Information Governance

IOSHQ Information Security Policy

The IOSHQ Information Security Policy establishes principles for protecting institutional information, user accounts and digital systems against unauthorized access, disclosure, alteration, loss or disruption.

Purpose

Purpose of the IOSHQ Information Security Policy

IOSHQ relies on digital systems and information to support educational, credential, administrative and institutional activities. Appropriate security controls help protect those resources throughout their use, storage and transmission.

This policy provides a general security framework rather than disclosing confidential technical configurations, defensive controls or operational security procedures.

Security Principles

Protecting IOSHQ Information

Information security measures should reflect the nature of the information, its institutional purpose and the risks associated with unauthorized access, modification, disclosure, destruction or unavailability.

Confidentiality

Information should be accessible only to people, systems or services with an appropriate reason and authorization to access it.

Integrity

Reasonable controls should protect records and systems against unauthorized or inappropriate alteration.

Availability

Systems and information should remain appropriately available for legitimate institutional and user needs.

Access Control

Account and System Access

Access to non-public IOSHQ systems and information should be limited according to legitimate responsibilities and operational requirements. Access rights may be changed or withdrawn when they are no longer appropriate.

Users are responsible for protecting credentials assigned to them and should not intentionally permit unauthorized individuals to use their accounts.

Information Protection

Handling Sensitive and Personal Information

Information requiring protection should be handled according to its sensitivity, purpose and applicable institutional requirements. Personal information should also be managed consistently with the IOSHQ Privacy Policy and relevant records-management practices.

Controlled Access

Sensitive information should not be made available to people who do not have an appropriate reason to access it.

Responsible Sharing

Information should be shared only through appropriate channels and for legitimate institutional purposes.

Records Management

Security considerations continue throughout the retention, archival and disposal lifecycle of institutional records.

User Security

Responsibilities of System Users

Anyone authorized to use an IOSHQ digital system should take reasonable precautions to protect their account and the information available through it.

Protect Credentials

Passwords and other authentication information should be kept confidential and protected against unauthorized use.

Recognize Suspicious Activity

Unexpected login activity, suspicious communications or unexplained account changes should be treated cautiously.

Report Concerns

Suspected compromise, unauthorized access or other security concerns should be reported promptly.

Security Incidents

Information Security Incident Reporting

A suspected information security incident may include unauthorized account access, unintended disclosure, loss of protected information, malicious activity or another event that could compromise an IOSHQ-controlled system or institutional record.

Security concerns should be reported without deliberately exploiting, altering or publicly exposing the affected system. IOSHQ may review relevant information and take proportionate measures to contain, investigate and address a reported incident.

Third Parties

External Systems and Service Providers

IOSHQ may rely on third-party technology or service providers for particular digital functions. Where external systems process or store institutional information, appropriate consideration should be given to the nature of the service, information involved and relevant security or privacy requirements.

Users who leave an IOSHQ-controlled website for an external service should also review the applicable provider’s security, privacy and account practices.

Responsible Use

Information Security and Acceptable Use

Security also depends on responsible use. Unauthorized access attempts, deliberate interference with systems, malicious activity and misuse of accounts are addressed further by the IOSHQ Acceptable Use Policy.

Frequently Asked Questions

IOSHQ Information Security Policy FAQ

It establishes general principles for protecting IOSHQ-controlled information, accounts and digital systems against unauthorized access, disclosure, alteration, loss and disruption.

Protect the account by changing applicable credentials where possible and report the suspected compromise promptly through the appropriate IOSHQ support channel.

No. The public policy establishes general information-security principles without publishing confidential technical configurations or defensive security details.

Use the IOSHQ Contact page to report a suspected security issue. Avoid deliberately exploiting or publicly exposing the affected system while the concern is being reviewed.

Information Security

Report a Security Concern

Contact IOSHQ if you identify suspected unauthorized access, account compromise or another security concern affecting an IOSHQ-controlled service.