Standards & governance
Technology policies for our parishes and schools
Clear, practical standards that protect the people we serve, covering how we approach artificial intelligence, cybersecurity, the equipment we support, and the records entrusted to our care.
Policy 01
Artificial Intelligence
The Diocese of Orange has established a Diocesan AI Council, made up of clergy, diocesan staff, and other key stakeholders, tasked with overseeing the responsible integration of artificial intelligence across the Diocese. Its charge is to ensure AI is used ethically, effectively, and in alignment with Catholic teaching.
The Council maintains an AI Guidebook as a living document, reviewed and updated regularly so it stays current and practical as the technology changes. Our department implements that guidance day to day: vetting tools, configuring them safely, and helping staff use them well.
Before adopting any AI tool in a parish, school, or office, check the Guidebook and talk with us. We’ll help you weigh privacy, accuracy, and pastoral appropriateness before anything touches real data.

The Council meets quarterly to:
- Review the latest developments in AI and what they mean for diocesan operations, ministry, and education
- Address emerging ethical concerns and challenges associated with AI use
- Update guidance as practical experience and Church teaching evolve
- Communicate updates to diocesan staff for alignment and transparency
Our Director of Information Technology serves on the Council, so guidance and implementation stay connected.
Policy 02
Cybersecurity
Our security practices follow widely adopted industry frameworks, the CIS Critical Security Controls and the NIST Cybersecurity Framework, scaled sensibly to parish and school environments. The goal is protection that works without getting in the way of ministry.
Identity & access
Multi-factor authentication on all diocesan accounts, least-privilege permissions, and prompt removal of access when someone leaves a role.
Endpoint protection
Managed antivirus and threat detection on every supported device, with full-disk encryption on laptops and mobile devices.
Patching & updates
Security updates applied on a regular cycle, with critical patches expedited. Unsupported operating systems are retired, not nursed along.
Backup & recovery
Backups follow the 3-2-1 rule: three copies, two media types, one off-site. Restores are tested, not assumed.
People & awareness
Security awareness training and phishing simulations for staff, because the most common way in is still a convincing email.
Incident response
A documented plan for containment, notification, and recovery. If something looks wrong, report it immediately. Early beats certain.
Think you’ve been phished or breached?
Don’t wait and don’t try to fix it yourself. Call the help desk at (714) 282-3019 right away.

Why these standards matter
Every policy here exists to protect people
Behind the records and systems we safeguard are families, students, and parishioners who trusted us with their information. Good standards are how we honor that trust.
Policy 03
Hardware & software standards
Standardizing on a short list of known-good equipment and applications keeps costs down, support fast, and security consistent. When everyone runs the same handful of configurations, we can fix problems once instead of nine different ways.
Planning a purchase or considering a new system? Loop us in early. It is far easier to choose well than to migrate later.
Hardware
- Purchase through the Diocese so pricing, warranty, and support are consistent
- Business-class models with next-business-day warranty, not consumer retail stock
- Every device enrolled in management and inventory before it reaches a desk
- Secure disposal with certified data wiping at end of life
Typical refresh cycle
Software
- Microsoft 365 is the diocesan standard for email, files, and collaboration
- Only currently supported operating systems and application versions
- New applications reviewed with us first for security, privacy, and licensing
- Properly licensed software only, with no shared keys or unlicensed installs
- Diocesan data stays in diocesan systems, not personal cloud accounts
- Google Workspace for Education is supported for schools alongside Microsoft 365
- Schools additionally meet CIPA content-filtering requirements
Policy 04
Document management
Most of our records live in Microsoft 365, and good document management is what keeps them easy to find, well protected, and consistent across our parishes, schools, and departments. Storing files in SharePoint and OneDrive means they are backed up, searchable, and still available when a computer is replaced or a staff member moves on.
Our retention schedule is specific to the Diocese of Orange. General canon law and archdiocesan examples found online do not apply here. Follow the official diocesan records retention policy, and ask us if a record type is not listed in it.

Retention
Every record type has a defined life set by the diocesan schedule, applied through Microsoft Purview retention labels and backed by tested recovery.
- Retention follows the Diocese of Orange schedule, not generic canon-law guidance
- Retention labels applied at the library level so staff do not have to remember rules
- Sacramental registers and governance records marked as permanent
- Recycle bin and version rollback for everyday recovery, with backups tested regularly
- Ask us before deleting anything you are unsure about
File naming conventions
Consistent names make files searchable years later and let version history do the work instead of filename suffixes.
- Lead with the date in YYYY-MM-DD format so files sort chronologically
- Then the record type, then a short subject: 2026-03-14 Minutes Finance Council
- Use hyphens, and avoid / \ : * ? ” < > |
- No version numbers or “final” in the name, version history keeps prior copies
- Keep names under about 80 characters so sync paths do not break
Folder structure framework
A shared shape for every site, so anyone moving between parishes or schools knows where to look and search finds what they need.
- One SharePoint site per parish, school, or department
- Top-level libraries by function: Finance, Facilities, Personnel, Ministry, Governance
- Then by fiscal or academic year, then by subject, three levels deep at most
- Metadata columns and site search so files are findable without knowing the path
- No personal folders in shared libraries, use OneDrive for drafts
Access & permissions
Access is granted by group and reviewed regularly, and files stay synced and shareable without loose copies.
- Microsoft 365 groups and Teams membership drive access, not individual grants
- Sensitivity labels and DLP policies on personnel, financial, and student records
- External sharing off by default and enabled case by case
- Share links rather than attachments so everyone works on the current file
- OneDrive sync and Known Folder Move for Desktop, Documents, and Pictures
These pages summarize our technology standards for everyday reference. The Diocesan AI Guidebook and the official diocesan records retention policy are the governing documents. Where anything here differs from them, they control. Questions about a specific record or system? Ask us.
Track your ticket
Check your ticket status any time.
Every request you send us becomes a ticket in Autotask. Sign in any time to check its status, read our updates, and see what we’re working on next. No need to wonder or follow up.