Information Technology Governance, Risk, and Compliance

Information Technology Governance, Risk, and Compliance (IT-GRC) provides leadership in developing, delivering, and maintaining programs and services that support Rutgers IT’s strategic priorities. These programs and services include cybersecurity policy development, cybersecurity risk management (risk assessment, mitigation, and monitoring), cybersecurity compliance program strategy (PCI, GLBA, CMMC, etc.), and cybersecurity awareness and training services.

Report a suspected scam, breach, or theft.

About our organization

Cybersecurity Compliance Program

The Cybersecurity Compliance Program assists technical and business teams, as well as the research community, with meeting regulatory and legal requirements to include contract reviews, annual compliance assessments, and mandated Security Awareness Training (i.e., Gramm-Leach-Bliley Act (GLBA), Payment Card Industry Data Security Standard (PCI-DSS), etc.).

Data Loss Prevention Services

Data Loss Prevention (DLP) services are available to departments, schools and units that manage data classified as Critical, Restricted and/or Internal under the 70.1.2-Information Classification Policy.

Cybersecurity Risk Management

Rutgers’ Cybersecurity Risk Management Program involves the identification, assessment, and prioritization of risks following a coordinated and efficient application of IT resources.

More cybersecurity resources

Read more about policies, tips, training, and more that help the Rutgers community protect accounts, devices, and data while meeting security and compliance requirements.

Cybersecurity Awareness and Training Program

The Cybersecurity Awareness and Training Program provides clinical, academic, and administrative staff with educational offerings meeting regulatory training requirements (i.e. PCI-DSS, GLBA, CMMC, etc.), supplemental training on handling sensitive Rutgers data, and general information for Rutgers community members on how to protect their information online.