Data Center and Server Room Policy

Summary

The purpose of the Data Center and Server Room Policy is to describe the minimum requirements for designing, installing, securing, monitoring, maintaining, protecting, and decommissioning a data center or server room at the University of Kansas.

Body

PRINT DISCLAIMER: Official version of this document is accessible in the online policy library at https://policyoffice.ku.edu/. Printed copies may not reflect the most recent updates.

DOCUMENT TYPE:

Policy

PURPOSE:

The purpose of the Data Center and Server Room Policy is to describe the minimum requirements for designing, installing, securing, monitoring, maintaining, protecting, and decommissioning a data center or server room at the University of Kansas.

APPLIES TO:

University employees (faculty, staff, and student employees), students, and other covered individuals (e.g., University affiliates, vendors, independent contractors, etc.) in their access and usage of University technology resources during the course of conducting University business.

CAMPUS:

 Lawrence

POLICY STATEMENT:

All data centers or server rooms performing any type of computer technology work under the auspices of the University shall implement and maintain their respective technology services via the approved Kansas University Data Center and Server Room Standards only.

EXCLUSIONS OR SPECIAL CIRCUMSTANCES:

Exceptions to this policy and associated standards shall be allowed only if previously approved by the KU Information Technology Security Office and such approval documented and verified by the Chief Information Officer.

CONSEQUENCES:

Faculty, staff, and student employees who violate this University policy may be subject to disciplinary action for misconduct and/or performance based on the administrative process appropriate to their employment.

Students who violate this University policy may be subject to proceedings for non-academic misconduct based on their student status.

Faculty, staff, student employees, and students may also be subject to the discontinuance of specified information technology services based on policy violation.

CONTACT:

Chief Information Officer
Price Computing Center
1001 Sunnyside Avenue
Lawrence, KS 66045
785-864-4999
kucio@ku.edu

APPROVED BY:

Chief Information Officer

APPROVED ON:

2009-12-10

EFFECTIVE ON:

2009-12-10 

REVIEW CYCLE:

Annual (As Needed)

BACKGROUND:

The standards associated with this policy are designed to represent the baseline to be used by the Data Center and Server Rooms located on the Lawrence campus. While specific-standards organizations are referenced for examples of best practices, it should be noted that site conditions, special requirements, and cost of modification will be taken into consideration when implementing the final configuration of a site. The standards will be regularly reviewed and updated based on new industry standards, new technology, and lessons learned.

RELATED STATUTES, REGULATIONS, AND/OR POLICIES:

Data Center and Server Room Standards

Data Classification and Handling Policy

Data Classification and Handling Procedures Guide

Information Access Control Policy

Virtual Private Network (VPN) Remote Access Procedure

Virtual Private Network (VPN) Service on the University of Kansas Data Network

Information Technology Security Policy

Network Policy

Security Policy Procedure: Risk and Vulnerability Assessments

Security Policy: Assessment for Local IT Environments and Outline for Risk and Vulnerability Assessments

Telecommunications Physical Infrastructure

Telecommunications Wiring Policy

Wireless Local Area Network (LAN) Systems Policy

CHANGE HISTORY:

03/26/2025: Migration to TeamDynamix from Drupal.
10/11/2024: Updated broken link.
04/11/2022: Updated link and corrected a grammatical error.
02/15/2021: Reviewed policy and updated contact information.
10/16/2014: Policy formatting cleanup (e.g., bolding, spacing).

Details

Details

Article ID: 20998
Created
Thu 3/13/25 1:08 PM
Modified
Mon 3/31/25 1:05 PM

Related Articles

Related Articles (13)

The purpose of the Data Center and Server Room Standards is to describe the minimum requirements for designing, installing, securing, monitoring, maintaining, protecting, and decommissioning a data center or server room at the University of Kansas.
Information is a valuable University asset and is critical to the mission of teaching, research, and service to Kansans.Determining how to protect and handle information depends on a consideration of the information’s type, importance, and usage.Classification is necessary to understand which security practices should be used to protect different types of information. The more protected the information needs to be, the more practices are required.
This Procedures Guide for the University community was created to help you effectively manage information in your daily mission-related activities. Determining how to protect & handle information depends on a consideration of the information’s type, importance, and usage. These procedures outline the minimum level of protection necessary when performing certain activities, based on the classification of the information being handled. Classification is necessary to understand which security p
To ensure the security and integrity of university data and information assets as well as safeguard the information of its constituents. All Kansas University technology resources will adhere to a uniform access control standard and framework.
This Information Security Policy (“Policy”) defines the security requirements that everyone who works or studies at KU Lawrence campus and all reporting units is expected to be familiar with and consistently follow. These security measures are set forth to avoid problems that affect the Confidentiality, Integrity, and Availability of information and systems at the University.
To define the University network and establish operational provisions governing use and operation of the network.
The procedure describes a framework for the assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic and paper data held by units of the University and outlines those items normally assessed in a University conducted Risk and Vulnerability Assessment.
To ensure the registration and collection of accurate information about all servers owned, operated or housed by the University of Kansas Lawrence campus and all reporting units and affiliated organizations, or servers that store data belonging to the University regardless of their location. This policy also describes the criteria for centralization of these systems into centrally administered data centers.
This policy covers the use of KU property to enable a telecommunications component on the Lawrence and Edwards campuses of the University of Kansas, regardless of location or placement on University buildings, towers or land, including that which is owned /operated by non-University entities but located on University property.
To establish principles and provisions to guide the University in the construction and ongoing management of its telecommunications cabling infrastructure.
To define administrative and operational procedures associated with VPN Remote Access Service. 
This policy outlines the purpose and approved use of Virtual Private Networks on the University of Kansas network
This policy outlines a uniform set of components, installation practices, processes, procedures and operational criteria, in order to manage (802.11x) wireless LAN systems and to ensure that these resources are used in a secure and efficient fashion.