Texas A&M UniversityWork In Progress

Technology Services

Compliance & Policy Posture

A representative compliance posture view with framework readiness, evidence pressure, and control-level risk signals.

Demo data Updated 15 min ago
4Tracked Frameworks

Representative FERPA, HIPAA, NIST, and system policy workstreams.

11Controls At Risk

Controls without current evidence, owner assignment, or recent review.

9Evidence Requests

Open items that must be satisfied in the next review cycle.

Framework Posture

Sample posture summaries for the frameworks Technology Services is likely to juggle in parallel.

NIST CSF operational baseline

Control set: core platform

Yellow
78% complete↑ 3%

Most gaps sit in evidence quality, not missing controls. Device lifecycle reporting still needs cleaner ownership.

78% complete
Owner: Security
Review Apr 9

FERPA support process alignment

Service delivery and access reviews

Amber
50% complete↑ 3%

Process exists, but the intake-to-approval trail for delegated access still needs a consistent retention pattern.

3 controls open
Owner: Service Desk
Policy note pending

HIPAA adjunct hosting boundaries

Infrastructure and contracts

Watch
50% complete↑ 3%

The control language is stable, but two vendor systems need refreshed data-handling attestations.

2 vendor artifacts
Owner: Procurement
Escalate if late

Evidence Queue

Representative evidence and control tasks to make the module useful during design review.

Conditional access exception signoff packet

Identity controls

Due soon

Consolidate approver signoff, exception rationale, and expiration tracking into one retained packet.

Due in 3 days Owner: IAM Packet 80% ready

Admin account quarterly access review

Privileged access

Pending evidence

Screenshots are captured, but the reviewer attestations need to be attached before the control can move green.

41 accounts Owner: Security lead Needs signatures

Shared mailbox retention rule inventory

Messaging and records

In progress

Map policy intent to the current config so downstream legal and compliance teams can self-serve the rationale.

Owner: Messaging 7 mailboxes sampled Draft ready