2. Information Security Policy

Our aim was to provide you with an Information Security policy, approved by Council and supported by the University:
New Information Security Policy

The policy was drafted with help from:
  • The Information Security Advisory Group
  • OxCERT
  • Council Secretariat
  • Legal Services Office

We focused on consolidating the pre-existing policies on Information Security into one document. That resulting policy (new Information Security Policy) defines the University's objectives for Information Security in line with its operational requirements and strategic plan. It also defines the scope of the policy and identifies roles and responsibilities for security.

In a devolved environment, such as a collegiate university, it is imperative that the policy should not go into detail about how those objectives should be met: each unit within the University will have their own methods, practices and controls in order to achieve the objectives, depending on local influences. The Information Security Toolkit provides guidance as to how those objectives might be met.

Developing the Information Security Policy:

Up: Contents Previous: 1. Information Security Best Practice Project Next: 3. Information Security Toolkit