Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Information Technology Cybersecurity topic
No spam. Unsubscribe anytime.
TSU trustees hear IT security update; administration outlines AI, intranet and email policy changes
Summary
Interim CIO Sterling Sanders told the Tennessee State University Board of Trustees the university has met Gramm‑Leach‑Bliley Act requirements, strengthened cybersecurity with Sophos and MFA, tested disaster recovery, and is developing an umbrella AI policy and an intranet/email policy to improve security and user experience.
Get email alerts on the Information Technology Cybersecurity topic
No spam. Unsubscribe anytime.
Interim Chief Information Officer Sterling Sanders told the Tennessee State University Board of Trustees in March that Information Technology has met federal security requirements and taken steps to reduce cyber risk while planning a redesigned intranet and a campus AI policy.
The update, delivered to the board during its March meeting, said TSU has completed measures intended to satisfy the Gramm‑Leach‑Bliley Act (GLBA) requirements for data protection, including appointing a chief information security officer (Dr. Bing Lee), deploying Sophos for endpoint and network protection, requiring multi‑factor authentication and using the KnowBe4 training platform for phishing awareness.
Sanders said the IT unit conducts weekly change‑management reviews, isolates outdated systems on segmented networks, and completed a data recovery tabletop exercise on Dec. 18 that tested restoring Banner systems. The department also identified a need to migrate from tape backups to cloud backups and said it will seek funding to do so.
Jerome Oglesby, technology strategic adviser to the president, outlined a three‑phase technology plan: immediate operational and security fixes, midterm business‑process and application improvements, and a longer‑term five‑year modernization agenda. Oglesby said the near‑term work includes tightening policy and access controls and addressing outstanding audit items.
The board heard that TSU resolved its FY23 and FY24 IT‑related audit findings related to least‑privileged access and routine auditing of data‑center access. Sanders reported a recent penetration test and related work yielded an estimated $35,000 in savings.
On artificial intelligence, Sanders and Oglesby told trustees the university is developing an umbrella AI policy with separate sections governing institutional tools and individual usage by students, faculty and staff; the plan is to refine the policy and implement it before July 1. The administration said the AI policy will distinguish governance of tools versus user behavior and that Provost Melton’s draft policy will be incorporated and expanded.
Board members asked for clarification on the intranet and email changes. Sanders said the intranet will be a two‑phase effort: an interim internal site in a few weeks and a fuller intranet later. Email policy changes will separate accounts and entitlements for current employees and students from those for alumni and retirees.
Trustees were also told the university currently has about 400 web content managers across departments; the administration plans to streamline and reduce that number, add controls and consider additional staffing or funding to support web‑site improvements. The board was told the current webmaster is Tracy Jeanette and that centralization or added staff may be necessary as the web redesign proceeds.
The IT presentation concluded with an emphasis on sustaining improvements: the five‑year technology plan will include decisions about which services to keep in‑house versus outsource and what staffing is required to maintain new systems.

