Part 1. Purpose. To establish requirements and responsibilities for acceptable use and implementation of electronic signatures. The requirements are designed to provide the appropriate level of security, authentication, and record integrity when implementing or using electronic signatures for transactions. Colleges and universities may adopt additional conditions of use, consistent with board policy, procedure, and this guideline.
Part 2. Authority. Board policy delegates authority to the chancellor to develop system guidelines for purposes of implementing policy and procedure.
Part 3. Definitions.
Transaction Impact Level Signature Type | Critical Impact | High Impact | Medium Impact | Low Impact |
Original, Handwritten Signatures | Yes | Yes | Yes | Yes |
Digital Signatures | Yes | Yes | Yes | Yes |
Multi Factor Authentication | No | Yes | Yes | Yes |
Single Factor Authentication | No | No | Yes | Yes |
Digitized Signatures | No | No | No | Yes |
Faxed/Scanned Signatures | No | No | No | Yes |
Critical | High | Medium | Low | |
Consent | Capture date and time of consent, with user ID and consent text. | Capture date and time of consent, with user ID and consent text. | Overall consent form signed to cover all medium transactions. | Overall consent form signed to cover all low transactions. |
Opt-Out | Capture date and time of opt out response with user ID and opt-out text. | Capture date and time of opt out response with user ID and opt-out text. | Overall consent form will state the ability to opt out. Reply by electronic means can be used to opt-out. | Overall consent form will state the ability to opt out. Reply by electronic means can be used to opt-out. |
Reproduce | Contain all of the information necessary to reproduce the entire electronic record and all associated signatures in a format that permits the person viewing or printing the record to verify: a) the contents of the electronic record; b) the method used to sign the electronic record, if applicable; c) the full name of the person(s) signing the electronic record; and d) the date and time of each signature. | Contain all of the information necessary to reproduce the entire electronic record and all associated signatures in a format that permits the person viewing or printing the record to verify: a) the contents of the electronic record; b) the method used to sign the electronic record, if applicable c) the full name of the person(s) signing the electronic record; and d) the date and time of each signature. | Email with signed document in unalterable format (i.e., PDF, JPEG) will be the reproducible record or the fields in the system log. | Email with signed document will be the reproducible record or the system log. |
Transmission | An electronic receipt or some form of electronic acknowledgement of a successful submission of the electronic record and signature must be provided. | An electronic receipt or some form of electronic acknowledgement of a successful submission of the electronic record and signature must be provided. | Email system or system log will acknowledge transmission. | Email system or system log will acknowledge transmission. |
Alteration | Cryptographic key is used to validate document has not been changed. | Multi-factor product or process will be used to validate document has not changed. | Email with the signed attachments in unalterable format (i.e. PDF, JPEG) or the system log. | Email with the signed attachments or the system log. |
Retention | All electronically-signed documents must be retained in accordance with the applicable records retention schedule. | All electronically-signed documents must be retained in accordance with the applicable records retention schedule. | Retained within email system or a system log. | Retained within email system or a system log. |
Audit | Transaction audit log. | Transaction audit log. | Email log or a system log. | Email log or a system log. |
Date of adoption: 12/09/15,
Date of implementation: 12/09/15,
Date of last review:
Date and Subject of Amendment: