<\/strong> While all units are required to adhere to the standard established by OISA (<a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/53\/r5\/upd1\/final\">NIST SP 800-53<\/a>), procedural examples for implementation are optional.<\/p>\n<h3 id=\"Four_0\">4.0 Requirements<\/h3>\n<h4 id=\"Four_1\">4.1 General Requirements<\/h4>\n<p>Prior to implementation of information systems, WSU Information System Owners, or their delegates, are required to remediate software and firmware vulnerabilities and flaws. Security relevant software and firmware updates are to be installed in accordance with <a href=\"https:\/\/policies.wsu.edu\/prf\/index\/manuals\/business-policies-and-procedures-manual\/bppm-87-30\/\">UPPM 87.30<\/a>.<\/p>\n<p>Software updates are to be tested in a non-production environment.&nbsp;<\/p>\n<p>Centrally managed spam protection mechanisms must be employed at information system entry and exit points to detect and&nbsp;act&nbsp;on unsolicited messages.&nbsp;<\/p>\n<p>Security tool malicious code protection mechanisms must be employed at information system entry and exit points as well as system endpoints.&nbsp;&nbsp;<\/p>\n<p>The malicious code and spam protection mechanisms are to be automatically updated whenever new releases are available, in accordance with WSU\u2019s OISA <a href=\"https:\/\/its.wsu.edu\/documents\/2026\/01\/system-and-information-integrity-standard.pdf\">standards (PDF)<\/a>.<\/p>\n<p>Malicious code protection mechanisms&nbsp;must&nbsp;perform periodic scans of information systems and take automated actions against any discovered malicious code.&nbsp;<\/p>\n<p>File scanning&nbsp;must&nbsp;be configured to run real-time for&nbsp;files from external sources, as files are downloaded, opened, or executed.&nbsp;<\/p>\n<p>Upon detection of malicious code, the malicious code protection mechanisms&nbsp;must&nbsp;block and\/or quarantine malicious code and send alerts to the&nbsp;WSU Security Operations Center (SOC).&nbsp;<\/p>\n<p>Information&nbsp;System&nbsp;Owners, or&nbsp;their&nbsp;delegates, must ensure that information systems are&nbsp;monitored&nbsp;to detect:&nbsp;<\/p>\n<ul>\n<li>Attacks;&nbsp;<\/li>\n<li>Indicators of potential attacks; and&nbsp;<\/li>\n<li>Unauthorized use.&nbsp;&nbsp;<\/li>\n<\/ul>\n<p>Information systems are to be&nbsp;monitored&nbsp;continuously to provide analysis of alerts and\/or notifications generated by institutional information systems.&nbsp;<\/p>\n<p>The level of information system monitoring&nbsp;is to&nbsp;be heightened when there is&nbsp;an indication&nbsp;of increased risk to operations, assets, and\/or individuals.&nbsp;<\/p>\n<p>Business units&nbsp;are to&nbsp;receive system security alerts, advisories, and directives on an ongoing basis:&nbsp;<\/p>\n<ul>\n<li>Internal security alerts, advisories, and directives&nbsp;are to&nbsp;be&nbsp;generated and&nbsp;disseminated&nbsp;as necessary.&nbsp;<\/li>\n<li>Security alerts, advisories, and directives are to be implemented in accordance with WSU\u2019s OISA <a href=\"https:\/\/its.wsu.edu\/documents\/2026\/01\/system-and-information-integrity-standard.pdf\">standards (PDF)<\/a>.<\/li>\n<\/ul>\n<p>Business&nbsp;Units&nbsp;are to&nbsp;ensure that applicable internal security alerts, advisories, and directives are&nbsp;disseminated&nbsp;to institutional&nbsp;Area&nbsp;Technology&nbsp;Officers (ATOs),&nbsp;Information&nbsp;System&nbsp;Owners, and other business unit personnel as needed.&nbsp;&nbsp;<\/p>\n<p>Business units&nbsp;must&nbsp;maintain&nbsp;a list of authorized business information systems and software.&nbsp;The list&nbsp;is to&nbsp;be protected to prevent loss of integrity.&nbsp;<\/p>\n<p>WSU&nbsp;personnel&nbsp;are to&nbsp;be alerted to failed security and privacy verification tests and when anomalies are discovered.&nbsp;<\/p>\n<p>WSU&nbsp;developers&nbsp;must ensure error messages generated from the information system&nbsp;provide&nbsp;the information necessary for corrective actions without revealing information that could be exploited by adversaries.&nbsp;&nbsp;<\/p>\n<h4 id=\"Four_2\">4.2 Moderate- and High-Impact Systems<\/h4>\n<p>In addition to the above, the following requirements apply to all moderate and high-impact systems.<\/p>\n<p>Moderate- and high-impact&nbsp;systems&nbsp;must&nbsp;use automated mechanisms to&nbsp;determine&nbsp;if system components have applicable security&nbsp;relevant software and firmware updates installed.&nbsp;<\/p>\n<p>Moderate- and high-impact systems&nbsp;must&nbsp;define and implement controls to protect the&nbsp;system&nbsp;memory from unauthorized code execution.&nbsp;<\/p>\n<p>Moderate- and high-impact systems&nbsp;must&nbsp;employ automated tools and mechanisms to support analysis of events.&nbsp;<\/p>\n<p>Moderate- and high-impact systems must&nbsp;define and&nbsp;monitor&nbsp;inbound and outbound communications traffic for unusual or unauthorized activities or conditions.&nbsp;<\/p>\n<ul>\n<li>Alerts&nbsp;must&nbsp;notify relevant personnel when indications of compromise or potential compromise occur.&nbsp;<\/li>\n<\/ul>\n<p>Moderate- and high-&nbsp;impact systems must&nbsp;use integrity verification tools to detect unauthorized changes to the software, firmware, and information.&nbsp;<\/p>\n<ul>\n<li>Response actions&nbsp;must&nbsp;occur when unauthorized changes to the software, firmware, and information are detected.&nbsp;<\/li>\n<li>Integrity checks&nbsp;are to&nbsp;be performed during system startup, restart, and shutdown.&nbsp;<\/li>\n<li>Detection of unauthorized changes to authorized business systems and software&nbsp;is to&nbsp;be processed&nbsp;in accordance with&nbsp;<a href=\"https:\/\/policies.wsu.edu\/prf\/index\/manuals\/business-policies-and-procedures-manual\/bppm-87-55\/\">UPPM 87.55<\/a>.&nbsp;<\/li>\n<\/ul>\n<p>Moderate- and high-impact&nbsp;systems&nbsp;must&nbsp;implement cryptographic authentication mechanisms to verify the integrity of software or firmware components.&nbsp;<\/p>\n<p>Moderate- and high-impact systems must&nbsp;validate&nbsp;syntax and semantics of system inputs to prevent cyberattacks, such as cross-site scripting and a variety of injection attacks.&nbsp;&nbsp;<\/p>\n<h4 id=\"Four_3\">4.3 High-Impact Systems<\/h4>\n<p>In addition to the above, the following requirements apply to all high-impact systems.<\/p>\n<p>High-impact systems must&nbsp;consider&nbsp;enabling&nbsp;provisions to ensure encrypted communications are visible to WSU monitoring tools and mechanisms.&nbsp;<\/p>\n<p>High-impact systems must&nbsp;automatically alert personnel when indications of inappropriate or unusual activities occur as defined in <a href=\"https:\/\/policies.wsu.edu\/prf\/index\/manuals\/business-policies-and-procedures-manual\/bppm-87-50\/\">UPPM 87.50<\/a>.<\/p>\n<p>High-impact systems must&nbsp;regularly verify the correct operation of security and privacy functions during system transitional states and upon command by a user with&nbsp;appropriate privilege.&nbsp;<\/p>\n<p>High-impact systems must&nbsp;employ automated tools to notify relevant personnel upon discovering discrepancies during integrity verification.&nbsp;<\/p>\n<p>When integrity violations are discovered, high-impact systems are to&nbsp;be configured to automatically shut down, restart,&nbsp;and\/or trigger an audit alert.<\/p>\n<h3 id=\"Five_0\">5.0 Training<\/h3>\n<p>See <a href=\"https:\/\/policies.wsu.edu\/prf\/index\/manuals\/business-policies-and-procedures-manual\/bppm-87-21\/\">UPPM 87.21<\/a> for training requirements related to UPPM Chapter 87.<\/p>\n<p>In addition to the requirements in <a href=\"https:\/\/policies.wsu.edu\/prf\/index\/manuals\/business-policies-and-procedures-manual\/bppm-87-21\/\">UPPM 87.21<\/a>, Information System Owners are responsible for ensuring that users receive appropriate information security and privacy training commensurate with their roles, responsibilities, and authorized access to information systems under the Information System Owner\u2019s authority.<\/p>\n<p style=\"font-size: .8rem\">_______________________<br><strong>Revisions:<\/strong>&nbsp; Feb. 2026 (Rev. <a href=\"https:\/\/policies.wsu.edu\/prf\/bppm-manual-revisions\/bppm-revision-651\/\">651<\/a>); July 2020 &#8211; new policy (Rev. <a href=\"https:\/\/policies.wsu.edu\/prf\/bppm-manual-revisions\/bppm-revision-552\/\">552<\/a>)<\/p>\n\n<\/div>\r\n\n<\/div>","protected":false},"excerpt":{"rendered":"<p>University Policies and Procedures Manual System and Information Integrity<\/p>\n","protected":false},"author":1061,"featured_media":0,"parent":50633,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_wsuwp_accessibility_report":null},"wsuwp_university_location":[],"wsuwp_university_org":[],"_links":{"self":[{"href":"https:\/\/policies.wsu.edu\/prf\/wp-json\/wp\/v2\/pages\/43481"}],"collection":[{"href":"https:\/\/policies.wsu.edu\/prf\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/policies.wsu.edu\/prf\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/policies.wsu.edu\/prf\/wp-json\/wp\/v2\/users\/1061"}],"replies":[{"embeddable":true,"href":"https:\/\/policies.wsu.edu\/prf\/wp-json\/wp\/v2\/comments?post=43481"}],"version-history":[{"count":26,"href":"https:\/\/policies.wsu.edu\/prf\/wp-json\/wp\/v2\/pages\/43481\/revisions"}],"predecessor-version":[{"id":71358,"href":"https:\/\/policies.wsu.edu\/prf\/wp-json\/wp\/v2\/pages\/43481\/revisions\/71358"}],"up":[{"embeddable":true,"href":"https:\/\/policies.wsu.edu\/prf\/wp-json\/wp\/v2\/pages\/50633"}],"wp:attachment":[{"href":"https:\/\/policies.wsu.edu\/prf\/wp-json\/wp\/v2\/media?parent=43481"}],"wp:term":[{"taxonomy":"wsuwp_university_location","embeddable":true,"href":"https:\/\/policies.wsu.edu\/prf\/wp-json\/wp\/v2\/wsuwp_university_location?post=43481"},{"taxonomy":"wsuwp_university_org","embeddable":true,"href":"https:\/\/policies.wsu.edu\/prf\/wp-json\/wp\/v2\/wsuwp_university_org?post=43481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}