Information Security Policies | IT Help and Support
Cyber crime is a persistent and ever-changing threat to the University and its people. The University is taking action to protect itself from this threat. We have a number of policies that set out our approach to information security.
Information Security Policies | IT Help and Support skip to content Study at Cambridge About the University Research at Cambridge Search site Home Study at Cambridge Undergraduate Undergraduate courses Applying Events and open days Fees and finance Postgraduate Postgraduate courses How to apply Postgraduate events Fees and funding International students Continuing education Executive and professional education Courses in education About the University How the University and Colleges work Term dates and calendars History Map Visiting the University Annual reports Equality and diversity News A global university Events Public engagement Jobs Give to Cambridge Research at Cambridge For staff For Cambridge students For alumni For our researchers Business and enterprise Colleges & departments Email & phone search Give to Cambridge Libraries Museums & collections IT Help and Support University Information Services Home New startersNew starters overview StudentsStudents overview Researchers Academic staff and visitorsAcademic staff and visitors overview Professional services staffProfessional services staff overview Institutions IT servicesIT services overview Accounts and passwordsAccounts and passwords overview SecuritySecurity overview EmailEmail overview PhonesPhones overview WifiWifi overview Network servicesNetwork services overview CloudCloud overview Collaboration toolsCollaboration tools overview Data and file storageData and file storage overview PrintingPrinting overview Desktop servicesDesktop services overview Support and IT trainingSupport and IT training overview SoftwareSoftware overview Teaching and learningTeaching and learning overview Research admin and computingResearch admin and computing overview Central systems and management reportingCentral systems and management reporting overview Websites and intranetsWebsites and intranets overview Retired services Service informationService information overview Signing up to service status messages Vulnerable periods System changes News A-Z Contact usContact us overview How to find us Staff Information Security Policies IT Help and Support New starters IT services Service information News A-Z Contact us Staff Cyber crime is a persistent and ever-changing threat to the University and its people. The University is taking action to protect itself from this threat. We have a number of policies that set out our approach to information security. For policies and guidance from other areas, visit the Policy Hub, a central source of links from across the University. Acceptable Use Policy What is it for Sets out the way in which the University’s information services should be used by authorised users. Read a summary of the policy and key actions for users. Who does it apply to All users Implementation date 1 April 2024 (Transition period to 1 April 2025) Systems Management Policy What is it for Sets out what system administrators, user account managers, and institutions must do to protect the University’s systems against common cyberattacks. Read a summary of the Systems Management Policy (University login required) Who does it apply to Staff who manage and are responsible for multi-user computer systems. Implementation date 1 April 2024 (Transition period to 1 April 2026) Email Allocation and Retention Policy What is it for Sets out the criteria for allocation and retention of University email addresses. Read a summary of the Email Allocation and Retention Policy Who does it apply to All users Implementation date Trial year from 1 January 2024. A pilot to test the processes for applying the policy for people who are leaving the University is taking place during the academic year 2023-24 at a limited number of institutions. Data Protection Policy What is it for Ensures compliance with the UK General Data Protection Regulation, the Data Protection Act 2018 and related legislation. Read a guide to the Data Protection Policy (and access the policy) Who does it apply to All staff (except when acting in a private, non-University capacity) and all students when processing personal data on behalf of the University. Implementation date March 2023 Related policies and guidelines Privacy policies and notices The University IT facilities and services privacy notice is the main privacy notice for all University IT services, whether websites, applications, large central systems or institutional bespoke systems. This privacy notice links to the main University privacy notices which are needed to cover the legal aspect. If your system is not fully covered by this privacy notice, then you need to write a short notice to cover the differences only, and then link to this one. You then need to display this notice at the beginning of the sign-up pages to your service, or communicate with your users prior to any changes to the system which require additional privacy notice statements. Web accessibility statement Sets out our approach to web accessibility and lists all known accessibility issues. Details how to request information in a different format.The statement was prepared on 7 December 2022. It was last reviewed on 21 February 2024. Access our web accessibility statement. Domain name policy Explains how we allocate domain names under cam.ac.uk and how to apply for a new domain name. Read the Domain name policy and Guidelines for requesting domain names within cam.ac.uk University software policy terms and conditions Sets out our policy on computer software licensed by the University of Cambridge and its Colleges. Read the University software policy Authorisation for use of the Cambridge University Data Network Specifies the designated use of the Cambridge University Data Network (CUDN) Authorisation for use of the Cambridge University Data Network (CUDN) Freedom of Speech The University of Cambridge is fully committed to securing and promoting freedom of speech within the law for staff, students and visiting speakers in all activities related to academic life. Our Code of Practice on Freedom of Speech sets out the University’s values, approach and associated procedures in detail. All the University’s policies and procedures are to be interpreted and applied in a manner consistent with the Code of Practice; in the case of any perceived conflict, the provisions of the Code of Practice will take precedence insofar as that is lawful and reasonably practicable. Read our Code of Practice on Freedom of Speech Contact us Information provided by: [email protected] Privacy policy Cookies UIS facilities Videoconferencing/AV Studios Teaching room bookings Resources Accessibility guidance Privacy policy Other guidelines and policies Comms kits UIS websites IT Service Status Telecoms Office Research Computing Services University IT Service Catalogue UIS staff intranet (UIS login required) 2026 University of Cambridge Contact the University Accessibility Freedom of information Privacy policy and cookies Statement on Modern Slavery Terms and conditions University A-Z Study at Cambridge Undergraduate Postgraduate Professional and continuing education Executive and professional education Courses in education About the University How the University and Colleges work Give to Cambridge Jobs Map Visiting the University Research at Cambridge Research news About research at Cambridge Public engagement Spotlight on...