Information Security Policy
Preamble
The operation of a university depends to a large extent on the quality of its IT services. Users’ trust in information technology forms the basis for its successful use. To justify this trust, the integrity, confidentiality, and availability of IT services and data must be ensured.
To enable the university to fulfill this responsibility, all departments must support the protection of information technology. These tasks are to be managed through a continuous information security management process based on these guidelines.
This methodological approach is based on necessary rules and requires appropriate measures to protect information and data in such a way that
- their confidentiality is adequately safeguarded and access is restricted to authorized individuals,
- their integrity is ensured through their accuracy and completeness,
- their availability is guaranteed so that authorized persons can access them at the desired time,
- legal obligations (e.g., the Bavarian Data Protection Act) can be met.
This document defines policies for the following information security objectives:
- Protection of the network infrastructure and IT systems, including the data processed therein, against misuse or sabotage from both internal and external sources.
- Ensuring information security to support robust, reliable, and secure teaching, research, and administrative operations.
- Providing secure and trustworthy online services for users both within and outside the university.
- Ensuring compliance with data protection requirements arising from statutory provisions.
- Damage caused by security incidents should be prevented, and such incidents should be minimized.
This guideline applies to all information technology and to all members of the university and external users who use or provide it. It is binding for all faculties and central units of the university. External service providers involved in the information technologies used at Augsburg University are also required to comply with it.
The information security management system encompasses all necessary organizational and technical measures to achieve and maintain a defined level of information security (security level) over the long term. To achieve an adequate security level, additional measures based on a risk analysis are defined for information that requires enhanced protection.
The necessary and specific rules for achieving the appropriate security level and implementing the principles are set forth in a security concept. This document provides sufficient detail regarding the requirements of this guideline and the required security level in the form of security policies. These policies then serve as the basis for the necessary security measures. These measures are documented in implementation requirements or service-specific security concepts.
The security guidelines cover at least the following areas:
- Organization of IT security
- Determination of information values (classification)
- Access control, network, and operational security
- IT systems (such as servers, storage systems, and workstations)
- Identification of vulnerabilities and protection against malware
- Handling Security Incidents
- Backup and emergency planning
- Risk management, compliance, and data protection
- Physical security
- Communication
The Central IT Security Officer is responsible for the operation of the information security management system. He or she advises the IT Committee, the IT officers of the faculties, and the Data Center.
By conducting regular reviews of the implementation of the security concept and further developing the measures, he or she ensures adequate information security.
He or she may obtain an overview of IT security in all areas of the university.
Services offered by the university that are accessible from outside the university network must be reviewed by the IT security officer and the data protection officer.
The IT Working Group is responsible for the overall management of the information security management system. The IT Security Officer acts on behalf of the IT Working Group and methodically coordinates the information security management system.
The final decision regarding risk acceptance and the degree of implementation rests with the Executive Board, which bears overall responsibility for the proper operation and information security of the university.
To ensure the continuous development of the guideline and related documents (e.g., the security concept), information security is a regular item on the agenda of the IT Working Group’s meetings. The IT Security Officer reports on the current status and receives his or her assignments based on the decisions of the IT Working Group.
Every university employee is responsible for maintaining the required level of information security within their area of responsibility, whether as an information owner or an information processor.
The owner of the information classifies each type of information into a confidentiality class in accordance with the IT security policy on information classification. This is done based on the information’s value and sensitivity in order to establish an appropriate level of security.
Access to data and IT systems is adequately controlled through technical measures and processes, commensurate with their value and importance.
All users of applications and IT systems are uniquely identifiable and are authorized and authenticated according to their role and responsibilities.
The principle of least privilege is applied, meaning that permissions are granted only to the extent necessary to perform the respective tasks.
All changes to important information and decisions made must be traceable through appropriate logging and documentation. The information owner determines the necessity, nature, and method of logging.
The required level of information security can only be achieved if employees are made aware of information security threats, understand their own responsibilities and duties, and act responsibly.
Security-related topics and rules are communicated to university members through appropriate training or information channels.
If there is a risk of a breach of IT security affecting the university’s critical systems, a service manager from the data center, in consultation with the CIO, may order the immediate, temporary shutdown of the affected IT system, as well as temporarily bar the responsible users from using the information technology.
Security incidents are handled in accordance with a documented process for managing IT security incidents.
The IT Working Group determines the IT services for which the central IT security officer collects and coordinates emergency plans. These plans contain instructions for action in hazardous situations and in the event of incidents.
These bylaws shall take effect on the day following their publication on November 25, 2017.