IOSHQ Information Security Policy
The IOSHQ Information Security Policy establishes principles for protecting institutional information, user accounts and digital systems against unauthorized access, disclosure, alteration, loss or disruption.
Purpose of the IOSHQ Information Security Policy
IOSHQ relies on digital systems and information to support educational, credential, administrative and institutional activities. Appropriate security controls help protect those resources throughout their use, storage and transmission.
This policy provides a general security framework rather than disclosing confidential technical configurations, defensive controls or operational security procedures.
Protecting IOSHQ Information
Information security measures should reflect the nature of the information, its institutional purpose and the risks associated with unauthorized access, modification, disclosure, destruction or unavailability.
Confidentiality
Information should be accessible only to people, systems or services with an appropriate reason and authorization to access it.
Integrity
Reasonable controls should protect records and systems against unauthorized or inappropriate alteration.
Availability
Systems and information should remain appropriately available for legitimate institutional and user needs.
Account and System Access
Access to non-public IOSHQ systems and information should be limited according to legitimate responsibilities and operational requirements. Access rights may be changed or withdrawn when they are no longer appropriate.
Users are responsible for protecting credentials assigned to them and should not intentionally permit unauthorized individuals to use their accounts.
Handling Sensitive and Personal Information
Information requiring protection should be handled according to its sensitivity, purpose and applicable institutional requirements. Personal information should also be managed consistently with the IOSHQ Privacy Policy and relevant records-management practices.
Controlled Access
Sensitive information should not be made available to people who do not have an appropriate reason to access it.
Responsible Sharing
Information should be shared only through appropriate channels and for legitimate institutional purposes.
Records Management
Security considerations continue throughout the retention, archival and disposal lifecycle of institutional records.
Responsibilities of System Users
Anyone authorized to use an IOSHQ digital system should take reasonable precautions to protect their account and the information available through it.
Protect Credentials
Passwords and other authentication information should be kept confidential and protected against unauthorized use.
Recognize Suspicious Activity
Unexpected login activity, suspicious communications or unexplained account changes should be treated cautiously.
Report Concerns
Suspected compromise, unauthorized access or other security concerns should be reported promptly.
Information Security Incident Reporting
A suspected information security incident may include unauthorized account access, unintended disclosure, loss of protected information, malicious activity or another event that could compromise an IOSHQ-controlled system or institutional record.
Security concerns should be reported without deliberately exploiting, altering or publicly exposing the affected system. IOSHQ may review relevant information and take proportionate measures to contain, investigate and address a reported incident.
External Systems and Service Providers
IOSHQ may rely on third-party technology or service providers for particular digital functions. Where external systems process or store institutional information, appropriate consideration should be given to the nature of the service, information involved and relevant security or privacy requirements.
Users who leave an IOSHQ-controlled website for an external service should also review the applicable provider’s security, privacy and account practices.
Information Security and Acceptable Use
Security also depends on responsible use. Unauthorized access attempts, deliberate interference with systems, malicious activity and misuse of accounts are addressed further by the IOSHQ Acceptable Use Policy.
IOSHQ Information Security Policy FAQ
It establishes general principles for protecting IOSHQ-controlled information, accounts and digital systems against unauthorized access, disclosure, alteration, loss and disruption.
Protect the account by changing applicable credentials where possible and report the suspected compromise promptly through the appropriate IOSHQ support channel.
No. The public policy establishes general information-security principles without publishing confidential technical configurations or defensive security details.
Use the IOSHQ Contact page to report a suspected security issue. Avoid deliberately exploiting or publicly exposing the affected system while the concern is being reviewed.
Report a Security Concern
Contact IOSHQ if you identify suspected unauthorized access, account compromise or another security concern affecting an IOSHQ-controlled service.
