Skip to content Accessibility statement

Information Security Board

Information Security Board (ISB) reports to University Executive Board (UEB). 

Terms of reference

Objectives and outcomes

The purpose of the Information Security Board (ISB) is to ensure that all University data, information, records and the supporting technology services and supply chain are protected and cyber secured throughout their lifecycle, in line with legislation, required standards and identified risks.

Its aims are to:

  • Safeguard University Information - Ensure the confidentiality, integrity, and availability of all University data, information, records, and supporting IT services across their lifecycle.
  • Ensure Compliance and Good Governance - Assure compliance with relevant legislation (including data protection), regulatory requirements, and recognised security and continuity standards.
  • Provide Strategic Oversight of Information Security and Governance - Oversee the development, implementation, and performance of the University’s:
    • Information security framework
    • Information governance framework
    • Records management framework
    • Technical business resilience and continuity arrangements
  • Manage Risk Effectively - Identify, review, and monitor information security, cyber security, and records management risks, ensuring appropriate mitigation, remediation, or escalation.
  • Enhance Organisational Resilience - Strengthen the University’s ability to prevent, detect, respond to, and recover from security incidents and data breaches.
  • Promote Awareness and Capability - Support effective training, awareness, and culture in information security, data protection, and records management across the University.
  • Enable Coordinated Governance and Decision-Making - Provide a central forum for prioritising and coordinating information governance and security activities across the institution.
Remit

Remit

The remit of the Committee is:

  • Policy and Framework Oversight
    • Reviewing and approving information security, information governance, and records management policies.
    • Overseeing the effectiveness and performance of:
      • Information security frameworks
      • Business continuity and resilience frameworks
      • Corporate records management standards and policies
  • Risk Management
    • Reviewing information, cyber security, and records management risks.
    • Assigning ownership for risk treatment actions.
    • Determining which risks require escalation to senior governance bodies.
  • Compliance and Assurance
    • Monitoring compliance with:
    • Data Protection legislation and information governance requirements
    • External security and resilience standards
  • Receiving audit reports and:
    • Monitoring progress against agreed actions
    • Reporting relevant matters to the Audit and Risk Committee
  • Incident Management and Response
    • Defining and overseeing the University’s security incident and data breach management processes.
    • Monitoring incident reporting, impact assessment, and response activity.
    • Sponsoring and reviewing institution-wide testing of incident response and continuity arrangements.
  • Training and Awareness
    • Overseeing the provision and effectiveness of training on:
      • Information security
      • Data protection and compliance
      • Records management
  • Coordination and Prioritisation
    • Providing oversight and prioritisation of Information Governance activities across the University.
    • Ensuring alignment between security, governance, and operational initiatives.
  • Communication and Stakeholder Engagement
    • Ensuring effective communication of:
      • Security risks, changes, and initiatives
      • Projects impacting wider University systems and services
    • Engaging with stakeholders to minimise risk and disruption.
  • Collaboration and Integration
    • Liaising with relevant internal groups, committees, and external stakeholders to ensure coordinated governance and alignment.
Committee authority, reporting and frequency

Authority

The Information Security Board has no budgetary control as set down in related policy and documentation, including the Scheme of Delegated Authority (SoDA).

The ISB is authorised to:

  • Approve policies within its remit
  • Escalate risks and issues to senior governance bodies
  • Commission reviews, audits, or investigations related to information security and governance

Reporting to UEB

ISB reports key points arising from its meetings to UEB as follows:

  • Bi-monthly: Meeting minutes.
  • Bi-annual: Through the ISB Update.
  • Annually:  Cyber Security Annual Report.
  • Ad hoc: where urgent University-wide matters require direct escalation to the University Executive Board  for decision or discussion.

Reporting to the Committee

The Information Security Board has the following core committees reporting into it:

  • ISO27001 DSH Management Group - Annual
  • ISO27001 SDDS Management Group - Annual
  • ITS Security Group - Bi-Monthly
  • PCI Working Group - Annual

Beyond this ISB is empowered to establish its own sub-groups and committees to reflect the requirements of University-level initiatives, promoting a task and finish approach where possible. The actions of the sub-groups/committees (or updates drawn from these in writing) should be presented to ASB on a timely basis.

 

Meetings

Meeting Frequency

The Information Security Board will meet a minimum of six times per year. Additional meetings may be called at the discretion of the Chair.

Meeting modes

Meetings will be held either in-person, online or via a hybrid format, subject to agreement by members.

Meeting dates 2026-27

Date Time
Friday 7 August 2026 14:00 - 15:30
Thursday 17 September 2026 14:00 - 15:30
Wednesday 18 November 2026 11:00 - 12:30
Wednesday 27 January 2027 14:00 - 15:30
Wednesday 17 March 2027 09:00 - 10:30
Thursday 13 May 2027 15:30 - 17:00
Thursday 15 July 2027 14:00 - 15:30

 

Constituency and Members

Other membership considerations

Professional Support members are drawn from across the University and between them have sufficient experience to be able to speak to the matters discussed by UIC from a range of levels and experiences. 

In consultation with the Chair, members may authorise an appropriate colleague to represent them if they are unable to attend a meeting. Individual colleagues may be invited to attend in order to advise and inform on select items as and when the need arises.

Quorum

50% of members, or 50% rounded up where the number of members is odd.

Membership Review

Membership will be periodically reviewed by the Committee itself on behalf of UEB's approval by the Chair. Membership is otherwise coterminous with the individual’s appointment term. Gender balance and wider EDI considerations should be factored into the Committee’s reflection on its own size and composition.

Members

  • Nigel Alcock, Chief Financial and Operating Officer (Chair)
  • Michael Barber, Contracts & Sponsorship Manager (Research, Knowledge Exchange Contracts)
  • Tyrrell Basson, Director of Information Technology
  • Gary Brannan, Keeper of Archives and Special Collections, Borthwick Institute for Archives
  • Durham Burt, Data Protection Officer
  • Justine Daniels, Director of Research, Innovation and Knowledge Exchange (RIKE)
  • Rachel Devaney, Director of Procurement & Transactional Services
  • Julia Durham, Head of Legal Services
  • Kris Fieldhouse, Assistant Director of Campus Services
  • Charles Fonge, Records Manager and University Archivist
  • Richard Fuller, Assistant Director of IT (Technology and Cyber)
  • Chris Goodman-Bowen, Head of Campus Safety
  • Chris Hewitt, Business Intelligence, MI and Higher Education Manager
  • Rob Hurt, Head of Cyber Security
  • Sarah Kennedy, Assistant Director of IT (Service Delivery and Product)
  • Rob McCarthy, Head of Student Systems
  • Alex McFarlane, HR Systems Manager
  • Laura McIlroy, Employee Relations and HR Policy Manager
  • Rachael Millhouse, Director of Human Resources
  • Adrian Murgatroyd, Assistant Director, Finance Shared Services Business Systems (HR/Student)
  • Anna Payne, Research Centre Coordinator and Manager, Centre for Health Economics
  • Laura Robinson, Marketing and Communications Manager 
  • Siamak Shahandashti, Senior Lecturer, Department of Computer Science
  • Calum Stevens, Cyber Risk and Compliance Manager

In attendance

  • Steve Austin, Head of DPS (Desktop, Print & Support Services)
  • Estelle Idiens, PA to the Chief Reputation & Stakeholder Relations Officer and the Director of IT Services (Secretary)

Parent committee and associated subcommittees