Published: November 2011
Last Revised: August 2026
- Authorization and Scope
- Rationale
- Principles
- Roles and Responsibilities
- IT Policy Governance and Approval
- Stakeholder Involvement
- IT Policy Structure and Criteria
- Approach and Publication
- IT Policy Life Cycle Process
- IT Policy Structure Definitions
Authorization and Scope
The responsibility for university-wide IT policy management has been assigned to the ITS Privacy and IT Policy Office. This includes:
- Coordination of IT policy and underlying development, dissemination, and education
- Review and analysis of existing policies for continued applicability and effectiveness.
- Interpretation of current policy related to specific issues, situations and incidents.
The IT policy framework covers all campuses, including UM-Dearborn, UM-Flint, and Michigan Medicine; unit-level policies and guidelines are out of scope. It is a principle of this framework that, wherever appropriate, policies should apply to all members of the university community. University IT policies apply to all users of U-M IT resources, including students, faculty, staff, workforce members, and sponsored or guest users.
Rationale
Information technology policies articulate the university's vision, strategy, and principles as they relate to the management and use of information and information technology resources, while supporting core academic, research, and teaching and learning missions. Further, IT policies also ensure compliance with applicable laws and regulations, promote operational efficiency, and manage institutional risk by specifying requirements and standards for the consistent management of IT resources across the university. This university-wide IT policy framework specifies:
- Structure and criteria for what should be categorized as an IT policy, guideline, or standard
- A process for initiating, reviewing, approving, and expiring IT policies
- Ongoing roles and responsibilities associated with IT policy development and maintenance
Principles
The IT policy structure and process reflect the following principles:
- Policy work shall be initiated when there is a compelling need for new or revised policy. Triggers may include new technologies, new laws or regulations, or operational or compliance needs that are not appropriately covered by existing policies or guidance.
- Policies and guidance shall be credible, implementable, enforceable, and sustainable. Impact analysis on both IT systems and end-users should be included in the policy planning and review processes.
- Any unit may request consideration of new IT policies or changes to existing policies that apply university-wide; the process to be followed for such consideration is outlined in this IT policy development and administration framework.
- IT policy development will be accomplished via individual workgroups convened to address specific topics. Each team will include appropriate subject matter experts. ITS Privacy and IT Policy will provide a central coordination function to ensure consistency and to address policy dependencies.
- The policy development process will be transparent. Input from stakeholders will be addressed and/or incorporated throughout the process. Preliminary/interim policies and guidelines will be posted and disseminated to solicit feedback.
- The policy development process will be flexible. Circumstances may necessitate the publishing of best practices as a stop-gap to provide immediate guidance while a policy is being developed, vetted, and approved. In other cases, a policy may be established with detailed guidance to be provided at a later time.
- University-wide policies should be considered a floor, not a ceiling. Unit-level policies, guidelines, standards, or procedures may be developed to supplement university-wide guidance. They must meet the minimum criteria set forth in university-wide policies and related guidance, but may be more restrictive.
Roles and Responsibilities
The roles and responsibilities defined below represent the staff positions or groups most directly involved in IT policy development.
Vice President for Information Technology and Chief Information Officer (VPIT-CIO): The Vice President and CIO has overall responsibility for IT policy and policy development at U-M, and approves new and revised standards and guidelines based on the recommendation of the Chief Information Security Officer.
Executive Director of Privacy and Faculty Affairs: The Executive Director works with the Assistant Director of Privacy and IT Policy to ensure alignment of the IT Policy program with Office of the CIO and University of Michigan objectives and priorities.
Chief Information Security Officer (CISO): The CISO and ITS Information Assurance provide subject matter expertise and set direction for policies, standards and guidelines related to IT security.
IT Policy Staff: IT policy staff provide overall direction for the IT policy function, including responsibilities for identifying and prioritizing policy needs, ensuring appropriate campus involvement in policy development, and conducting research and benchmarking for emerging policy development.
The Assistant Director of Privacy and IT Policy provides day-to-day support for the policy development function, serves ex officio on policy development working groups, and plans and executes policy education and awareness efforts. Specifically, this includes managing an annual review and analysis of existing policies, standards, and guidelines for continued applicability and effectiveness; interpretation of current policies in response to unit/departmental inquiries or specific incidents.
IT Policy Governance and Approval
The IT policy function resides with the Office of VPIT-CIO, with delegated responsibilities to the ITS Office of Privacy and ITS Information Assurance for policy development, coordination, education, and maintenance.
The following identifies the different levels of governance review, approval, and vetting of policies, standards and guidelines (initially drafted by IT policy development working groups):
- Executive Director of Privacy and Faculty Affairs: Initial review of policies, guidelines, and standards.
- CISO: Initial review of policies, guidelines, and standards.
- VPIT-CIO: First level of governance review for IT policies; final approval of guidelines and standards before adoption and dissemination to campus.
- IT Council: Second level of governance review for new or substantially revised university IT policies.
Stakeholder Involvement
Campus stakeholders will be engaged throughout the IT policy development process—in both individual and group settings—to ensure that all appropriate perspectives are accounted for and incorporated as feasible in final versions of new or revised policies, standards, and guidelines. IA maintains a list of potential stakeholders to be involved at various stages in the IT policy life cycle process.
Specific individuals and groups will be identified during the planning and initiation phase of a given policy, standard, or guideline. Membership in policy development working groups will vary based on the primary content of a policy being developed. The IT Policy and Compliance Lead will serve ex officio and provide staff support to all working groups. In general, any faculty or staff member will be able to provide comments on draft and interim policies, standards, and guidelines on the IT policy web site. Specific stakeholders may be identified and solicited to provide input and review draft documents, while others may be only in the need to inform category.
Students, student groups, and student governments will have opportunities to provide input and feedback on draft policies, standards, and guidelines that deal with student code of conduct amendments or have the potential to impact availability of, or access to, IT resources for students.
IT Policy Structure and Criteria
Categories of university-wide guidance for additional information about these categories:
- IT Policies articulate the university's values, principles, strategies, and positions relative to a broad IT topic. They are designed to guide organizational and individual behavior and decision making. They are concise, high-level, and independent of a given technology. University IT policies are mandatory. All new or substantially revised policies, once approved by the policy owner(s), will be submitted to the Ethics, Compliance, and Integrity Office for inclusion in the online Standard Practice Guide.
Example: Information Security Policy (SPG 601.27) - IT standards specify requirements for becoming compliant with university IT policies, other university policies, as well as applicable laws and regulations. Standards may include technical specifications. Standards are mandatory.
Example: Third Party Vendor Security and Compliance (DS-20) - IT guidelines provide guidance and best practices relative to a particular IT topic. They may accompany, interpret, or provide guidance for implementing IT policies, other university policies, or applicable laws and regulations. University IT guidelines are not mandatory.
Example: Endpoint Protection Guidance.
Approach and Publication
The IT policy framework will create processes and structures that are consistent with the university Standard Practice Guide, specifically the Procedures for Development of University Policy on the SPG website as they apply to information and information technology policies. The SPG website maintains in its Policies by Category a section with all current information technology policies. All prospective new IT policies as well as existing IT policies that are being formally reviewed will be highlighted in Policies Under Review. Multiple communication methods and vehicles will be employed to widely disseminate policies, standards, and guidelines, both while under review and after final approval.
While it is necessary to provide a flexible policy/guidance structure that keeps pace with technological innovations, process simplicity will be balanced with concerns over legal exposure and assurance of stakeholder collaboration. Ultimately, this policy framework will result in a process that provides proper scoping, collaborative development, and structured vetting and approval.
IT Policy Life Cycle Process
The IT policy life cycle process applies to IT policies, standards, and guidelines. Standards and guidelines require fewer approvals than policies.
- Identification, Planning and Initiation
- Identify compelling need for new or updated policy/guidance. Drivers may include new regulatory requirements, technology developments, operational needs, and identification of current issues or gaps. Request may come from any unit, central office, or IA.
- Determine whether the need should be satisfied by a policy, guideline, or standard
- Identify sponsorship, stakeholders, working group members and their relevant roles
- Develop high level implementation impact analysis
- Obtain approval to proceed with draft policy (or guideline, standard)
- Prioritize and schedule policy work
- Development, Review, and Approval
- Draft initial policy (guideline, standard)
- Distribute to a small group of stakeholders for initial review and input
- Incorporate initial feedback
- Distribute to a larger group of stakeholders for review and input
- Post final draft on the IT policy web site for general feedback
- Review and, where appropriate, incorporate feedback
- Present to appropriate governance entity for approval
- Obtain approval
- Rollout
- Post and announce guidance (policy standard, guideline)
- Conduct educational activities
- Initiate implementation activities (efforts to develop/update standards and guidelines may be needed for some new policies)
- Determine ongoing review cycle.
- Compliance, Review and Maintenance
- Monitor compliance and effectiveness of implemented guidance
- Review and implement modifications per review cycle (last revision and review dates shall be posted on each policy). IA, the policy owner will generally be responsible for most policy reviews.
- Policy Retirement
- As part of the maintenance and review process, policies, standards, and/or guidelines may be identified as out-of-date or no longer needed. They will be retired via the same process by which they were approved.
IT Policy Structure Definitions
| Category | Purpose | Approval Authority | Frequency of Change | Characteristics and Notes |
|---|---|---|---|---|
| IT Policies |
| Policy Owner | Review every 5 years |
|
| IT Standards |
| VPIT-CIO or delegate | Review every 2 years |
|
| IT Guidelines |
| IT process owner for a given topic | Review annually |
|
| Unit-or Campus-Level IT Policies, Standards, or Guidelines | As defined above when unique unit-level requirements exist | Applicable campus authority | Review every 2 years |
|