Skip to main content

Information Security Office

The Information Security Office (ISO) orchestrates efforts and provides services to protect the information assets that are important to Stanford.

In this modern age of data centricity and pervasive computing, information privacy and security are increasingly essential, yet increasingly elusive. What has become one of the greatest challenges of our time, information security is multifaceted and spans all elements of the Stanford enterprise. As such, ISO collaborates with partners throughout the university and supports more than 50 distinct services in order to maintain Stanford's comprehensive and leading cybersecurity program.

Pursuant to ISO's mission "to protect the information assets important to Stanford", information security is largely an exercise in risk management. Accordingly, ISO is deeply involved in the university's Enterprise Risk Management (ERM) effort, ensuring that Stanford’s top cybersecurity risks are identified and that mitigation plans are in place.

The Information Security Office dual reports into UIT and the Office of the Chief Risk Officer (OCRO). This structure enables ISO to work closely with IT while maintaining a strong connection with Privacy, Internal Audit, Enterprise Risk Management, Risk Management (insurance), and Ethics and Compliance.

Cybersecurity Governance, Risk and Compliance (GRC)

The Cybersecurity Governance, Risk and Compliance (GRC) team spearheads policy and procedure development in the university’s information security space. They provide oversight to security risk and compliance services, including Stanford’s Minimum Security Standards, General Data Protection Regulations (GDPR), Payment Card Industry Data Security Standard (PCI-DSS), and enterprise assessments and reviews. They also manage ISO’s education, awareness, and outreach programs, including Stanford Information Security Academy (SISA), Cybersecurity & Privacy Festivals, Phishing Awareness, and much more.

Security Operations (SecOps)

The Security Operations (SecOps) team detects and responds to cybersecurity threats, delivers safer computing environments, and engages with the Stanford community as partners in protecting University data. 

The team's work is organized around four areas of focus: detecting threats, vulnerabilities, misconfigurations, and other risks using tools enhanced by sophisticated automation; responding to incidents through investigation, assessment and action; delivering guardrails, controls, and tools that help campus service owners secure their systems; and engaging the community through education and outreach to build a shared sense of responsibility for cybersecurity at Stanford.

School of Medicine IRT Security

Dual reporting into ISO and Stanford Health Care's Technology & Digital Solutions (TDS), the School of Medicine's security team provides specialized tools for SoM (e.g., AMIE and SUSI), firewall rule management, network anomaly monitoring, encrypted flash drives, annual onboarding for high risk communities (hospital residents and Med School trainees), and coordination for security activities with Stanford Medicine (SoM, SHC, and SMCH).