The goal of the policy
This policy aims to provide cybersecurity requirements based on best practices and standards related to documenting cybersecurity requirements and the university's compliance with them, in order to reduce cyber risks and protect the university from internal and external threats. This is achieved by focusing on the core objectives of protection, namely: confidentiality, integrity, and availability of information, in application of the controls set by the National Cybersecurity Authority (NCA) and in accordance with the international information security standard ISO 27001.
Policy scope
This policy applies to all information technology and technical projects, including university employees, temporary staffing agency personnel, suppliers, partners, contractor personnel, and functional units, regardless of geographical location. The Cybersecurity Department is responsible for resolving any issues arising from the implementation of this policy. This policy serves as the primary driver for all cybersecurity policies, procedures, and standards across various topics, as well as an input for internal processes such as human resources, vendor management, project management, change management, and others.
Policy elements
- Cybersecurity management must establish cybersecurity standards and document its policies and programs, based on the results of the risk assessment, in a manner that ensures the dissemination and adherence to cybersecurity requirements, in accordance with the university's organizational business requirements and relevant legislative and regulatory requirements. They must also be approved by the authorized authority and disseminated to the relevant university employees and stakeholders.
- The cybersecurity administration must develop, implement, and enforce cybersecurity policies, programs, and standards.
- The Cybersecurity Department is authorized to access information and gather the necessary evidence to ensure compliance with relevant legislative and regulatory requirements pertaining to cybersecurity.