The Office of Information Technology Cybersecurity department and distributed campus IT partners have launched Phase III of the Computer Security Standard (CSS). 

The Office of Information Technology Cybersecurity department and distributed campus IT partners have launched Phase III of the Computer Security Standard (CSS). The CSS establishes mandatory cybersecurity requirements to protect research, data, and operational systems at Georgia Tech by consistently applying security controls across desktops, laptops, and servers used to store, process, or transmit Institute data. 

The CSS also requires alignment of procurement activities with institutional deadlines and ensuring appropriate IT oversight for tracking IT-related expenditures. This standard ensures all computer purchases and transfers meet CSS requirements and are properly configured before deployment. 

Phase III applies to Default and Alternate Control Plan 1 Compliance and has a compliance deadline of Sept. 20. During this phase, IT professionals (computer service representatives) will work with faculty, researchers, and research administrators to identify impacted devices, determine classifications, and implement required security controls. Early engagement with your department’s IT professional is encouraged to help ensure compliance and minimize disruptions to research activities. 

To support this transition, Cybersecurity will maintain the CSS Companion Guide for IT staff and provide training sessions. The Information Security Procedures, Standards, and Guidelines webpage will be routinely updated, outlining required steps and additional resources and tools.   

For additional questions or support, email support@oit.gatech.edu.