<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:x="urn:schemas-microsoft-com:office:excel" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-GB" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">Hello,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I've been asked to forward the following to you by Ronnie Wallace (Faculty IT Coordinator), about the Information Security policies of the University.
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Details can be found here:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><a href="http://www.strath.ac.uk/staff/policies/informationsecurity/">http://www.strath.ac.uk/staff/policies/informationsecurity/</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Here are the highlights:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><b>(a) Before purchasing a new device, staff should consult with their local IT staff as required by the Policy on the Procurement of IT Commodity Devices<o:p></o:p></b></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">This policy came about for two reasons. Firstly it is to ensure that the University can fulfil its obligations to ensure that devices are encrypted. This is seen as a vital step for all organisations by the Information Commissioner. It
was also a direct recommendation in the Information Security Audit carried out by the External Auditors on our Faculty in 2013. It will also help ensure that devices are set up to take advantage of the many software packages and operating systems for which
the University has a site license.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I no longer want IT support staff to be in the position where they are presented with a device from a member of staff of which they have had no input in the procurement process.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><b>(b) No one should ever have to share their authentication credentials with another colleague<o:p></o:p></b></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Anyone finding that they have to do this to complete a task may have a problem with their access rights that can easily be addressed or possibly needs advice and/or training on different ways to achieve the same results. If they do have
such issues it is important that these are identified so they can be addressed.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><b>(c) In the James Weir fire a large amount of very valuable information was on local devices<o:p></o:p></b></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Following the fire none of this information could be accessed until after the devices were cleaned and this led to long delays in retrieving vital data. Local devices are also easily lost or stolen and of course can fail. For these reasons,
wherever possible use should be made of network filestore rather than using storage on the local device.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">In relation to network filestore, the University’s provisioning has recently taken a step change and so should meet most user/dept requirements. With regard to departments that offer their own networked storage it should be at the very
least mirrored between two different buildings. (The University storage offering is mirrored and replicated across two sites and backed up to a third site.)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I would expect a migration away from departmentally hosted storage services in the longer term as the Research Data Management and Sharing Project delivers new tools to access that storage such as Strathcloud.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Every effort should be made to avoid carrying USB data pen drives. If you do, and they contain information that is confidential or commercially sensitive, encrypting them is vital.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><b>(d) Unsurprisingly Disaster Recovery shot up the agenda following the James Weir fire and it was also highlighted as an area to be addressed in the Information Security Audit completed last year<o:p></o:p></b></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">It is important that IT systems on which you depend for your day to day operation have Disaster Recover Plans in place. These are already in place for centrally provided systems like email, central filestore and PEGASUS. However if anyone
in your department offers an IT services that performs a critical function for the running of your department and/or faculty it needs to have a Disaster Recovery Plan in place (reviewed annually) and stored on the University’s external Sharepoint site.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">It is stored externally so that it could still be accessed following a catastrophic event that meant all IT systems were unavailable. Details of how to access this site and a document template have previously been provided to your department
IT staff contacts.<o:p></o:p></p>
<p class="MsoNormal">If you would like to discuss any of this further feel free to get in touch.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">If you want more information on these policies, or help in complying with them, please contact me or Colin Bain.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Many thanks,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Timothy<o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:10.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt">Timothy Briggs<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt">Research and Teaching Support<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt">Department of Physics, University of Strathclyde, John Anderson Building, 107 Rottenrow, Glasgow G4 0NG<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt">Tel: 0141 548 3376 Fax: 0141 552 2891 Email:
<a href="mailto:timothy.briggs@strath.ac.uk"><span style="color:blue">mailto:timothy.briggs@strath.ac.uk</span></a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt">The University of Strathclyde is a charitable body, registered in Scotland, number SC015263<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>