Information ServicesKey Principles

Key Principles of Information Security

Information security helps protect the University's information, systems, and services that support teaching, research, administration, and collaboration. Everyone who accesses University information or IT services has a responsibility to help keep them secure.

The University's approach to information security is based on the following key principles:

Protect Information

We protect the confidentiality, integrity, and availability of University information and information systems. This means ensuring that information is only accessible to authorised individuals, remains accurate and trustworthy, and is available when needed to support University activities.

Shared Responsibility

Information security is everyone's responsibility. Staff, students, contractors, visitors, and third parties are expected to follow University policies and take appropriate steps to protect the information and systems they use.

Manage Risk

We take a risk-based approach to information security, helping to protect the University from threats that could impact our reputation, finances, operations, or ability to deliver services.

Meet Legal and Regulatory Requirements

Information must be handled securely and in accordance with applicable legal, regulatory, contractual, and University requirements.

Develop Security Awareness

We promote a culture of information security through awareness, education, and training, helping our community understand their responsibilities and make informed decisions when handling information.

Follow Recognised Good Practice

The University aligns its approach to information security with recognised cyber security frameworks and guidance, including the Scottish Government's Public Sector Action Plan on Cyber Resilience and the National Cyber Security Centre's Cyber Assessment Framework (CAF).  

Continually Improve

Information security is regularly reviewed to ensure that our controls, policies, and ways of working remain effective and continue to support the needs of the University.

 

For further information, please refer to the Information Security Policy and supporting policies available on this page.

 

Training

All staff and students should complete cyber security awareness training available.