Key Principles of Information Security
Information security helps protect the University's information, systems, and services that support teaching, research, administration, and collaboration. Everyone who accesses University information or IT services has a responsibility to help keep them secure.
The University's approach to information security is based on the following key principles:
Protect Information
We protect the confidentiality, integrity, and availability of University information and information systems. This means ensuring that information is only accessible to authorised individuals, remains accurate and trustworthy, and is available when needed to support University activities.
Shared Responsibility
Information security is everyone's responsibility. Staff, students, contractors, visitors, and third parties are expected to follow University policies and take appropriate steps to protect the information and systems they use.
Manage Risk
We take a risk-based approach to information security, helping to protect the University from threats that could impact our reputation, finances, operations, or ability to deliver services.
Meet Legal and Regulatory Requirements
Information must be handled securely and in accordance with applicable legal, regulatory, contractual, and University requirements.
Develop Security Awareness
We promote a culture of information security through awareness, education, and training, helping our community understand their responsibilities and make informed decisions when handling information.
Follow Recognised Good Practice
The University aligns its approach to information security with recognised cyber security frameworks and guidance, including the Scottish Government's Public Sector Action Plan on Cyber Resilience and the National Cyber Security Centre's Cyber Assessment Framework (CAF).
Continually Improve
Information security is regularly reviewed to ensure that our controls, policies, and ways of working remain effective and continue to support the needs of the University.
For further information, please refer to the Information Security Policy and supporting policies available on this page.