Status and Details

Status and Details

This page contains information about the status, approval and implementation of this document, contact details for enquiries about document application/interpretation, and a brief summary of changes between this and the previous version.

Information Technology - User Device Security Standard

Status Current
Effective Date 12th September 2025
Review Date 3rd June 2029
Approval Authority Chief Operating Officer
Approval Date 18th April 2024
Expiry Date Not Applicable
Policy Author Sinan Erbay
Chief Information Officer
Policy Owner Fiona Notley
Chief Operating Officer
Enquiries Contact ITS Governance, Risk and Compliance

Summary of Changes from Previous Version

12/09/2025: Document republished following minor amendment, as approved by the COO on 12 September 2025.

Clauses 22-25 added to address Removable Media. Initiated under the ITS Cyber Program, this revision is aimed at:

• Aligning with NIST 800-53 to enhance our security maturity by adopting international standards.
• Supporting auditing requirements to ensure compliance with the annual NIST audits and aligning with the NIST Cybersecurity Framework (CSF).
• Standardising practices and facilitating a common language throughout our procedures, consistent with NIST guidelines.

Clauses Amended:Standard: 22-25