Information Security Board
Remit
Remit
The remit of the Committee is:
- Policy and Framework Oversight
- Reviewing and approving information security, information governance, and records management policies.
- Overseeing the effectiveness and performance of:
- Information security frameworks
- Business continuity and resilience frameworks
- Corporate records management standards and policies
- Risk Management
- Reviewing information, cyber security, and records management risks.
- Assigning ownership for risk treatment actions.
- Determining which risks require escalation to senior governance bodies.
- Compliance and Assurance
- Monitoring compliance with:
- Data Protection legislation and information governance requirements
- External security and resilience standards
- Receiving audit reports and:
- Monitoring progress against agreed actions
- Reporting relevant matters to the Audit and Risk Committee
- Incident Management and Response
- Defining and overseeing the University’s security incident and data breach management processes.
- Monitoring incident reporting, impact assessment, and response activity.
- Sponsoring and reviewing institution-wide testing of incident response and continuity arrangements.
- Training and Awareness
- Overseeing the provision and effectiveness of training on:
- Information security
- Data protection and compliance
- Records management
- Coordination and Prioritisation
- Providing oversight and prioritisation of Information Governance activities across the University.
- Ensuring alignment between security, governance, and operational initiatives.
- Communication and Stakeholder Engagement
- Ensuring effective communication of:
- Security risks, changes, and initiatives
- Projects impacting wider University systems and services
- Engaging with stakeholders to minimise risk and disruption.
- Collaboration and Integration
- Liaising with relevant internal groups, committees, and external stakeholders to ensure coordinated governance and alignment.
Committee authority, reporting and frequency
Authority
The Information Security Board has no budgetary control as set down in related policy and documentation, including the Scheme of Delegated Authority (SoDA).
The ISB is authorised to:
- Approve policies within its remit
- Escalate risks and issues to senior governance bodies
- Commission reviews, audits, or investigations related to information security and governance
Reporting to UEB
ISB reports key points arising from its meetings to UEB as follows:
- Bi-monthly: Meeting minutes.
- Bi-annual: Through the ISB Update.
- Annually: Cyber Security Annual Report.
- Ad hoc: where urgent University-wide matters require direct escalation to the University Executive Board for decision or discussion.
Reporting to the Committee
The Information Security Board has the following core committees reporting into it:
- ISO27001 DSH Management Group - Annual
- ISO27001 SDDS Management Group - Annual
- ITS Security Group - Bi-Monthly
- PCI Working Group - Annual
Beyond this ISB is empowered to establish its own sub-groups and committees to reflect the requirements of University-level initiatives, promoting a task and finish approach where possible. The actions of the sub-groups/committees (or updates drawn from these in writing) should be presented to ASB on a timely basis.
Meetings
Meeting Frequency
The Information Security Board will meet a minimum of six times per year. Additional meetings may be called at the discretion of the Chair.
Meeting modes
Meetings will be held either in-person, online or via a hybrid format, subject to agreement by members.
Meeting dates 2026-27
| Date | Time |
|---|---|
| Friday 7 August 2026 | 14:00 - 15:30 |
| Thursday 17 September 2026 | 14:00 - 15:30 |
| Wednesday 18 November 2026 | 11:00 - 12:30 |
| Wednesday 27 January 2027 | 14:00 - 15:30 |
| Wednesday 17 March 2027 | 09:00 - 10:30 |
| Thursday 13 May 2027 | 15:30 - 17:00 |
| Thursday 15 July 2027 | 14:00 - 15:30 |
Constituency and Members
Other membership considerations
Professional Support members are drawn from across the University and between them have sufficient experience to be able to speak to the matters discussed by UIC from a range of levels and experiences.
In consultation with the Chair, members may authorise an appropriate colleague to represent them if they are unable to attend a meeting. Individual colleagues may be invited to attend in order to advise and inform on select items as and when the need arises.
Quorum
50% of members, or 50% rounded up where the number of members is odd.
Membership Review
Membership will be periodically reviewed by the Committee itself on behalf of UEB's approval by the Chair. Membership is otherwise coterminous with the individual’s appointment term. Gender balance and wider EDI considerations should be factored into the Committee’s reflection on its own size and composition.
Members
- Nigel Alcock, Chief Financial and Operating Officer (Chair)
- Michael Barber, Contracts & Sponsorship Manager (Research, Knowledge Exchange Contracts)
- Tyrrell Basson, Director of Information Technology
- Gary Brannan, Keeper of Archives and Special Collections, Borthwick Institute for Archives
- Durham Burt, Data Protection Officer
- Justine Daniels, Director of Research, Innovation and Knowledge Exchange (RIKE)
- Rachel Devaney, Director of Procurement & Transactional Services
- Julia Durham, Head of Legal Services
- Kris Fieldhouse, Assistant Director of Campus Services
- Charles Fonge, Records Manager and University Archivist
- Richard Fuller, Assistant Director of IT (Technology and Cyber)
- Chris Goodman-Bowen, Head of Campus Safety
- Chris Hewitt, Business Intelligence, MI and Higher Education Manager
- Rob Hurt, Head of Cyber Security
- Sarah Kennedy, Assistant Director of IT (Service Delivery and Product)
- Rob McCarthy, Head of Student Systems
- Alex McFarlane, HR Systems Manager
- Laura McIlroy, Employee Relations and HR Policy Manager
- Rachael Millhouse, Director of Human Resources
- Adrian Murgatroyd, Assistant Director, Finance Shared Services Business Systems (HR/Student)
- Anna Payne, Research Centre Coordinator and Manager, Centre for Health Economics
- Laura Robinson, Marketing and Communications Manager
- Siamak Shahandashti, Senior Lecturer, Department of Computer Science
- Calum Stevens, Cyber Risk and Compliance Manager
In attendance
- Steve Austin, Head of DPS (Desktop, Print & Support Services)
- Estelle Idiens, PA to the Chief Reputation & Stakeholder Relations Officer and the Director of IT Services (Secretary)