Skip to main content

Cybersecurity

Information security principles and standards

At UFV, protecting our information assets is a top priority. Our security standards are designed to safeguard our users, systems, and sensitive data. Below, you'll find key security standards that all staff, faculty, and students must follow to ensure compliance with UFV’s Information Security Policy.

These standards provide clear guidance on managing access, passwords, information handling, and email communications. Each document is available for download as a PDF.

Identity and access management standard

This standard outlines the University's requirements for the effective management of identities, accounts, and access rights. This management is essential to ensure that access to the University’s information and information systems is restricted to authorized users.

Key points:

  • Account Management
  • Privileged Account Standards
  • Access Control Policy
  • Access Review Standards

Download the Identity and Access Management standard (PDF)

Password and authentication standard

This standard outlines the University's requirements for the effective management of account password and authentication mechanisms. This management is essential to ensure that access to the University’s information and information systems is restricted to authorized users.

Key points:

  • Password requirements, storage, and management
  • Multi-factor authentication (MFA)
  • Access control

Download the Password and authentication standard (PDF)

Information classification and handling standard

This standard describes the University’s Information Handling policy, the roles and responsibilities related to Information Assets, and how to appropriately secure and handle information based on its classification. This is to ensure that the University meets its requirements for Information Security.

Key points:

  • Information classification and handling
  • Data storage and transmission
  • Personal data handling, data disposal, and removal of information

Download the Information classification and handling standard (PDF)

Data loss and encryption standard

Summary here

Key points:

  • TBD
  • TBD
  • TBD

Download the Data loss and encryption standard (PDF)

Email and communications security standard

This standard describes requirements for securing email and communications infrastructure against cyber threats in order to support the Information Security Policy and to ensure that the University meets its business requirements for Information Security.

Key points:

  • Email terms of use
  • Authentication and access control
  • Archiving and retention

Download the Email and communications security standard (PDF)