Information ServicesInformation Security Management System (ISMS)

What is an ISMS?

An Information Security Management System (ISMS) is a structured framework used to manage and protect the University’s information.

It ensures information is:

  • Confidential - only accessed by authorised users
  • Accurate - protected from unauthorised change
  • Available - accessible when needed

The ISMS is based on recognised standards (such as ISO 27001) and brings together policies, processes, controls, and responsibilities.

How it is used within the University

The University uses its ISMS to manage information security in a consistent and risk-based way across all systems and services.

It supports:

  • Policy implementation
    Applying the Information Security Policy and related procedures across the University
  • Risk management
    Identifying and reducing cyber and data risks
  • Security controls
    Protecting systems and data (e.g. access control, monitoring, encryption)
  • Incident management
    Detecting, responding to, and learning from security incidents
  • Training and awareness
    Ensuring staff understand their responsibilities
  • Continuous improvement
    Reviewing and strengthening controls through audit and monitoring

Relationship to the Information Security Policy

The Information Security Policy sets out the University’s high-level security principles.

The ISMS is how those principles are implemented, managed, and continuously improved in practice.

For more guidance on information security for managers, please visit the IT Spotlight Security Pages.

Training

All staff and students should complete cyber security awareness training available.