Accessibility statement

Information Security Policy

Related pages

This is the overarching policy which explains the key ways that the University ensures the secure handling of its information while providing appropriate access.

It applies to everyone - all staff, students, associates, and anyone else authorised to use University IT facilities and information.

1. Policy

1.1 It is the policy of the University of York that the information it manages will be appropriately secured to protect against the consequences of personal data breaches, breaches of confidentiality, failures of integrity, or interruptions to the availability of that information.

1.2 The University will aim to achieve a culture in which legal requirements, information assurance and cyber security risks are considered whenever information is handled, through the provision of training, awareness campaigns and specialist guidance, advice and process.

1.3 The University will implement information security management practices which apply appropriate security while at the same time enabling staff, students and visitors to access, use and share the information they need.

1.4 The University will ensure that requirements and contracts that result in the collection, processing or storage of information are undertaken and protected in accordance with applicable legislation and standards.

1.5 Information held in user accounts may be examined on behalf of the University by authorised persons for specific operational or legal reasons. In these cases access will be authorised and conducted in accordance with the University policy on IT Investigations and Data Access Policy.

1.6 This document, together with related information security policies and implementation documents at www.york.ac.uk/information-services/information-policy/index/, defines the framework within which information security is managed across the University.