Information Technology Governance, Risk, and Compliance
Information Technology Governance, Risk, and Compliance (IT-GRC) provides leadership in developing, delivering, and maintaining programs and services that support Rutgers IT’s strategic priorities. These programs and services include cybersecurity policy development, cybersecurity risk management (risk assessment, mitigation, and monitoring), cybersecurity compliance program strategy (PCI, GLBA, CMMC, etc.), and cybersecurity awareness and training services.
About our organization
Cybersecurity Compliance Program
The Cybersecurity Compliance Program assists technical and business teams, as well as the research community, with meeting regulatory and legal requirements to include contract reviews, annual compliance assessments, and mandated Security Awareness Training (i.e., Gramm-Leach-Bliley Act (GLBA), Payment Card Industry Data Security Standard (PCI-DSS), etc.).
Data Loss Prevention Services
Data Loss Prevention (DLP) services are available to departments, schools and units that manage data classified as Critical, Restricted and/or Internal under the 70.1.2-Information Classification Policy.
Cybersecurity Risk Management
Rutgers’ Cybersecurity Risk Management Program involves the identification, assessment, and prioritization of risks following a coordinated and efficient application of IT resources.
More cybersecurity resources
Read more about policies, tips, training, and more that help the Rutgers community protect accounts, devices, and data while meeting security and compliance requirements.
Cybersecurity Awareness and Training Program
The Cybersecurity Awareness and Training Program provides clinical, academic, and administrative staff with educational offerings meeting regulatory training requirements (i.e. PCI-DSS, GLBA, CMMC, etc.), supplemental training on handling sensitive Rutgers data, and general information for Rutgers community members on how to protect their information online.
