Information Security and Governance Framework
| Approving Authority | Information Governance and Information Security Group (IGIS) |
|---|---|
| Date of Approval | 03/2022 |
| Date of Review | 03/2026 |
1. Purpose
1.1 This Framework establishes the University’s approach to Governance arrangements for Information Security and Information Compliance, Management and Monitoring in respect of applicable information legislation and sets out the requirements, standards and best practice that apply to the handling of information so that all University information is processed lawfully, securely, proportionately and effectively.
1.2 Information governance is a key responsibility of every member of the University community.
1.3 The Framework surrounds both the University’s Information Security Management System (ISMS), and the University’s Personal Information Management System (PIMS) comprising the core policies outlined in the Framework.
2. Scope
2.1 The scope of the Framework is all activities in support and delivery of:
The provision of teaching and research and enterprise services using internal systems, support services and external resources.
2.2 The Framework applies to:
- All individuals working for or with University. This includes casual workers including those appointed through UniWorkforce, agency workers, volunteers, patients, individuals with visitor status, all lay members of the University Council and its committees, external examiners, clients, contractors and project partners. For the purposes of the Framework, it also includes honorary staff and Emeritus Professors/Fellows (“Users”). Note that this list is non-exhaustive.
- All university premises.
- All university owned data and data that it is entrusted with from third parties.
- All personal data that comes into the possession, custody or control of the university.
- All information infrastructure systems and equipment.
- All services procured in support of these activities.
2.3 The Framework covers all information gathered, stored, processed and shared within the University, including both paper and electronic forms:
- All paper documents and records.
- Electronic data stored on University file-stores, portable computers and other storage devices.
- Electronic data stored within cloud storage and other Software as a Service facilities, as procured by the University.
- Electronic data transmitted over a network.
- Audio and video data, including CCTV footage.
2.4 The Framework does not form part of any employee's contract of employment and the University may amend it at any time.
3. Principles
3.1 Information is a vital asset that underpins the University's research, teaching and enterprise. Information governance is the process by which the handling of that organisational information is managed and controlled, in particular, the personal and sensitive or special category information of Users.
3.2 The University recognises the need to maintain a balance in its management and use of information between:
- its public accountability and transparency in its governance;
- its compliance with legal and regulatory obligations; and
- the need to both protect and secure the personal and commercially sensitive information that it has responsibility for.
3.3 The University's information is used as the basis on which decisions are made and services provided. The aim of information governance is to ensure that this information, whether in paper or electronic format, is handled efficiently and effectively at all times. In particular, information governance should help to:
- Maintain confidence in the integrity and authenticity of information;
- Protect the privacy of Users;
- Provide effective and efficient services to Users;
- Support decision-making by ensuring that relevant, accurate and comprehensive information is readily available to inform the future of the University;
- Ensure accurate funding allocations and demonstrate accountability to public and private funders;
- Increase cost-effectiveness by making sure data is disposed of when no longer needed;
- Minimise the risk of information security breaches; and
- Ensure the University's compliance with legal and regulatory requirements.
4. Legal and Compliance
4.1 The Framework must ensure compliance with legislation relating to the handling and use of information, as well as the common law duty of confidentiality. These include, but are not limited to:
- Data Protection Act 2018
- UK General Data Protection Regulation
- Freedom of Information Act 2000
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (as amended)
- Environmental Information Regulations 2004
- Regulation of Investigatory Powers Act 2000
- The Telecommunications (Lawful Business Practice) Regulations 2000
- Computer Misuse Act 1990
- Human Rights Act 1998
- Copyright, Designs and Patents Act 1988
- Official Secrets Act 1989
- Malicious Communications Act 1988
- Digital Economy Act 2010
- Intellectual Property Act 2014
- Investigatory Powers Act 2016
- Human Tissue Act 2004
- The Medicines for Human Use (Clinical Trials) Regulations 2004
4.2 Where relevant the following legislation also requires consideration in the handling and use of information.
- The Gramm–Leach–Bliley Act (GLBA), also known as the Financial Services Modernization Act of 1999
- General Data Protection Regulation (Regulation (EU) 2016/679)
5. Roles and Responsibilities
There are a number of key roles and responsibilities across the University in relation to information governance, as set out below.
5.1 Vice President Operations (VPOps) and Senior Information Risk Owner (SIRO)
The SIRO is accountable at a senior management level for ensuring that the University has robust information governance and security processes and procedures in place. This role is held by the University’s Vice President (Operations). The SIRO also chairs the Information Governance and Information Security Group.
5.2 Executive Director of iSolutions and Chief Information Officer (CIO)
The CIO is the senior executive responsible for the implementation, management and usability of computer and information technologies.
5.3 Data Protection Officer (DPO)
The University is required, as a Public Body, to appoint a Data Protection Officer. They are responsible for monitoring the organisation’s overall compliance with the relevant information legislation, and act as the focal point for all University activity in relation to data protection. Throughout this framework and associated policies, the duties and instructions of the DPO are reflected across a range of groups, stakeholders and roles reflected below, and oversight of the DPO is broadly through the oversight groups along with ad hoc individual consultation where needed in response to incidents, risks and procedure. The University’s Data Protection Officer post is currently fulfilled by the University’s Vice President Operations.
5.4 Head of Information Governance
The Head of Information Governance primarily supports the DPO in carrying out their duties, monitoring compliance and reporting across all areas of Information governance to the Information Governance and Information Security Group, the SIRO, CIO and DPO.
They are responsible for the University’s activities as outlined in the relevant policies, procedures and standards as outlined in the Framework, and are directly responsible for the content and maintenance of relevant polices, primarily policies under the University’s Personal Information Management System (PIMS) Their role, along with their team is to lead and oversee Information Governance (IG) in the University, ensuring compliance with UK data protection legislation and other information legislation, Supporting the University in making effective, secure and compliant use of information in all its forms across professional service departments and Faculties and Schools allowing them to exploit fully information assets in support of organisational priorities and processes.
5.5 Information Governance and Compliance Team
Responsible for the management of Data Subject Rights, responding to Subject Access Requests, Data Erasure Requests and associated requests from individuals wishing to exercise their rights under the data legislation.
The team coordinate the response to personal data breaches as reported by individuals via the University’s self-service portal. The team also manage the handling and publication of Freedom of Information and Environmental Information Regulation requests.
Records are maintained by the team consisting of the investigation, determination and where applicable escalation of such requests and investigations – reporting to the Head of Information Governance and Data Protection Officer as necessary for escalation and record keeping.
5.6 Associate Director Cyber Security
Senior executive responsible for managing and overseeing the information security posture of the University. Their primary role is to ensure the confidentiality, integrity, and availability of the University’s information assets. Directs staff in identifying, developing, implementing, and maintaining processes across the enterprise to reduce information and cyber security related risks. They seek to: develop and implement the University’s information security strategy; oversee the risk management process in relation to information security risks; establish and enforce security policies, standards, and procedures – notably the documentation required under the University’s ISMS as outlined in this Framework; oversee the selection, implementation, and management of security technologies; promote a culture of security awareness and own the security training function; develop and maintain the University’s cyber incident response plan; ensure that the organisation maintains compliance with security related contractual requirements, and industry best practice standards (e.g.; ISO/27001 or Cyber Essentials),; and they conduct regular security assessments and audits.
They also work closely with other executives, department heads, and external partners to align security initiatives with overall business goals and objectives.
5.7 Cyber Security Team
The Cyber Security team, led by the Associate Director Cyber Security, is responsible for delivering against the University’s Cyber Security strategy. They carry out the day-to-day technical and operational activities related to cyber security within the University, monitoring, detection of, and response to security incidents of all levels. They also provide security risk guidance, architecture, policy support, security compliance, and assurance activities, as well as supporting the Associate Director with his responsibilities as laid out above.
5.8 Caldicott Guardian
Caldicott Guardians are responsible for “safeguarding the confidentiality of patient identifiable information” (Dame Fiona Caldicott,2017) and are usually a senior person within a health or social care organisation who makes sure that the personal information about those who use its services is used legally, ethically and appropriately, and that confidentiality is maintained.
As an educational institution, the Caldicott Guardian role is not always applicable across all health data processing activities; however because within the University there are a number of research, clinical and enterprise data operations that require the submission of NHS Digital Toolkits, or involve a high volume of clinical data, the University has appointed a Caldicott Guardian (ODS Code EE133879)
Separately to the University activities outlined above, the Auditory Implant Service (within the University’s Faculty of Medicine) is registered as a ‘Independent Sector Healthcare Provider; and has a Caldicott Guardian appointed for its operations (ODS NRF)
The Caldicott Guardian is accountable for:
- Ensuring compliance with the principles contained within the Confidentiality: NHS Code of Practice and that relevant staff are made aware of individual responsibilities through policy, procedure and training
- Providing routine reports to the senior management on confidentiality and data protection issues
- Identifying and addressing any barriers for sharing for care
The Caldicott Guardians should usually raise concerns, escalate or report on compliance to the Data Protection Officer via:
- The Information Governance and Information Security Group (via attendance at the group or the Head of Information Governance)
- The DPIA Panel, (via attendance at the group or the Head of Information Governance)
The Information Governance Team maintain a record of Caldicott Guardian notifications and will normally be copied into any notification or reporting. An annual review of notifications will be undertaken by the Information Governance and Information Security Group.
5.9 Line Managers, Senior Management, Heads of Department
In addition to the individual responsibilities laid out for staff below, management staff are expected to:
- Make all staff within their areas aware of the Framework;
- Ensure that appropriate processes and training (Information Governance, E-learning modules etc.) are engaged with to enable compliance with data protection law; and
- Ensure that appropriate processes are implemented within their areas to enable data assets containing personal data within their area are included in the University’s Data Asset Registers.
5.10 All Staff and Members of the University Community
Each data user at the University holds the following responsibilities relating to data protection laws, and, where reasonable this also applies to students:
- Completing relevant data protection and information security training
- Following relevant advice, guidance and tools/methods provided by Information Governance depending on their role, regardless of whether access to and processing of personal data is through University-owned and managed systems, or through their own or a third party’s systems and devices
- When processing personal data on behalf of the University, only using it as necessary for their contractual duties and/or other University roles, in line with the purposes and practices illustrated to data subjects via the privacy notice and associated statements during data collection and not disclosing it unnecessarily or inappropriately
- Recognising, reporting internally via the information governance protocols, and cooperating with any remedial work arising from personal data breaches
- Embedding Privacy by Design, ensuring relevant procedures and data protection principles (such as the completion of a DPIA) are considered at the design of projects, procurement and development of working practices.
5.11 Information Asset Owners (IAOs)
Also referred to as business or data owners, the IAO is normally a role of a senior member of staff responsible for specific datasets, data journeys or processing operation.
The IAO’s role is to be accountable for specific information assets (e.g. congruent datasets such as finance data, staff data) and to ensure those assets are handled and managed appropriately. This means making sure information assets are properly protected against risk and that their value to the organisation is recognised.
6. Oversight
6.1 Information Governance and Information Security Group (IGIS)
The IGIS is made up of senior members of staff across the institution, including representation of the roles outlined above, and has the following overarching remit and responsibilities.
- To approve Information Governance (IG) and Information Security (IS) strategy and policy and maintain oversight of their delivery thereby providing assurance that the University’s legal obligations and accountability are in place.
- To ensure that appropriate and comprehensive Information Governance and Information Security Frameworks are in place ad being implemented throughout the University in line with current legislation, national and international standards.
- To act as Approving Authority for relevant policies in line with those frameworks, including, but not limited to the Information Governance framework and Information Security Policy.
- In support of SIRO activities, the Board are a defined point on the information risk management process, acting as escalation for the top level recognition of those risks
- To approve and monitor improvement activities, and risk updates.
- To provide an escalation point for the discussion and resolution of in individual Information Governance and Information Security activities where referred by the Head of Information Governance, Associate Director Cyber Security and Caldicott Guardian.
- To receive reports on performance against established strategic goals, to be aligned with Organisational Excellence, where indicators are established within parameters of institutional objectives and identified risk areas.
- To receive reports on identified KPIs around compliances activities in relation to Security and Information compliance, such as FOIA, Data Subject Rights, Data Breaches and Vulnerabilities.
- To receive reports on data breaches and information security incidents, including trend analysis and where appropriate recommend corrective action to ensure risk of future incidents is mitigated.
- To provide oversight of the implementation, delivery and recording of training and development opportunities to improve the knowledge and capabilities of all staff and students in data compliance and information security.
- To champion the Information Governance and Information Security strategy by promoting on-going appropriate communications and engagement.
- Receive reports from relevant groups across the organization, chiefly the Data Quality Group.
The Information Governance and Information Security Group and where applicable the University Executive Board formally approves, issues and maintains all IGIS University policies using a consistent process and format.
6.2 Data Protection Impact Assessment (“DPIA”) Panel
The DPIA Panel provides a mechanism for compliance with data protection legislation (GDPR, 2016; DPA, 2018; PECR, 2019; UKGDPR), supporting the DPO in understanding the University’s privacy risks, and keeping records to demonstrate compliance. The Panel is critical to ensuring Data Protection Impact Assessments are adequately reviewed and reports into the IGIS Group, and Data Protection Officer as required, ensuring that the University’s senior leadership is aware of any privacy or wider information governance risks arising from the processing of personal data under the activity/operation.
7. Relevant Policies
7.1 The Framework of Information Governance and Security (IGIS) policies, standards, procedures and guidance have been developed to manage information in a cohesive way to ensure that all information, including personal information, is dealt with legally, securely and effectively so that all Users who have access to that information know what information is held, where it is held, who is responsible for it and how long it is kept.
7.2 The Information Governance and Information Security Group reviews and recommends changes to all relevant. All policies are made available to staff via the internet and are communicated via regular updates to staff.
7.3 Existing policies are updated, and new policies introduced in line with requirements, with policies reviewed on an regular basis. These policies must be read in conjunction with staff employment contracts or student regulations as appropriate.
7.4 Policies outline scope and intent and provide staff, students and academics with a robust information governance framework whilst setting out their responsibilities. The University is committed to ensuring that all staff and those working with it are familiar with the organisation’s objectives and what is expected for these to be achieved.
7.5 Definitions
7.6 Policy: An official University directive that:
- provides guiding or governing principles to be followed in carrying out the activities of the University
- dictates organisational strategic goals
- establishes key requirements and responsibilities
- helps ensure compliance with applicable laws, promotes operational efficiencies, advances the University’s mission, and/or reduces institutional risks
- has broad application throughout the University and applies to all members of the University community
7.7 Policies under this framework must be approved via IGIS following amendments or review. Cosmetic or non-material amendments to policy can be actioned by the Policy Author outside of formal approval, but should be subject to notification to IGIS.
7.8 Policies within the Framework include (but are not limited to) the Policies under the purview of the Associate Director Cyber Security and the Head of Information Governance, detailed across the University’s Policy pages and relevant SharePoint sites.
7.9 There will be some policies that fall under the purview of this framework (i.e. subject matter or principles relevant to University handling of information and personal data) but are subject to separate approvals under broader University governance, in those cases IGIS must be consulted and act as endorsing body.
7.10 Procedures: Statements that:
- articulate the method by which a University Policy is carried out
- contain explicit repeatable activities in order to accomplish specific tasks
- identify roles and responsibilities
7.11 Subject to relevant consultation, procedures are approved by the Head of Information Governance and Associate Director Cyber Security and may be presented to IGIS for information and dissemination purposes.
7.12 Standards: Statements that outline:
- Explicit requirements for an item, asset or process
- Expectations of performance or conformance
- Instructions for performing operations
- Technical specifications that relate to operations
7.13 Standards may come from internal frameworks outlined in relevant policies, or may come from an external sources such as statutory or administrative law.
7.14 Subject to relevant consultation, Standards are approved by the Head of Information Governance and Associate Director Cyber Security and may be presented to IGIS for information and dissemination purposes.
7.15 Complementary Policies:
7.16 The Clinical Informatics Research Unit (CIRU) is an applied research and enterprise unit within the Faculty of Medicine at the University of Southampton.
7.17 The CIRU undertake applied research in software development, secure data environments, data terminology, modelling and standards. The unit provide software and data processing services under licence as Trading Services to those engaged in human health research to improve quality and effectiveness, and drive new research questions within research data management.
7.18 As an enterprise unit, CIRU’s processing activities are distinct from usual University processing, and are undertaken via separate policies, procedures and working practices. These policies are designed, reviewed and approved via CIRU Programme Group committees, however are aligned with wider University Information Security and Information Governance as they are subject to the University’s registration as Data Controller, and are accountable to the University SIRO and DPO in respect of data subject rights, breaches and management of obligations under relevant data legislation. As such policies created for CIRU activities are subject to review/consultation from the Information Governance and Information Security Group.
8. Training and Development
8.1 Information Governance and Information Security training is essential for staff and those subject to this framework to develop their understanding, inform organisation behaviours and improve knowledge and skills in relation to the processing and management of the information processed across the University.
8.2 Training is provided for all staff in both data protection and information security and it is essential that staff understand the value of the information held by the University and their responsibilities for it, including embedding fairness, lawfulness and transparency of processing personal data and the criticality of maintaining confidentially, availability and integrity of data.
8.3 All new staff are provided with relevant training and are asked to complete it as part of their staff induction. Further bespoke training, workshops and resources are available to all staff via the Information Governance SharePoint pages.