2025 IT Policy and Standard Updates

Issue Date
Section
Shared Responsibility & Unit Support
Newsletter Reference
Preview

Shared Responsibility & Unit Support

2025 IT Policy and Standard Updates

Notepad with Policies written on the top of the page

As the university’s digital environment evolves in response to global technological developments and the needs of the U-M community, so do our cybersecurity practices and underlying IT policies and standards.

Here is a roundup of the IT policies and standards that were updated in 2025:

In early 2026, we published an update to Personally Owned Devices that Access or Maintain Sensitive Institutional Data (SPG 601.33) to adjust the definition of sensitive university data in alignment with Institutional Data Stewardship Policy (SPG 601.12) and the university data classification levels.

Later in the year, we are queuing up reviews and revisions of  Vulnerability Management (DS-21) and Disaster Recovery Planning and Data Backup for Information Systems and Services (DS-12).
To stay up to date on recent and upcoming IT policy and standard revisions, visit the Information Technology Policies Under Review page on the VPIT-CIO website.