The University of Illinois System owns all information gathered, stored, or maintained for business purposes, unless otherwise stated in a contractual agreement. This ownership includes all system information regardless of location or media. Such information is to be used only for conducting system business.
People who act as stewards or caretakers for the business financial information of the system have a responsibility to ensure that business is transacted legally, protect the assets of the system, and avoid conflicts of interest.
System units have unlimited, read-only access to most business financial information, but must follow the standard access approval process that includes Unit Security Contacts and Administrative Information Technology Services (AITS). Unit heads are responsible for the security of system data used by their unit. Unit heads must ensure that that Unit Security Contacts are notified in a timely manner when employees transfer to another unit or no longer work for the University of Illinois System.
Individuals must report known or suspected security violations to the Associate Vice President for Administrative Information Technology Services (AITS) or delegate.
The system has a fiduciary responsibility regarding business financial information (including Social Security Numbers). The system will respond to security violations by:
Business financial information covered by this policy includes but is not limited to information held in systems where financial, payroll, employment, and student transactions can be started, routed, approved, and/or completed.
Employees, contractors, and students are expected to exercise responsible, ethical behavior when using system computers, information, networks, or resources.
Individual responsibilities include preserving the confidentiality and security of data to which the user has been granted access and ensuring that data are used only for and in the conduct of system business. These responsibilities also include the proper storage, access control, and disposal of private and confidential data presented to the user in any form.
Unit heads are responsible for establishing proper data controls, such as;
Last Updated: May 21, 2020 | Approved: Senior Associate Vice President for Business and Finance | Effective: May 21, 2020