Colorado § 24-37.5-404.5 - Institutions of higher education - information security plans.
Full text of Colorado Colorado Revised Statutes § 24-37.5-404.5 — Institutions of higher education - information security plans., with citation guidance and answers to common questions.
§ 24-37.5-404.5. Institutions of higher education - information security plans.
(1) Each institution of higher education, in coordination with the department of higher education, shall develop an information security program. The information security program shall provide information security for the communication and information resources that support the operations and assets of the institution of higher education.
(2) The information security program shall include:
(a) Periodic assessments of the risk and magnitude of the harm that could result from a security incident;
(b) A process for providing adequate information security for the communication and information resources of the institution of higher education;
(c) Information security awareness training to inform the employees, administrators, and users at the institution of higher education about the information security risks and the responsibility of employees, administrators, and users to comply with the institution's information security program and the policies, standards, and procedures designed to reduce the security risks;
(d) Periodic testing and evaluation of the effectiveness of information security for the institution of higher education, which shall be performed not less than annually;
(e) A process for detecting, reporting, and responding to security incidents consistent with the information security policy of the institution of higher education. The institutions of higher education, the Colorado commission on higher education, and the chief information security officer shall establish the terms and conditions by which the institutions of higher education shall report information security incidents to the chief information security officer.
(f) Plans and procedures to ensure the continuity of operations for information resources that support the operations and assets of the institution of higher education in the event of a security incident.
(3) (a) Every three years, in accordance with the schedule specified in subsection (3)(b) of this section, each institution of higher education shall submit to the department of higher education a report concerning the development and implementation of the institution's information security program and compliance with the requirements specified in subsection (2) of this section. Upon receipt of the reports, the department of higher education shall review the reports and subsequently submit the reports to the chief information security officer.
(b) The department of higher education shall divide the institutions of higher education into three groups. Each institution of higher education shall submit the report required by subsection (3)(a) of this section as follows:
(I) The institutions in the first group shall submit the report by July 1, 2020, and by July 1 every three years thereafter;
(II) The institutions in the second group shall submit the report by July 1, 2021, and by July 1 every three years thereafter; and
(III) The institutions in the third group shall submit the report by July 1, 2022, and by July 1 every three years thereafter.
(4) Nothing in this section shall be construed to require any institution of higher education or the department of higher education to adopt policies or standards that conflict with federal law, rules, or regulations or with contractual arrangements governed by federal laws, rules, or regulations.
(5) and (6) (Deleted by amendment, L. 2011, (SB 11-062), ch. 128, p. 431, § 8, effective April 22, 2011.)
(7) (Deleted by amendment, L. 2011, (HB 11-1301), ch. 297, p. 1422, § 13, effective August 10, 2011.)
Source: L. 2006: Entire part added, p. 1717, § 1, effective June 6. L. 2007: (1) amended, p. 914, § 10, effective May 17. L. 2011: (1), (2)(e), (3), (5), and (6) amended, (SB 11-062), ch. 128, p. 431, § 8, effective April 22; entire section amended, (HB 11-1301), ch. 297, p. 1422, § 13, effective August 10. L. 2016: (3) amended, (HB 16-1375), ch. 225, p. 859, § 2, effective August 10. L. 2021: (3) amended, (HB 21-1236), ch. 211, p. 1109, § 12, effective September 7.
Source: official Colorado text · Last verified 2026-08-27
Frequently Asked Questions About Colorado § 24-37.5-404.5
What does Colorado Revised Statutes § 24-37.5-404.5 cover?
Section 24-37.5-404.5 ("Institutions of higher education - information security plans.") is part of the Colorado Revised Statutes, the codified statutory law of Colorado. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.
How do I cite Colorado § 24-37.5-404.5?
A common citation format is "Colorado Revised Statutes § 24-37.5-404.5" (Colorado). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.
Is this the official text of Colorado law?
No. This page is for research and education and may not include the most recent amendments. For official current law, check the Colorado official source linked on this page or consult a licensed Colorado attorney.
How does Colorado § 24-37.5-404.5 apply to my situation?
Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Colorado can advise on how this section applies to you. Contact your state or local bar association for a referral.
Sources & Verification
Not legal advice. Verify against the official source and consult a licensed attorney in Colorado.