Plicy Planning and Analysis Team (PAT) Charter Purpse f this Charter Dcument This charter defines the missin, guiding principles, scpe, rles, membership, and peratins fr the Plicy Planning and Analysis Team (PAT), as envisined under the IT gvernance structure. This charter will be reviewed annually. Authrizatin f the Plicy Planning and Analysis Team PAT is advisry t the CIO and the ITC. The fllwing individuals authrize the peratin f the PAT and serve as its executive spnsrs. Chief Infrmatin Officer (CIO) and Vice Prvst fr Infrmatin Technlgy Chair f the Infrmatin Technlgy Cmmittee (ITC) The executive spnsrs apprve the charter, and may make temprary r permanent adjustments t the missin, guidelines principles, scpe, rles, membership, and peratins f the team. Missin The missin f the Plicy Planning and Analysis Team (PAT) is t supprt the plicy-related activity f IT gvernance. The PAT helps IT gvernance ensure that IT plicies are necessary and apprpriate, the develpment prcess is cllabrative and transparent, and the supprting technical and prcedural implementatin enables efficient and effective cmpliance. The PAT maintains and iteratively imprves the IT Plicy Principles and Prcedures, guides IT plicy cmmunicatins and engagement with the UW-Madisn cmmunity, and evaluates suggestins fr new r revised IT plicies. Guiding Principles The Plicy Planning and Analysis Team (PAT) is guided by the fllwing principles: Cllabratin: IT plicies shuld be develped cllabratively t ensure that the needs and cncerns f relevant stakehlder grups are heard and addressed. Practical implementatin: IT plicies shuld be supprted by an apprpriate technical and prcedural implementatin that enables cmpliance in an efficient and effective manner. Cmpelling need: The need fr an IT plicy shuld be sufficiently cmpelling that it mtivates participatin in the cllabrative plicy develpment prcess, and mtivates the allcatin f sufficient resurces fr a practical implementatin. Transparency: Bth PAT peratins and plicy develpment shuld be transparent, hwever, peratins and develpment must nt reveal infrmatin that culd be harmful t the institutin r individuals. Representatin: PAT membership shuld represent a diversity f academic and administrative units. Cnsensus: Whenever pssible, decisins shuld be made by cnsensus. When cnsensus is nt pssible, minrity pinins shuld be recrded. Other principles are included in the IT Plicy Principles and Prcedures. August, 4, 2017 Page 1 f 5
Scpe IT Plicy is UW-Madisn plicy that gverns the develpment, use, and management f IT services and the prcesses fr the efficient and effective use f IT assets and resurces. The scpe f IT plicy is defined by the executive spnsrs in cnsultatin with IT gvernance, data gvernance, and ther ffices that publish UW-Madisn plicies. Examples f general areas f IT plicy are: Cybersecurity, Digital Accessibility, Electrnic Recrds Management Identity and Access Management Intellectual Prperty (in electrnic frm) IT Resurce Management Netwrking and Telecmmunicatins A particular plicy in these r ther areas might, r might nt, be treated as IT plicy. When this is unclear, the PAT may make the decisin, but a decisin by the executive spnsrs will supersede it. Data plicy, as defined by UW-Madisn data gvernance, is ut-f-scpe fr IT plicy, althugh IT plicy may supprt the implementatin f data plicy. IT Plicy is develped using the prcess described in the IT Plicy Principles and Prcedures (PP&P). IT plicy-related dcuments such as guidelines, prcedures, principles, and standards may als be develped in a similar manner, especially if they are clsely assciated with an IT plicy. In additin t IT Plicy per se, there are ther UW-Madisn plicies with significant IT cmpnents r implicatins. These are develped using special prcesses agreed upn by the executive spnsrs and the ther ffices that publish UW-Madisn plicies. Rle Plicy Planning and Analysis Team (PAT) activities include: Maintain, and iteratively imprve the IT Plicy Principles and Prcedures (PP&P). The PP&P guides IT plicy develpment, cmmunicatins, and implementatin. The PP&P are apprved by the executive spnsrs in cnsultatin with IT gvernance. Serve as an entry pint fr suggestins fr new IT plicies, determine if they are IT plicy, and evaluate them fr cnsistency with the PP&P. Identify plicies that are needed, in need f revisin, r n lnger needed. Advise n the relative pririty f plices fr develpment and revisin. Analyze and cmment upn plicies r plicy-related dcuments befre they are submitted t IT gvernance fr cnsideratin. The purpse f analysis and cmmentary is t facilitate deliberatin by IT gvernance. It des nt replace the review, endrsement, and apprval f IT gvernance. The analysis and cmmentary help t: ensure that a plicy is cnsistent with ther plicies and requirements. analyze and highlight significant implicatins f a plicy. assess t what degree there has been r will be adequate applicatin f the PP&P. Mnitr the deplyment f the supprting technical and prcedural implementatin, and make recmmendatins t IT gvernance and IT service prviders t help ensure that the implementatin enables efficient and effective cmpliance. August, 4, 2017 Page 2 f 5
Advise n IT plicy engagement with the UW-Madisn cmmunity. Guide plicy cmmunicatins such as awareness f plicies, the IT plicy knwledge base, plicy frums, and annuncement f plicy activity. Membership T ensure that the PAT is fully respnsive t the needs f IT gvernance, the nine vting members f the PAT are appinted by IT gvernance bdies and key executive fficers. PAT vting membership is pen t any UW-Madisn faculty, staff, r students. Vting members are nt required t be members f an IT gvernance r shared gvernance bdy. The appintments are: (1) by the Infrmatin Technlgy Cmmittee (ITC), wh serves as senir c-chair (1) by the IT Steering Cmmittee (ITSC), wh serves as the ther c-chair (1) by the Divisinal Technlgy Advisry Grup (DTAG) (1) by the Infrastructure Advisry Grup (IAG) (1) by the Research Technlgy Advisry Grup (RTAG) (1) by the Teaching and Learning Technlgy Advisry Grup (TLTAG) (1) by the Chief Data Officer (CDO) (1) by the Chief Infrmatin Officer (CIO) (1) by the Directr f the Office f Cmpliance Ex-ffici members include members-at-large and subject matter experts. The number f exffici members may vary. Ex-ffici members participate in discussin and cnsensus building, but d nt vte. Ex-ffici membership is pen t any UW-Madisn faculty, staff, and students, but must be apprved by the PAT executive cmmittee. Typical ex-ffici members culd include: (~5) At-large members, (the number f vlunteers may vary) (1) Cmmunicatins representative (1) Enterprise systems representative (1) HIPAA representative (1) IT Plicy Cnsultant (1) Recrds Management representative (1) Security Educatin, Training and Awareness representative Operatins Executive Cmmittee The Plicy Planning and Analysis Team (PAT) will have an executive cmmittee which will serve t: be respnsive t the pririties f IT gvernance. set the agenda f PAT meetings. establish and enfrce grund rules fr PAT meetings. establish ther PAT perating prcedures, as needed. cmmunicate n behalf f the PAT. ther duties assigned in the PAT charter r by the executive spnsrs. August, 4, 2017 Page 3 f 5
Membership f the executive cmmittee must be apprved by the executive spnsrs. The executive cmmittee will cnsist f five PAT members: (2) the PAT c-chairs, wh als serve as the c-chairs f the executive cmmittee. (1) ther vting member f PAT, wh may als serve as the acting chair. (2) ther members f PAT, either vting r ex-ffici. Subcmmittees PAT will make use f subcmmittees t d analysis and cmmentary n IT plicies r plicyrelated dcuments, and t perfrm ther wrk best dne by a smaller grup. PAT subcmmittees are cmmissined and mnitred by the executive cmmittee. At least ne subcmmittee member must be a PAT member, either vting r ex-ffici. Subcmmittee leadership and membership are therwise pen t any UW-Madisn faculty, staff, r students, but must be apprved by the executive cmmittee. Plicy Stakehlder Teams Chartering f a Plicy Stakehlders Team (PST) t develp recmmendatins fr IT plicy is part f the PP&P. A PST has its wn spnsrs, and is chartered by and reprts t thse spnsrs. The PAT may make recmmendatins n the need fr a PST, the draft charter fr a PST, and will typically prvide feedback n PST recmmendatins befre they are submitted t the PST spnsrs. The PAT executive cmmittee may mnitr PST activity t assess its cnsistency with the PP&P, cmmunicating with the PST chair(s) r spnsrs, if warranted. Leadership and membership f a PST is determined by the PST charter. When a plicy is prpsed by a particular stakehlder r stakehlder grup, that stakehlder r grup shuld be represented n the PST r amng the PST spnsrs. Drafting Teams Appintment f a small drafting team t draft IT plicy r plicy-related dcuments is part f the PP&P. A typical drafting team has three members. The PAT executive cmmittee appints the drafting team and designates the chair, unless the PAT executive spnsrs r the spnsrs f the crrespnding Plicy Stakehlder Team prefer t make the appintments. The drafting team reprts t thse wh appinted them. The PAT executive cmmittee may mnitr drafting team activity t assess its cnsistency with the PP&P, cmmunicating with the team, (r its spnsrs,) if warranted. Appintment t a drafting team is pen t any UW-Madisn faculty, staff, r students. When a plicy is prpsed by a particular stakehlder r stakehlder grup, that stakehlder r grup shuld be represented n the drafting team. Qurum and Vting Qurum fr the executive cmmittee is three. Qurum fr a PAT meeting is a majrity f all vting members currently serving n the PAT. Fr example, if seven f the nine slts are filled, the qurum is fur. Electrnic cnferencing is permitted. In time critical situatins, electrnic vtes transmitted t the entire executive cmmittee are acceptable, prvided that the ttal f August, 4, 2017 Page 4 f 5
vtes cast electrnically r therwise achieves a qurum. Infrmal discussins may ccur withut a qurum, and may be recrded fr cnsideratin at a future meeting. All executive cmmittee and PAT decisins shuld be made by cnsensus whenever pssible. When vting, a simple majrity is required unless therwise nted. The nly circumstances requiring a qurum and frmal vte by the PAT are: t frward an IT plicy r plicy-related dcument fr cnsideratin by IT gvernance alng with any analysis and cmmentary frm the PAT. (Requires a majrity f all vting members currently serving n the PAT.) t apprve f the minutes f PAT meetings, and t include r exclude material, r therwise adjust the recrd. t make a timely decisin n sme ther matter when cnsensus cannt be reached in the time available fr discussin, as determined by the c-chair(s) r the vting member serving as the acting chair. August, 4, 2017 Page 5 f 5