Information security

Information and resources to help combat security threats and keep the University's and your data safe

Why is Information Security important?

Information is one of the most important assets to an organisation and all information is valuable and should be appropriately protected. Security is a combination of systems, operational procedures and internal controls to ensure integrity, confidentiality and availability of data to support the operation of the organisation.

'Why is Information Security important' video created by Security Fresh.

 

Information security policies

Whether you are a student, member of staff or contractor, you all have an important part to play in protecting University systems and the information stored on them. The information security policies below explain those expectations, obligations and conditions of use which you should read, understand and comply with. These policies have been comprehensively reviewed and revised to make them easier to read, and we are committed to a regular review cycle to ensure they remain accessible and helpful.

Staff information security policy

1. Purpose

This policy sets out the conditions of use for University computers and systems, in order to protect those systems and the information stored on them for which the University is legally responsible. Adherence to this policy is mandatory and non-compliance could lead to disciplinary action.
If you need any help complying with this guidance (for example technical assistance) please contact Technology & Information Services (TIS) via IT Self Service.

2. Personal use

University systems exist to support and enable the aims of the University. A reasonable amount of personal use is allowed. However, it must not cause damage or disruption to computers or networks, or any difficulty, damage or distress to others. 
In a home working environment, you are responsible for ensuring University equipment and the data stored on it are protected from access by family, friends and visitors. 
2.1. Personal data
Unless specifically marked as ‘Personal’, all data stored on systems managed by Technology and Information Services (TIS) is considered to be work-related. As such it does not constitute personal information which is protected under Human Rights legislation, and therefore may be accessed by the University with due authority. 
2.2. Monitoring, auditing and control
The University reserves the right to monitor use of IT systems and data, audit networks and systems and implement technical controls. We do this to secure data and systems, and to protect the safety of other users. All monitoring and auditing is conducted in compliance with UK legislation. 

3. Protection of information

You should take care of any University information you have access to including your own work, and protect it against unauthorised disclosure, modification or destruction. Here are three simple steps you can take to protect your identity and your work:
1. Look after the password for your University account. You must never disclose your password to anyone (including IT staff will never ask you for your password). 
2. Update any personal computers and devices you use to access University information with the latest software patches and updates, and protecting your computer using up to date anti-virus software.
3. Secure any personal computer or device you use to access University information with a PIN or password. This makes it harder for someone to access your personal information or University information if your device is lost or stolen.
3.1. Information classification
You must handle University information according to the University Information Classification Policy. This policy defines how University information is classified based on its level of sensitivity and its value to the University. That classification then determines how you should store, process and transfer that data. You should take particular care to handle Personally Identifiable Information (PII) in accordance with the University Data Protection and Information Classification Policies.
3.2. Personally identifiable information in email
If you handle confidential or restricted personally identifiable information in email (e.g. you have teaching, supervision or management responsibilities), you must not forward your email to a third party email service, as this would be in breach of the University Information Classification Policy. 
3.3. Clear desk and clear screen
Hard copy confidential data should be locked away when not required, especially when you are not in your office or remote working space. 
Computers you use to access University systems and data should be secured with a ‘lock-on-idle’ policy after (at most) 10 minutes of inactivity. In addition, the screen and keyboard should be manually locked by the responsible user whenever leaving the machine unattended. 
3.4. Mobile devices and remote working
Because information on portable devices such as laptops, tablets and smartphones, is especially vulnerable, special care should be exercised with these devices. You will be held responsible for the consequences of theft of or disclosure of information on portable devices you use for work if you have not taken reasonable precautions to secure it (including those set out in this policy). 
3.5. Information transfer
You must not send, upload, remove on portable media or otherwise transfer to a non-University system any information that is designated as confidential, or which you could reasonably regard as being confidential to the University, except where explicitly authorized by your line manager or the information asset owner.
3.6. Use of personal email 
The use of personal non-University email accounts for any University communications or activities is prohibited. All University-related emails must be conducted through designated University email accounts to ensure the security, confidentiality, integrity and availability of University information. Exception requests will be managed on a case-by-case basis and recorded accordingly.

4. Reporting security events

If you think your computer or a University computer is infected with a virus, your account password is known by someone else, or you believe information is at risk for any other reason, you should immediately report this as breach by following the personal data breach process. There is no penalty for reporting something which turns out not to be legitimate, so if in doubt, report it.

5. Unacceptable use

All users should use their own judgement regarding what is unacceptable use of University systems. Below are some examples of unacceptable use of University systems. This list is not exhaustive, and when using University systems you should bear in mind the terms and conditions of your employment contract, the University Equality, Diversity and Inclusion Policy, and ultimately the interests and wellbeing of colleagues and students. 
5.1. Examples of unacceptable use of University IT systems
  • Creation or transmission of material (including via social media) which is defamatory and could constitute harassment or bullying, or simply intends to cause annoyance, inconvenience or needless anxiety.
  • Communication which could constitute emotional abuse or sexual violence (including the non-consensual sharing of indecent or sexual images). 
  • Creation or transmission of material with the intent to defraud. 
  • Creation or transmission of material such that this infringes the copyright of another person.
  • Deliberate unauthorised access to networked facilities or services.
  • Illegal activity including, but not limited to, accessing pornographic images or sites or media which are specifically designed to promote terrorism or which advocates or promotes any unlawful act.
  • Any activity which jeopardises the security, integrity, performance or reliability of University IT systems including the introduction of malware or attempting to disrupt or circumvent IT security measures.
  • Any activity which brings the University into disrepute.
     
Version 1.1. Reviewed no changes. Contributor: Anthony Bruton (Information Security Manager). Approved 02 September 2026. Next review Q3 2027
Version 1.1. Amendments: Section 3.6 added. Contributor: Anthony Bruton (Information Security Manager). Approved 03 June 2024. Next review Q3 2025
Version 1.0. Author: Richard Bartlett (Enterprise Security Architect).  Approved 9 February 2021

Student information security policy

1. Purpose

The University cares about the experience of our students and we want you to be safe at all times whilst you are studying with us.
This policy sets out the ways you should keep your information secure and the expectations you may have of other staff and students in relation to information security and safety. It includes some rules you must follow in order to protect your student digital identity and the University data and systems you have access to.
If you are unclear or have any questions about this policy please contact the Library

2. Scope

This policy applies to your use of IT systems as a student. If you are employed by the University your use of IT systems as an employee is covered by the Staff Information Security Policy. If you are employed by the Student Union please refer to their information security policy. 

3. Personal use

University systems exist to support and enable the aims of the University. A reasonable amount of personal use is allowed. However, it must not cause damage or disruption to computers or networks, or any difficulty, damage or distress to others.
3.1. Personal data
Unless you mark specific data as personal, anything stored on University-managed systems will be considered to be stored in accordance with the aims of the University. This means it does not constitute personal information as protected by human rights legislation, and the University may access this data at any time. 

4. Monitoring, auditing and control

The University reserves the right to monitor your use of IT systems and data, audit networks and systems and implement technical controls. We do this to secure data and systems, and to protect the safety of other users. All monitoring and auditing is conducted in compliance with UK legislation. 

5. Protection of information

You should take care of any University information you have access to including your own work, and protect it against unauthorised disclosure, modification or destruction. Here are three simple steps you can take to protect your identity and your work.
1. Look after the password for your University account. You must never disclose your password to anyone (including IT staff who will never ask you for your password).
2. Update any computers and devices you use to access University information with the latest software patches and updates, and protecting your computer using up to date anti-virus software.
3. Secure any computer or device you use to access University information with a PIN or password. This makes it harder for someone to access your personal information or University information if your device is lost or stolen. 

6. Reporting security events

If you think a University computer is infected with a virus, your account password is known by someone else, or you believe information is at risk for any other reason, you should immediately report this as breach by following the personal data breach process. There is no penalty for reporting something which turns out not to be legitimate, so if in doubt, report it. 

7. Unacceptable use

Below are some examples of unacceptable use of University systems. This list is not exhaustive, and when using University systems you should bear in mind the Student Code of Conduct and Disciplinary Procedure, and ultimately the interests and wellbeing of University staff and your fellow students.
If we have a concern that you may have acted in a way that was not compliant with this policy, the University will carry out an investigation which could, in cases of major misconduct being found proven, result in a sanction up to and including your permanent expulsion from the University. 
7.1. Examples of unacceptable use of University IT systems
  • Creation or transmission of material (including via social media) which is defamatory and could constitute harassment, hate crime or bullying, or simply intends to cause annoyance, inconvenience or needless anxiety. 
  • Communication which could constitute emotional abuse or sexual violence (including the non-consensual sharing of indecent or sexual images). 
  • Creation or transmission of material with the intent to defraud. 
  • Creation or transmission of material such that this infringes the copyright of another person. 
  • Deliberate unauthorised access to networked facilities or services. 
  • Illegal activity including, but not limited to, accessing pornographic images or sites or media which are specifically designed to promote terrorism or which advocates or promotes any unlawful act. 
  • Any activity which jeopardises the security, integrity, performance or reliability of University IT systems including the introduction of malware or attempting to disrupt or circumvent IT security measures. 
  • Any activity which brings the University into disrepute.
     
Version 1.0. Reviewed no changes. Contributor: Anthony Bruton (Information Security Manager). Approved 02 September 2026. Next review Q3 2027
Version 1.0. Reviewer: Anthony Bruton (Information Security Manager). Approved 03 June 2024. Next review Q3 2025
Version 1.0. Author: Richard Bartlett (Enterprise Security Architect). Approved 9 February 2021

IT information security policy

1. Purpose

This policy sets out the University’s approach to managing its information security objectives (see below). It addresses the governance and operation of IT security and sits above the Staff and Student Information Security policies, which address user behaviour.
1.1. Audience and scope
The audience for this policy is managers, technical staff, information asset owners, system owners, and others responsible for the management, operation, delivery, or oversight of University information assets, systems, services, and infrastructure.
This policy applies to all University organisational units, including Technology Information Services, professional services, faculties, schools, research groups, and other teams that own, manage, operate, support, or procure information assets, systems, services, or facilities. Such organisational units are responsible for implementing and maintaining controls necessary to comply with this policy and associated standards for assets under their control.

2. Information security roles and responsibilities

Role: Senior Information Risk Owner (SIRO)
Role/title: University Secretary and Registrar
Responsibility: Providing accountability and assurance to UEG that information governance policies, including data protection and information security policies are complied with. 
Role: Information Asset Owners
Role/title: Executive Deans Directors, Deputy Vice-Chancellors, members of the Senior Leadership forum
Responsibility: Has accountability and authority to manage the risk; approving the risk treatment plan and residual risk for the risks that they own. 
Role: Risk Assessors
Role/title: Privacy Coordinators
Responsibility: Compliance with Data Protection policy, including assessment of information security risk within their organisational area. 
Role: Risk Assessors
Role/title: TIS Enterprise Security
Responsibility: Assessing cyber security risk across the University and providing advice on appropriate mitigating measures. 
Role: Security Incident Management
Role/title: IT Director
Responsibility: Co-ordinating the University’s technical response to a major or critical information security incident. 

3. Information classification

The University Information Classification policy sets a framework for classifying and handling University information based on its level of sensitivity, and its value to the University. Personally Identifiable Information (PII) must be managed and protected in accordance with the University Data Protection and Information Classification Policies. 

4. Communications security

4.1. Network controls
Any part of the University that manages a network, or networks on behalf of others, shall define and implement responsibilities and procedures to protect information, systems, applications, and network services.
Information transmitted across University networks, including University-managed cloud environments, shall be protected against unauthorised access, interception, or modification through appropriate digital and physical security controls, including encryption where required by the information classification and risk profile.
University operated wireless networks shall be protected using modern authentication and encryption technologies ('modern' meaning currently in active development and supported by a vendor or community). Cryptographic controls used for wireless networks shall meet approved institutional standards and applicable regulatory requirements.
Connections to University systems and services shall be protected using modern authentication and encryption technologies. Where this is not possible, the exception shall be documented, managed as an information security risk, and approved through the University risk management process.
Network security events shall be logged from network devices, including routers, firewalls, wireless infrastructure, and virtual network infrastructure in cloud hosted environments and retained in accordance with the University records retention schedule.
Access to systems connected to the University network through wired, wireless, remote access, or VPN connections shall be authenticated unless an exception has been formally approved by the institution responsible for managing the network.
Network controls shall be implemented to appropriately segregate and protect information systems, network services, and network connections based on business requirements, risk, and information classification.
Network activity shall be monitored and logged to support the identification, investigation, and response to security events.
Network controls shall be implemented to protect the confidentiality, integrity, and availability of University information and services.
4.2. Unauthorised use
Attaching more than one device to any network port by use of network switches, firewalls, routers or wireless access points or any other means without authority should be prevented using technical controls. Use of any software or hardware which causes disruption to the correct functioning of University systems is prohibited under the Student and Staff Information Security Policies. If such disruption does occur the offending device or software should be disconnected from the University network by the institution responsible for managing the network. 

5. Access control

Access to University information, systems and resources shall only be granted based on need, the principle of least privilege, and in accordance with the University Information Classification and Data Protection policies.
Access rights shall be assigned, reviewed, modified and removed throughout the user account lifecycle to reflect changes in employment status, enrolment status, role, responsibilities and requirements.
5.1. Regular user access control
Role Based Access Control (RBAC) shall be used wherever possible to assign access rights throughout the account lifecycle, with access determined by approved roles and data from authoritative staff and student information systems or other relevant information systems.
Access granted outside approved RBAC roles shall be authorised and reviewed regularly. Where recurring exceptions are identified, RBAC roles shall be modified or created where practicable to minimise individual access assignments.
All user accounts shall be uniquely assigned to an individual and remain inactive until the user's identity has been verified through an approved process. Following activation, users shall establish their own authentication credentials.
As the status of a user changes within the relevant information systems, accounts shall either:
  • be deactivated promptly if no longer required and deleted after no more than three months; or 
  • have access rights and group memberships amended to reflect the user's current role and responsibilities. 
Access rights shall be reviewed regularly to ensure they remain appropriate and authorised. Information asset owners shall approve and periodically review access to sensitive information assets under their control.
Privileged or administrative access shall be granted only where required, approved by an appropriate authority, and reviewed regularly.
5.2. Privileged user access control
Staff who require privileged access for the technical administration of information systems must be provided with a separate account for that purpose. Those accounts are only for use where privileged access is required, and not for any routine activity including email or instant messaging and web browsing.
Privileged access to systems must be reviewed by system owners annually.
Role Based Access Control (RBAC) is the default method of assigning privileged access rights based on the responsibilities of that member of staff.
Any privileged access granted outside the RBAC groups must be reviewed as part of the annual privileged account review, and wherever possible RBAC groups should be created or modified to incorporate that access to minimise exceptions.
Technical controls should enforce enhanced authentication measures (including but not limited to increased password length, multi-factor authentication and conditional access) for all privileged accounts.
Access to and administration of systems by privileged accounts must be logged. 

6. Protection from malware

6.1. Security awareness
The University Induction Policy requires all staff to complete Data Protection and Information Security Training at the start of their employment, and every two years thereafter. This training includes information on how to stay safe online and avoid viruses.
6.2. Controlling software installation and use
Staff should not have administrative access to desktops and laptops unless their role requires it. Where administrative access is required it should be actively managed, proportionate to user need, wherever possible time limited, and subject to annual review.
6.3. Malware detection
The Student and Staff Information Security Policies (see above) require that all personal computers which store or process University information must be protected using up to date anti-virus software, and updated frequently with the latest operating system and application patches and updates. University computers must comply with the same requirement, and wherever possible anti-virus and patching should be managed by IT to ensure compliance.
Email services used in the University must have built-in malware protection to prevent the transmission of viruses contained in both inbound and outbound messages.

7. Management of technical vulnerabilities

7.1. Inventory of assets
All University server and endpoint (desktop and laptop) assets should be recorded within an IT asset inventory which should be maintained and regularly reviewed by the responsible IT team to ensure it is accurate.
7.2. Identifying vulnerabilities
Appropriate information sources and resources shall be maintained to identify vulnerabilities affecting assets within the University asset inventory and shall be updated to reflect changes to that inventory.
System owners are responsible for identifying, monitoring, assessing, and addressing vulnerabilities affecting systems under their control. TIS is responsible for providing oversight, guidance, including advising the University on the level of risk presented and assurance activities where required.
To support these responsibilities, TIS may assess, audit, or monitor University systems, infrastructure, and networks to verify compliance with information security policies, standards, and regulatory requirements.
7.3. Reacting to vulnerabilities
A documented process shall be maintained for assessing the risk of identified vulnerabilities and implementing appropriate corrective actions. The process shall define roles and responsibilities and how actions are recorded for audit and review purposes.
Identified vulnerabilities shall be addressed through appropriate corrective actions, including patching, mitigation, compensating controls, or approved workarounds, based on the level of risk.
High risk or critical security updates for operating systems, firmware, applications, and other supported technology assets shall be addressed as soon as possible and within 14 days of release for all systems.
Medium and low risk security updates shall be applied on a regular maintenance cycle and, where possible, within 30 days of release.
Where vulnerabilities or security updates cannot be addressed within the required timeframe, the exception shall be documented, managed as an information security risk, approved by the appropriate authority, and reviewed regularly.
7.3.1 Patch Management Requirements
Update classification and required timeframe
  •  Critical / High - Within 14 days of release
  •  Medium - Within 30 days of release
  •  Low - Within 30 days of release
  •  Unable to Patch - Risk assessment, compensating controls, and formal approval and exception logging required
7.4. Monitoring vulnerabilities
Owners of systems and infrastructure shall ensure compliance with applicable vulnerability and patch management requirements.
A documented process shall be maintained to verify that network and server infrastructure remains compliant with applicable security update requirements.
The process shall include the identification, reporting, escalation, and remediation of non compliant systems.
Vulnerability and patch compliance information shall be reviewed regularly to support the timely remediation of identified issues. 

8. Backup

All data should be backed up according to its value to the University, the cost of recreating the data, any financial costs or penalties which might be incurred as a result of data loss or corruption, and the risk of data loss or corruption. 
The primary purpose of data backup is to allow the Faculty or Service to continue its activity after a data loss incident, by retrieving some or all of the data lost, ideally from a point in time backup taken within the last 24 hours.
All backups should meet the following minimum requirements: 
  • It has been designed to meet the recovery time and recovery point requirements of the Faculty or service.
  • It is physically secured against theft.
  • It is sufficiently resilient that failure of a single hardware component would not result in data loss.
  • It is held separately from the original data storage location such that it would be unaffected by hardware or software failure or physical/environmental incidents (e.g., fire or flood).
  • It is protected from unauthorised access through technical controls and as far as possible physical separation from the original data storage location (to prevent destruction in the event of a security incident, e.g. ransomware). 
  • It is tested at least annually to ensure the data backed up could be used in the event of a data loss incident.
Suitable backup locations include cloud based backup services, tape libraries and mirroring to resilient disk storage. Portable backup devices are not suitable for backup of PII or data where loss would result in significant cost to recreate or disclosure would result in financial penalties due to breach of legislation or regulation

9. Cryptographic controls

University information shall be protected at all times in accordance with the University Information Classification Policy. Where the policy requires encryption, modern cryptographic controls shall be used to protect information both at rest and in transit. This requirement applies to servers, desktop computers, laptops, mobile devices and other systems that store or process University information.
Where cryptographic protection cannot be implemented, the exception shall be documented, managed as an information security risk, approved by the appropriate authority, and reviewed at least annually.
Backups shall be encrypted to prevent unauthorised access, disclosure, modification, or loss of information.
Wherever possible, cryptographic key management solutions shall be used to centrally provision, store, manage, rotate, and revoke encryption keys and secrets.
Responsibilities for the implementation, management, and monitoring of cryptographic controls and cryptographic keys shall be clearly defined.

10. Physical and environmental security

Areas where sensitive or critical information is processed, stored, or accessed shall be provided with an appropriate level of physical security and access control based on the criticality of the information, systems, and services they support.
Access to such areas shall be restricted to authorised individuals with a legitimate business, academic, or operational need. Staff and other authorised individuals granted access shall be provided with information on the relevant security risks and the measures used to control them.
The organisational unit responsible for the area shall ensure appropriate physical security controls are implemented, maintained, and reviewed.
As the status of an individual changes within the relevant area, physical access rights shall either:
  • be removed promptly if no longer required; or 
  • be amended to reflect the individual’s current role and access requirements based on business need. 
Access rights shall be reviewed regularly to ensure they remain appropriate and authorised. 
Records relating to access must be retained in accordance with the University records retention schedule.
10.1 Low Criticality Systems
Areas supporting low criticality systems shall be protected through normal building access and control procedures.
10.2 Medium Criticality Systems
Areas supporting medium criticality systems shall be located in defined rooms or facilities with controlled access using appropriate physical access controls.
Visitors, contractors and delivery personnel shall be identifiable, authorised where required, and supervised while in controlled areas.
10.3 High Criticality Systems
Areas supporting high criticality systems shall be located within specially designated secure areas with physical security controls appropriate to the level of risk.
Access to high criticality areas shall be controlled and recorded through an approved access control mechanism.
Visitors, contractors, and delivery personnel shall be authorised, identifiable, and accompanied at all times within high criticality areas.
Deliveries and public enquiries shall be managed so as to prevent unauthorised access to high criticality areas.

11. Supplier relationships

Responsibility for the management of supplier relationships should be clearly documented. 
Cloud service providers and third-party software suppliers should by default have no access to University data, including administrative accounts on systems. Data is protected by access control and encryption, with the encryption keys being managed and controlled by the University. Non-Disclosure Agreements (NDAs) shall be used in all situations where the disclosure of Confidential or Restricted to a Cloud service provider or third-party software supplier is deemed necessary and appropriate.
Supplier access to systems should only be allowed when authorised by the University as part of a technical support call or planned maintenance activity, provided on the principle of least privilege, audited and logged. Where necessary, supplier access will be accompanied or observed in order to ensure compliance with University policy. 

12. Information security incident management

 Any part of the University that manages their own network or systems, or manages networks or systems on behalf of others should establish Incident Management procedures to ensure a quick, effective and orderly response to information security incidents. Those procedures should identify the individual or team responsible for responding to information security incidents. 
12.1. Identifying security events
Information security events reported by service users or triggered by monitoring and management systems should be recorded. Those events should be assessed by staff with the appropriate skills and experience (or an appropriate third party), and decision made whether those events are classified as an information security incident 
12.2. Responding to security incidents
Information security incidents should be recorded as such and responded to according to the institution’s documented incident management procedures. Any knowledge gained from analysing and resolving those incidents should be recorded and used to reduce the likelihood or impact of future incidents. 
Any evidence gathered during the incident response process should be appropriately recorded, and as far as possible original evidence should be preserved as per ACPO guidelines and ISO/IEC 27037
The institution's incident management procedures should include appropriate escalation guidance, such as for internal escalation (including to TIS, Legal, HR, Finance and the Media and Communications Team), and for reporting to the relevant authorities (Jisc, Action Fraud, and the South West Regional Cyber Crime Unit).

13. Mobile device management

The scope of Mobile Device Management applies to mobile devices for which the University requires security controls to enable access to University information, systems, or services.
Mobile devices within scope shall be authorised, maintained in a secure and supported state, and protected using security controls appropriate to the information classification, level of risk and method of access.
Where required by the University, mobile devices shall be enrolled in an approved Mobile Device Management (MDM) solution to enable the application and enforcement of security controls.
Where mobile access is permitted, appropriate authentication, cryptographic, and device security controls must be applied according to the information classification and level of risk.
Loss, theft, compromise, or non-compliance of an in-scope mobile device shall be reported promptly and may result in the removal of access to University systems and information.
Exceptions to mobile device security requirements shall be documented, managed as an information security risk, approved by the appropriate authority, and reviewed regularly.

14. Compliance and Audit

Compliance with information security policies, standards, legal, regulatory, and contractual requirements shall be monitored and assessed regularly.
The University may undertake audits, reviews, and assessments to verify compliance with information security requirements and the effectiveness of security controls. Relevant users and stakeholders shall cooperate with authorised compliance and audit activities.
Non compliance, control deficiencies, and audit findings shall be recorded, addressed through appropriate corrective actions, and managed through the University risk management processes.
Exceptions to information security requirements shall be documented, approved by the appropriate authority, managed as an information security risk, and reviewed regularly.
 
Version 1.1. Reviewer: Anthony Bruton (Information Security Manager). Approved 02 September 2026. Next review Q3 2027
Version 1.0. Reviewer: Anthony Bruton (Information Security Manager). Approved 03 June 2024. Next review Q3 2025
Version 1.0. Author: Richard Bartlett (Enterprise Security Architect). Approved 9 February 2021
 
computer and information security plymouth

Study information security at University of Plymouth

Cyber security is now widely recognised as an international priority, with hacking, malicious code, and data theft being just three of the many reasons why it's vital in the design, development and implementation of today’s IT systems. Our courses deliver a view of security threats and solutions, alongside an essential background in wider IT topics.
Find out more about our courses:
Certificate in Education (incorporating the Diploma in Education and Training)

Information security training

If you have discovered a vulnerability or weakness within our network, please report it to the Enterprise Security Team.
If you want to report an information security incident, please contact the Enterprise Security Team.

If you have any ideas or suggestions regarding our information security, please share them with us!

Email: infosecurity@plymouth.ac.uk