Main Content

This policy statement lays down the objectives, motivation and direction for Scottish Enterprise to protect its business information, systems and networks.

Information and information systems are fundamental to Scottish Enterprise in its role as Scotland’s main economic development agency supporting business growth and developing the business environment.

This policy includes all information and data handled, information systems, and networks operated by, and for, Scottish Enterprise. This covers the organisation of Scottish Enterprise, and includes outlying and international offices.

What's in the policy? 

This policy covers the following topics:

  1. Alignment with security standards
  2. Authority
  3. Balancing democratic and commercial security requirements
  4. Compliance with legal requirements - Data Protection Act, Freedom of Information Act, etc
  5. The principal tenets of information security
  6. Types and scope of information
  7. Security commitment
  8. Risk management principals
  9. Individual responsibility and accountability for security awareness
  10. The security management infrastructure
  11. Technical procedures - whoever is custodian of systems
  12. Customer contracts

Download the information security policy (PDF, 172 KB)