Submit a Help Request (804) 828-2227 |
Send us an e-mail
Get help quickly

Call (804) 828-2227 for immediate assistance.

Information Technology Policies, Standards, Baselines and Guidelines

Virginia Commonwealth University provides and maintains computing resources to support the University's mission critical operations of education, research, service and administration. In order to ensure that these resources are used ethically, equitably, and legally by faculty, staff and students, VCU has established certain IT policies, standards, baselines, and guidelines.  All users of VCU systems, data, information and technology resources must adhere to these requirements.

Shown below is the Information Technology Policy Framework listing the IT Policies, Standards, Baselines and Guidelines.  Highlighted document names contain links to view the currently published version.  All current policies can also be found on the University's Policy Library.  In addition, documents planned for development, in development or in the review and approval process are also listed.  Links to the finalized and published documents will be provided as those documents become available.

The Baseline documents are technical documents for use by IT professionals. They can be found in the IT Professionals Intranet (ITPI) under IT Resources - Security Baselines unless otherwise noted.  Access to the IT Professionals Intranet is restricted to authorized IT professionals.  IT professionals can request access by contacting

Key to Acronyms:

NID - New in Development

NIRAP - New in Review/Approval Process

RID - Revisions in Development

RIRAP - Revisions in Review/Approval Process

TBD - To Be Developed


Information Technology Policy Framework 2016

 Computer and Network Resource Use Policy 

Information Security Policy

Application Security Standard  (NID)

Business Associates Standard (RID)

Change Management Standard (NID)

Data Classification Standard  (RIRAP)

Data Handling and Storage Standard (NID)

Email and Collaboration Tools Security Baseline (TBD)

Media Sanitization Security Guideline (ITPI)

Research Information Security Baseline (ITPI)

Removable / Portable Storage Device Security Baseline (TBD)

System Backup Baseline (TBD)

Encryption Security Standard

Data Encryption Baseline (TBD)

Incident Response Standard

Network Management and Security 

Network Configuration and Security Baseline (ITPI)

Password, Authentication and Access Standard 

Password Baseline (TBD)

Personnel Security Standard (NID)

Physical Security Standard (NID)

Privacy Standard (TBD)

Remote Access Standard

Risk Management Standard (NID)

System Security Standard (RID)

Active Directory Management Baseline (ITPI)

Apache Tomcat Server Configuration Baseline (ITPI)

Apache Web Server Configuration Baseline (ITPI)

Apple Desktop / Laptop Configuration Baseline (ITPI)

Application Security Baseline (ITPI)

Automated Software Distribution Baseline (ITPI)

Apple iOS Configuration Baseline (TBD) 

Google Android Configuration Baseline (TBD)

Linux Desktop / Laptop Configuration Baseline (ITPI)

Linux Server Configuration Baseline (ITPI)

Microsoft IIS Web Server Configuration Baseline (ITPI)

Microsoft SQL Server Configuration Baseline (ITPI)

MySQL / MARIADB Configuration Baseline (ITPI)

Oracle Configuration Baseline (ITPI)

Public, Classroom, and Lab Computer Configuration Baseline (RID)

VCU IT System Preā€Authentication Banner Text (ITPI)

Windows Desktop / Laptop Configuration Baseline (ITPI)

Windows Server Configuration Baseline (ITPI)

 Exposure and Breach of Information Policy

 Records Management Policy

Data Retention/Schedule Standard (TBD)

 Web Content, Hosting, and Management Policy (NIRAP)

VCU Web Standards and Guidelines (NIRAP)