Information Security Policies and Standards We create and maintain documentation to support appropriate information security in all UCL operations. This includes reviewing existing documentation, developing new policies and retiring old ones. Main Information Security Policy Document Information Security PolicyDefinition of Terms used in the Policy Supporting Documentation Acceptable Use Policy How to use UCL systems in a secure and responsible way. Classification of Information Assets How to classify and document information assets. Technical Asset Management How to manage the security of UCL’s technical assets. Appropriate Security Controls Information on appropriate security controls. Risk Management How to identify, assess and record risks. Third Party Risk Due diligence of third-party suppliers and services. Incident Management How UCL manages security incidents. Individual Responsibility for Security How individuals can help UCL stay secure. Business Continuity Managing backups & recovery plans to reduce the risk of service loss.