Information Security Policy

From  Cyber Security (iSolutions) and Information Governance  
Approval Date  12/02/2026  
Approving authorityIGISG (Information Governance and Information Security Group) 
Review  Annually  
Version  2.1  

1. Policy Intent

1.1 Information is at the heart of the University. It is what defines us and what drives us towards achieving our stated goals and objectives. It is vital to ensure the security of that information is an activity embedded in ALL aspects of University operations. 

1.2 This policy forms part of the Information Security Management System (ISMS) of the University of Southampton; the set of policies, standards, processes and guidance which define the University’s approach to information security.  

1.3 The primary aims of this policy are to:  

1.3.1 Ensure that information held by the University is protected against unauthorised access and data breaches.  

1.3.2 To maintain the confidentiality, integrity and availability of information held by the University; and  

1.3.3 To maintain the confidentiality, integrity and availability of networks and computer systems used to process information held by the University.  

1.3.4 Above all, the University must embed information and cyber security practices into all layers. This is referred to as “security by design, security by default”.  

2. Legislation 

2.1 The University of Southampton has a responsibility to abide by and adhere to all current UK and EU legislation as well as a variety of other regulatory and contractual requirements.  

2.2 Information in regards to the University’s data protection strategy can be found within the University’s Information Governance and Data Protection site

2.3 A non-exhaustive summary of the legislation and regulatory obligations that contribute to the form and content of this policy is provided in Relevant Legislation.  

3. Definitions and Abbreviations  

3.1 It is intended that this policy be used in conjunction with other policies published as part of the University’s Information Security Management System, in particular the Information Security Policy, which sets out the formal scope for all policies and other documents within the Information Security Management System (ISMS).

3.2 A non-exhaustive list of definitions that contribute to the contents of this policy is provided in the Glossary of Abbreviations and Definitions. 

3.3 In this and other Information Security Management System policy documents, the following verbal forms may be used: 

3.3.1 “shall” indicates a requirement 

3.3.2 “should” indicates a recommendation 

3.3.3 “may” indicates a permission 

3.3.4 “can” indicates a possibility or a capability 

4. Scope

4.1 After consideration of the organisation and its context and the needs and expectations of interested parties, the scope of the Information Security Management System is: 

The provision of teaching, research, professional and enterprise services using internal systems, support services and external resources.  

4.2 The scope applies to:

4.2.1 All individuals working for or with the University. This includes casual workers including those appointed through UniWorkforce, agency workers, volunteers, individuals with visitor status, all external members of the University’s Council and its committees, external examiners, researchers, clients, contractors and project partners. For the purposes of this policy, it also includes honorary staff and Emeritus Professors/Fellows (this list is non-exhaustive). 

4.2.2 All university premises. 

4.2.3 All university owned data and data that it is entrusted with from third parties. 

4.2.4 All personal data that comes into the possession or control of the university.  

4.2.5 All university information infrastructure systems and equipment.

4.2.6 All services procured in support of these activities. 

4.3 This policy does not form part of any employee's contract of employment and the University may amend it at any time. 

4.4 For the purposes of this policy, the individuals listed in Section 4.2 under the defined scope shall hereafter be referred to collectively as ‘staff’

5. Definition of Information Security 

5.1 Information Security means preserving the confidentiality, integrity, and availability of the University's physical and information assets. 

5.2 Core Security Principles 

5.2.1 Confidentiality involves ensuring that information is accessible only to those authorised to access it, preventing both deliberate and accidental unauthorised access to the University's information, research data, and systems. 

5.2.2 Integrity involves safeguarding the accuracy and completeness of information and processing methods, preventing deliberate or accidental destruction or unauthorised modification of physical assets or electronic data.  

5.2.3 Availability means that information and associated assets are accessible to authorised users when required. The computer network must be resilient, and the University must be able to detect and respond rapidly to incidents that threaten continued availability. 

5.3 Asset Definitions 

5.3.1 Physical assets include computer and network hardware, data cabling, telephone systems, filing systems, and physical data files. 

5.3.2 Information assets include information in all forms: printed or written on paper, transmitted by post, shown in films, spoken in conversation, and stored electronically on servers, websites, extranets, intranets, PCs, laptops, mobile devices, and any digital or magnetic media. This also includes software: operating systems, applications, and utilities.

5.4 Risk Appetite Statement 

5.4.1 The University accepts that information security risks cannot be entirely eliminated but maintains a low to moderate risk appetite for information security threats. The University will: 

a. Accept low-level risks that are effectively managed through standard controls.  

b. Require additional controls and senior management approval for moderate risks.  

c. Not accept high or critical risks without comprehensive mitigation strategies and Executive Board approval.

d. Maintain zero tolerance for risks that could result in significant harm to individuals, major regulatory breaches, or substantial reputational damage.  

6. University Policy Principles 

6.1 Leadership and Governance 

6.1.1 Management Commitment 

a. The University Council, University Executive Board and management of the University and NETSCC are committed to preserving the confidentiality, integrity, and availability of all the physical and electronic information assets, including personally identifiable information (PII), throughout the organisation to preserve its competitive edge, legal, regulatory, and contractual compliance, and commercial image. 

6.1.2 Strategic Alignment and Standards Framework 

a. The University’s current strategic business plan and risk management framework provide the context for identifying, assessing, evaluating, and controlling information- and privacy-related risks through the establishment and maintenance of an Information Security Management System (ISMS), designed in accordance with the specification contained in ISO/IEC 27001to support the accreditation of NETSCC with an additional view to possibly achieve accreditation for the University.  

b. The principles and framework of the internationally recognised standards – ISO/IEC 27001, which defines the requirements for an Information Security Management System, and ISO/IEC 27701, which defines the requirements for a Privacy Information Management System – aligns with the University’s commitment to embedding strategic adherence and understanding of good cyber security practices, senior leadership and management support, risk management and information security by design and default.  

6.1.3 Objectives and Enablement 

a. Information, privacy, and information security requirements will continue to be aligned with University’s goals, and the ISMS is intended to be an enabling mechanism for information sharing, for electronic operations, and for reducing information- and privacy-related risks to acceptable levels.

b. The University aims to achieve specific, defined information security and privacy objectives, which are developed in accordance with the business objectives, the context of the organisation, the results of risk assessments and the risk treatment plan.  

6.2 Risk Management and Environmental Controls 

6.2.1 Environmental and Physical Risk Considerations 

a. The University shall consider environmental, physical, and operational factors that could affect the confidentiality, integrity, and availability of information assets. This includes environmental risks such as climate change, fire, flood, power loss, temperature or humidity extremes, and other conditions that could impact the security of physical and electronic systems.  

b. Climate change considerations shall include external issues such as extreme weather conditions affecting the availability of data centres, flooding and fire risks affecting our physical locations, supply chain disruptions affecting ICT services, temperature changes affecting cooling systems and remote working increases due to climate changes.

6.2.2 Risk Assessment and Treatment

a.The Risk Assessment, Statement of Applicability and Risk Treatment Plan identify how information- and privacy-related risks are controlled. The Director Organisational Risk is responsible for the management and maintenance of the risk treatment plan. Additional risk assessments may, where necessary, be carried out to determine appropriate controls for specific risks.

6.3 Operational Security Controls 

6.3.1 Segregation of Duties 

a.The University shall implement segregation of duties to reduce the risk of error, fraud, and misuse of information assets. Responsibilities for critical processes, systems, functions and units shall be divided among different individuals or teams to ensure that no single person has excessive control or unchecked authority. Where segregation of duties cannot be fully achieved due to operational constraints, the University shall apply appropriate compensating controls, such as enhanced monitoring, oversight, or independent review.  

6.3.2 Documented Operating Procedures 

a. The University shall establish and maintain documented operating procedures for critical information systems and processes. These procedures shall be approved, communicated, and reviewed to ensure they remain accurate, effective, and aligned with policy requirements.  

6.3.3 Core Security Functions 

a. Information and cyber security training, business continuity and contingency plans, data backup procedures, avoidance of viruses and criminal hackers, access control to systems, and information security and privacy incident reporting are fundamental to this policy.

6.4 Compliance and Legal Framework

6.4.1 Legislative and Regulatory Compliance 

a. The University is committed to ensuring compliance with all applicable legislative, regulatory, and contractual requirements. 

6.4.2 Contact with Authorities 

a. The University shall establish and maintain appropriate contact with relevant authorities, including regulatory bodies, law enforcement, and supervisory agencies. Such contact shall ensure compliance with applicable legal, regulatory, and contractual obligations, and provide a clear channel for the reporting and escalation of information security incidents. Responsibility for maintaining these relationships shall be clearly defined within the University ISMS, and contact details shall be reviewed and updated regularly.

6.4.3 Contact with Special Interest Groups 

a. The University shall establish and maintain contact with relevant special interest groups, industry forums, and professional associations to gain awareness of current threats, vulnerabilities, and best practices in information security. 

6.5 Intellectual Property and Asset Protection 

6.5.1 Intellectual Property Rights 

a. The University shall respect and protect intellectual property rights, including copyrights, patents, trademarks, and software licences. Appropriate processes shall be implemented to prevent infringement and to ensure that intellectual property is used in compliance with applicable laws and agreements. 

6.5.2 Protection of Information Systems During Audit Testing 

a.The University shall ensure that audit activities involving information systems are carefully managed and controlled to avoid disruption to operations, compromise of confidentiality, or damage to system integrity. Controls shall be in place to protect information systems during audit testing.  

b. The University shall carefully protect information used for testing to prevent unauthorised access, disclosure, or misuse. Test data shall be anonymised or deidentified wherever possible, and the use of live production data shall only occur with appropriate authorisation and safeguards.  

6.6 Quality Assurance and Continuous Improvement 

6.6.1 Independent Review of Information Security 

a. The University shall ensure that the ISMS and associated controls are independently reviewed at planned intervals to confirm their effectiveness and alignment with the University’s objectives, compliance obligations, and risk management approach.  

b. The University shall ensure that the Information Security Management System (ISMS) is subject to planned internal audits and independent reviews. These audits and reviews shall confirm the ISMS is operating effectively, remains aligned with the University’s objectives, and meets applicable legal, regulatory, and contractual requirements. Findings shall be documented, reported to senior management, and used to drive continual improvement.  

6.6.2 Systematic Review and Improvement 

a. The ISMS shall be subject to continuous, systematic review and improvement.  

b. This and other ISMS policies shall be reviewed to respond to any changes in the risk assessment or risk treatment plan, biennially.  

6.6.3 Planning of Changes

a. Changes to the ISMS shall be documented and carried out in a planned and controlled manner. During the implementation project phase, changes shall be managed through local project committees. Following project completion, all changes shall be managed through local Change Management processes. 

6.7 Incident Management and Business Continuity 

6.7.1 Cyber Incident Response 

a. The University shall establish and maintain a clear process for reporting and responding to information security and data privacy incidents. All staff are required to report suspected or actual incidents through defined channels without delay. Incidents shall be assessed, managed, and resolved in a timely manner to minimise impact and support compliance with legal, regulatory, and contractual obligations.  

6.7.2 Business Continuity Integration 

a. Incident management shall be integrated with the University’s business continuity and disaster recovery arrangements to ensure that essential services are maintained and critical operations are restored in the event of significant disruption. Lessons learned from incidents shall be used to improve the Information Security Management System (ISMS).  

6.8 Information Security in Project Management  

6.8.1 Information security should be integrated into all University projects regardless of type, size, or complexity. 

6.8.2 Information security risks should be assessed at project initiation and reviewed periodically throughout the project lifecycle. Risk treatment effectiveness should be monitored and tested. 

6.8.3 Security requirements for project deliverables should be identified early in the project planning phase and addressed throughout project execution.

6.8.4 Project oversight bodies should review information security activities at defined project stages, with clear allocation of security responsibilities to project roles.  

6.8.5 Access controls and authentication requirements for project systems shall be established based on the sensitivity of information involved. 

6.8.6 Projects involving third parties should establish security requirements in formal agreements, and project systems shall integrate with University security monitoring capabilities. 

6.9 Capacity Management 

6.9.1 Capacity requirements for information processing facilities, human resources, software licenses, and physical facilities shall be identified based on business criticality, with system performance tuned and monitored using detective controls to identify issues before they impact availability or security.

6.9.2 Critical systems shall undergo stress testing to verify sufficient capacity exists for peak demand scenarios. 

6.9.3 Capacity planning should account for business growth and system changes, particularly for resources requiring extended procurement.

6.9.4 Capacity issues shall be addressed through demand reduction (data deletion, system decommissioning, process optimisation) or capacity increases (additional resources, cloud elasticity). 

6.9.5 Dependencies on key personnel shall be identified and managed to avoid single points of failure. 

6.9.6 Capacity management plans shall be documented for mission-critical systems.  

6.10 Protection of Records 

6.10.1 Records shall be protected from loss, destruction, falsification, and unauthorised access in accordance with legal and regulatory requirements. 

6.10.2 A retention schedule should specify record types, required retention periods, approved storage methods, and authorised disposal processes.

6.10.3 Records shall be stored in systems that enable timely retrieval and protect against technology obsolescence. 

6.10.4 Encryption keys and tools required to access secured records shall remain available throughout retention periods. 

6.10.5 Record protection levels should align with the University's information classification standard, and essential metadata should be maintained as part of each record. 

6.11 Logging

6.11.1 Logs shall be retained for a minimum of 90 days and should be retained for 180 days for critical or priority systems and services where possible. 

6.11.2 Systems and services should generate, at minimum, security, audit, and access logs. 

6.11.3 System and service owners shall ensure that appropriate logging is enabled, these logs should contain sufficient detail to support security investigations. 

6.11.4 Security logs shall be protected from unauthorised access, modification, and deletion, including by privileged users. 

6.11.5 Logs should be logically segmented from their source systems to prevent tampering.

6.11.6 Security logs from critical and priority systems and services should be forwarded to the University's central security event management system. 

6.11.7 Logs shared with third parties for support or troubleshooting purposes should be redacted or sanitised where possible to remove personal or organisationally sensitive information. Where this is not feasible, an appropriate non-disclosure agreement must be in place prior to sharing.

6.12 Monitoring 

6.12.1 Critical and priority systems and services should be monitored to detect anomalous behaviour indicative of security incidents. 

6.12.2 Threat intelligence should be integrated with security monitoring to enable detection of known indicators of compromise. 

6.12.3 Logging and monitoring activities that process sensitive data should be handled in accordance with the University's data protection requirements and may be subject to an IDPR or DPIA. 

6.12.4 Where critical or priority systems and services are managed by a supplier, logging and monitoring may be operated by the supplier as part of the service. 

6.12.5 Enterprise units or research environments managing or conducting confidential or highly confidential research may implement local logging and monitoring processes where required to meet specific research governance or contractual obligations. 

7. Compliance with this policy 

7.1.1 For staff, failure to comply with this and the other related policies in the ISMS may result in disciplinary action being taken against you under the relevant University procedures up to and including summary dismissal and/or in the withdrawal of permission to use the University’s facilities. If there is anything in this policy that you do not understand, please discuss it with your line manager. 

7.1.2 For non-employees, failure to comply with this and the other related policies in the ISMS may result in your network access being revoked until the non-compliance is rectified. 

7.1.3 The University reserves the right to audit compliance with this and the other related policies in the ISMS. 

7.1.4 Where there is evidence that a criminal offence may have been committed because of any misuse of the University’s information technology and communications systems, this may be referred to the police or the appropriate regulatory authority. 

8. Roles and responsibilities 

8.1 Details of roles and responsibilities within the University of Southampton are defined in the following controlled documents and sites, which form part of the University Information Security Management System (ISMS): 

8.1.1 ISMS Roles and Responsibilities 

8.1.2 ISMS-UOS-004 NETSCC Roles & Responsibilities Document

8.1.3 ISMS-UOS-002 Roles & Responsibilities Document 

9. Policy Implementation and Sub-Policy List 

9.1 Implementation Timeline 

9.1.1 This policy becomes effective immediately upon approval. Associated sub-policies will be implemented according to the following priority schedule: 

a. Phase 1 (0-6 months): Critical security policies  

b. Phase 2 (6-12 months): Operational policies  

c. Phase 3 (12-18 months): Strategic and governance policies  

9.2 Sub-Policy List 

Policy NumberPolicy Name  
SECPOL-UOS-1002  Security Incident Response Policy  
SECPOL-UOS-1003  Cyber Essentials Compliance Policy  
SECPOL-UOS-1004  Acceptable Use Policy  
SECPOL-UOS-1005  Removable Media Policy  
SECPOL-UOS-1006  Remote Working Policy  
SECPOL-UOS-1007  Staff Commencement Transfer and Termination Policy  
SECPOL-UOS-1008  Inventory of Assets Policy  
SECPOL-UOS-1009  Information Transfer Policy  
SECPOL-UOS-1010  Data Protection Policy  
SECPOL-UOS-1011  Information Classification Policy  
SECPOL-UOS-1012  Disposal and Reuse Policy  
SECPOL-UOS-1013  Identity and Access Control Policy (Password Policy) 
SECPOL-UOS-1014  Cryptographic Controls Policy  
SECPOL-UOS-1015  Physical and Environmental Protection Policy 
SECPOL-UOS-1016Clear Desk and Clear Screen Policy  
SECPOL-UOS-1017  Change Management Policy  
SECPOL-UOS-1018  Secure Remote Connection Policy  
SECPOL-UOS-1019  Endpoint Management Policy  
SECPOL-UOS-1020  Backup and Restoration Policy  
SECPOL-UOS-1021  Network Protection Policy
SECPOL-UOS-1022  Secure System Development Policy  
SECPOL-UOS-1023  Supplier Management Policy  
SECPOL-UOS-1024  Disaster Recovery Policy
SECPOL-UOS-1025Business Continuity Policy  
SECPOL-UOS-1026  Risk Management and Exception Policy  
SECPOL-UOS-1027  Cloud Security Policy  
SECPOL-UOS-1028  Security Awareness Training Policy  
SECPOL-UOS-1030  Vulnerability and Patch Management Policy  
SECPOL-UOS-1031  Bring Your Own Device Policy  

10. Governance, Review, Oversight and Improvement 

10.1  The University shall maintain effective governance of the Information Security Management System (ISMS) to ensure that information security remains aligned with organisational objectives, legal and regulatory obligations, and emerging risks. Senior management shall provide oversight and accountability for information security performance, ensuring that responsibilities are clearly assigned and adequate resources are available.

10.2 The ISMS, associated policies, and supporting controls shall be subject to regular review and independent assessment to confirm their continuing suitability, adequacy, and effectiveness. Findings from internal and independent audits, risk assessments, incident investigations, and lessons learned shall be used to drive continual improvement. 

10.3 The University should establish appropriate committees or groups with relevant stakeholder representation as needed to oversee information security and the implementation of the Information Security Management System (ISMS). 

10.4 The University shall ensure that changes in the organisational context, business objectives, technological environment, or regulatory landscape are reflected in the ISMS and related policies in a timely manner. Governance processes shall promote a culture of accountability, risk awareness, and continuous enhancement of information security practices across all University activities.