IT Security Process

IT Security Process

What is the IT Security Process?

IT Security is fundamental to an organisation’s ability to operate is a world of ever increasing digital threats.
The key principles of our IT security in the University are:

-          protection of the IT network and devices

-          protection of identities

-          protection of data and

-          promoting security awareness amongst all University of Galway users.

 IT Security is the responsibility of all individual users of IT systems. It is enforced through an array of processes and technologies.
Governance is crucial to the development and implementation of an appropriate IT security posture for the University.
The ICT Security and Data Protection Committee is a subcommittee of the University’s Risk Management Group and is the primary body overseeing the implementation of IT security measures. The committee develops IT Security Policies, monitors compliance and reviews security and data protection incidents. The membership of the committee is drawn from the Academic, Research and Professional Support communities within the University to ensure that the needs of these communities are adequately represented in the development of IT security solutions.

Further Information

Policies & Documents

An up to date catalog of all IT Security Policies is available here:

ICT Policies - University of Galway

A more comprehensive overview of IT Security in the University, including links to IT Security training, is available here:IT Security - University of Galway

ICT Security and Data Protection Committee
IT Security and Data Protection Committee TORs - Draft

Roles & Responsibilities

Please see below for a detailed accountability matrix and the key contacts for this area.  

Head of IT Security

If you have any queries on IT Security, please contact the declan.staunton@universityofgalway.ie

Contact me

Other Key Contact

If you have additional queries on IT Security, please contact declan.staunton@universityofgalway.ie

Contact Me

IT Security Process RACI

Coming Soon

RACI Explained

RACI stands for Responsible, Accountable, Consulted and Informed.  See below for a further explanation. 

RESPONSIBLE "Doer"

The person or group who is assigned to ensure the works is completed to meet the goals, objectives and overall quality as expected, who will report to the accountable team as to progress, and calls out any risks or impediments to that success

ACCOUNTABLE "Buck Stops Here"

The person or group who is ultimately answerable for the correct and thorough completion of the workstream, ensures the prerequisites are met to support success, and delegates the work to those responsible

CONSULTED "In the Loop"

The person or group in two-way communications in relation to the process or decision

INFORMED "FYI"

The group or person kept informed of the decision or process

Related Processes

Coming Soon