What is an ISMS?
An Information Security Management System (ISMS) is a structured framework used to manage and protect the University’s information.
It ensures information is:
- Confidential - only accessed by authorised users
- Accurate - protected from unauthorised change
- Available - accessible when needed
The ISMS is based on recognised standards (such as ISO 27001) and brings together policies, processes, controls, and responsibilities.
How it is used within the University
The University uses its ISMS to manage information security in a consistent and risk-based way across all systems and services.
It supports:
- Policy implementation
Applying the Information Security Policy and related procedures across the University - Risk management
Identifying and reducing cyber and data risks - Security controls
Protecting systems and data (e.g. access control, monitoring, encryption) - Incident management
Detecting, responding to, and learning from security incidents - Training and awareness
Ensuring staff understand their responsibilities - Continuous improvement
Reviewing and strengthening controls through audit and monitoring
Relationship to the Information Security Policy
The Information Security Policy sets out the University’s high-level security principles.
The ISMS is how those principles are implemented, managed, and continuously improved in practice.