Information Security Docs
Breadcrumbs

CISO Investigative Access Authority Policy

Purpose

Under Texas Administrative Code (TAC) Chapter 202 and UT System Policy UTS 165, the Chief Information Security Officer (CISO) has enterprise authority to access systems and information necessary to perform security investigations, reviews, compliance monitoring, and controls evaluation or testing. This access does not require prior approval from IT, data owners, or Legal. Denying or delaying access creates institutional risk and compliance exposure.

This Policy establishes the authority, scope, and procedures under which the CISO and authorized Information Security Office (ISO) personnel shall obtain unfettered and unobstructed access to institutional information systems, data, and resources for the purpose of:

  • Information security investigations.

  • Incident response and containment.

  • Threat detection and monitoring.

  • Risk assessment and compliance activities.

This Policy ensures that investigative access is conducted in a lawful, controlled, auditable, and risk-based manner while fulfilling Texas state and UT System requirements.

Scope and Applicability

Systems and Data

This Policy applies to:

  • All UTRGV-owned or managed information systems.

  • Cloud services, Software as a Service (SaaS) platforms, and vendor-hosted systems.

  • Network infrastructure, identity systems, and endpoints.

  • Logs, telemetry, and security monitoring systems.

  • Institutional data, including:

    • Confidential and regulated data, including data subject to FERPA, HIPAA, GLBA, and other applicable requirements.

    • Research and administrative data.

    • Security and audit records.

Personnel

This Policy applies to and authorizes investigative activities by:

  • The Chief Information Security Officer (CISO).

  • Information Security Office staff, including RSOC, GRC, Operations, Incident Response, and other ISO functions.

  • Authorized designees formally approved by the CISO.

This Policy also applies to institutional personnel, system owners, data owners, custodians, IT departments, and business units whose cooperation or resources are required to support authorized ISO activities.

Authority and Governing Requirements

This Policy is established pursuant to and in support of:

  • Texas Government Code Section 2054.136.

  • Texas Administrative Code (TAC) Chapter 202.

  • UT System Policy UTS 165, Information Resources Use and Security Policy.

  • UTRGV HOP ADM 09-101, Information Resources Use and Security.

Under these authorities, the CISO:

  • Has enterprise-wide authority over information security.

  • Is responsible for protecting the confidentiality, integrity, and availability of institutional information resources.

  • Must investigate, assess, and respond to information security risks and incidents.

  • Must determine and ensure that appropriate risk controls and mitigations are in place and functioning.

Accordingly, the CISO and delegated ISO personnel are authorized to access institutional systems, data, and logs without prior approval from system owners, custodians, or departments when required for security investigations, response activities, or compliance reviews.

Definitions

Click to expand...

Authorized ISO Personnel - Information Security Office staff or other designees formally authorized by the CISO to perform activities under this Policy.

Chief Information Security Officer (CISO) - The UTRGV official responsible for the institutional information security program and the authorities and responsibilities assigned to that role by applicable law, regulation, UT System policy, and UTRGV policy.

Information Security Office (ISO) - The UTRGV organizational function responsible for information security activities, including security operations, incident response, monitoring, risk and compliance activities, and related security functions.

Institutional Information Resources - UTRGV-owned or managed systems, networks, endpoints, cloud and hosted services, logs, telemetry, data, records, and other information resources within the scope of this Policy.

Investigative Access - Access to institutional information resources necessary to perform an information security investigation, incident response, threat detection or monitoring, risk assessment, compliance review, controls evaluation or testing, forensic analysis, or evidence collection.

System Owner, Data Owner, and Custodian - Institutional roles responsible for the governance, management, access, operation, or protection of information systems or data, as defined by applicable UTRGV and UT System requirements.

Policy Requirements

Investigative Access Authority

The CISO and authorized ISO personnel may access systems, logs, and data necessary to:

  • Investigate suspected or confirmed security incidents.

  • Identify vulnerabilities or threats.

  • Validate compliance with policies and regulations.

  • Perform monitoring, forensic analysis, and evidence collection.

  • Require cooperation from IT, system owners, and custodians.

No Prior Approval Requirement

Investigative access shall not require prior approval from:

  • System owners.

  • Data owners.

  • IT departments.

  • Individual business units.

Legal approval is not required for internal access by the ISO for security investigations, subject to the Legal and Privacy Coordination requirements below.

Mandatory Cooperation

All institutional personnel must:

  • Provide timely access to systems, logs, and information upon request by the ISO.

  • Not delay, obstruct, or condition access on additional approvals.

Immediacy During Incident Response

During active incidents, the ISO is authorized to:

  • Access systems immediately.

  • Isolate or contain systems when necessary.

  • Collect data and preserve evidence.

Delays due to approval workflows are not permitted during active incident response.

Minimum Necessary Principle

The CISO or designated ISO personnel will ensure that:

  • Access is limited to information relevant to the investigation or activity.

  • Over-collection or unnecessary exposure is avoided.

Confidentiality and Data Protection

All accessed data must:

  • Be protected according to its classification level.

  • Be handled in accordance with FERPA, HIPAA, GLBA, and other applicable laws, regulations, policies, and requirements.

ISO personnel are subject to strict confidentiality obligations when accessing, handling, preserving, analyzing, or disclosing information obtained through activities under this Policy.

Logging and Auditability

All investigative access activities must be logged where technically feasible. Logging shall include, where technically feasible:

  • The user performing the access.

  • Date and time.

  • Systems accessed.

  • Purpose, including the applicable case, incident, or activity.

Logs shall be retained in accordance with institutional retention policies and shall be available for audit.

Segregation of Duties

Where practicable, investigative actions shall be:

  • Peer-reviewed.

  • Documented and approved post hoc for audit defensibility.

Legal approval is not required for internal access by the ISO for security investigations.

Legal shall be engaged when:

  • There is litigation risk.

  • Law enforcement is involved.

  • Regulatory reporting requirements apply.

  • Information is to be disclosed externally.

If directed by Legal, investigations may be conducted under attorney-client privilege.

Prohibited Actions

The following actions are strictly prohibited:

  • Blocking or delaying ISO access.

  • Requiring Legal or management approval prior to fulfilling an authorized ISO request.

  • Blocking the creation of system-level accounts or access required for authorized ISO activities. Normal access processes will be observed.

  • Altering or deleting data during an investigation.

  • Retaliating against personnel who cooperate with an ISO investigation or authorized security activity.

Roles and Responsibilities

Chief Information Security Officer

The CISO shall:

  • Exercise enterprise-wide information security authority consistent with applicable requirements.

  • Authorize ISO personnel and designees to perform activities under this Policy.

  • Ensure appropriate risk controls and mitigations are established and functioning.

  • Oversee information security investigations, incident response, threat detection, monitoring, risk assessment, and compliance activities.

Information Security Office Personnel and Authorized Designees

Authorized ISO personnel shall:

  • Exercise investigative access only as necessary to perform authorized security activities.

  • Follow the minimum necessary, confidentiality, data protection, logging, auditability, and segregation-of-duties safeguards established by this Policy.

  • Protect information obtained through investigative access according to its classification and applicable legal, regulatory, and institutional requirements.

Data Owners

Data owners shall:

  • Maintain accountability for data governance.

  • Provide context and support for investigations.

  • Not restrict authorized ISO access.

IT and Custodians

IT personnel and custodians shall:

  • Provide system-level access and technical support required for authorized ISO activities.

  • Enable investigative activities.

  • Provide timely access to systems, logs, and information upon request by the ISO.

  • Not delay, obstruct, or condition access on additional approvals.

Institutional Personnel

All institutional personnel shall cooperate with authorized ISO activities and comply with the access and non-obstruction requirements established by this Policy.

Legal shall be engaged when the circumstances specified in the Legal and Privacy Coordination section apply and may direct that an investigation be conducted under attorney-client privilege.

Compliance and Enforcement

Compliance with this Policy may be assessed through security investigations, reviews, compliance monitoring, control evaluations or testing, audits, and other authorized information security activities.

Non-compliance may result in:

  • Escalation to executive leadership.

  • Formal policy violation.

  • Disciplinary action.

Exceptions

External References

  • Texas Government Code Section 2054.136.

  • Texas Administrative Code (TAC) Chapter 202.

  • UT System Policy UTS 165, Information Resources Use and Security Policy.

  • Family Educational Rights and Privacy Act (FERPA).

  • Health Insurance Portability and Accountability Act (HIPAA).

  • Gramm-Leach-Bliley Act (GLBA).

  • DIR Texas: Covered Applications and Prohibited Technologies.

Review and Revision History

This Policy shall be reviewed annually and updated as required.

Date

Action

Notes

Source effective date

Source document became effective as CISO Investigative Access Authority Standard, ISO-100-S1.

Source revision

Last revision date shown on the source Standard.

Contact Information

Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823