Overview
The University of Toronto Information Security strategy sets the mission, vision, goals, objectives, and outcomes that will drive the information security priorities for the University of Toronto over the next four years. It aims to enrich and support the University’s academic mission by enabling scholars, researchers, academics, and staff.
The strategy was developed through a community-driven approach. This involved extensive consultation with academic and administrative units and incorporates the voices of several community members. It was also influenced and shaped by the IT@UofT strategy and the NIST Cyber Security Framework, along with results of internal and external security assessments, reality of the security threat landscape, and advice from security experts.
By setting a shared direction for information security at the University, the strategy empowers units to identify their priorities, define and execute operational plans, and measure progress over the next four years.
Our mission and vision
Mission
Enable world-class teaching, learning, and research through information security leadership and services that empower people, adapt to risk, and respond to the diverse needs of the university community.
Vision statement
Secure Together.
Message from the Chief Information Security Officer
The world is rapidly becoming a digital-first experience. At the University this is reflected in our hybrid learning environments, course registration processes, real-time research collaboration across the world, and use of data to drive effective evidence-based decision making.
Information and technology are at the core of almost everything we do today. It is therefore essential that we enable resilient ecosystems that ensure the security and safety of our people, data, and systems, wherever they are.
Our vision is to work together, each of us doing our small part to help secure our ecosystem, so we can focus on what matters most: our learners, our scholars, our staff, and the communities we are in.
Our systems and workflows must not only meet discipline-specific needs but also have security and privacy embedded into their design. This, coupled with the influence of those who are best informed to make the right decisions, is how we will enable transformative education, innovative research, and the University’s Three Priorities.
We truly are Secure Together.
Objectives and outcomes
- Secure University digital transformation
- Seamless access to the digital university enabled through a single identity
- Appropriate protections for our people, data, and systems regardless of location
- Innovative approaches to securing the next generation of digital solutions
- Information Security regarded as an enabler of digital transformation and the University mission
- Trustworthy teaching, learning, and research
- An information security-aware culture
- Accelerated adoption of privacy-conscious edtech solutions
- Seamless information security support across the entire research lifecycle
- Alignment with University data governance strategic outcomes
- Resiliency through effective risk management
- Risk management programs adopted by units and reviewed by the Information Security Council
- Cyber incidents prevented or detected and responded to in a timely manner
- Managed supply chain risk
- Common framework to address regulatory and compliance obligations
- Excellence through collaboration
- Normalized collaboration on cybersecurity across the University
- Increased use of secure shared platforms, capabilities, and methodologies
- Experiential learning and career growth opportunities for students, faculty, and staff
- Strong sector partnership on shared opportunities and challenges
Our strategic goals
- 1Enable the mission of the University
- 2Uphold privacy, openness, and free inquiry
- 3Deliver a world-class, exemplary information security program
Guiding principles
Overview of Security at U of T
Elements of the Security Program:
- Identify outcomes and risks
- Protect against security threats
- Detect security issues as quickly as possible
- Respond timely to limit impact
- Recover and get back to teaching & research
What matters most:
- People
- Data
- Systems
Our goals:
- Enable the mission of the University
- Uphold privacy, openness, and free inquiry
- Deliver a world-class, exemplary information security program
Our objectives:
- Secure University digital transformation
- Trustworthy teaching, learning, and research
- Resiliency through effective risk management
- Excellence through collaboration
Initiatives for a world-class program
Office of the CISO focus areas for 2023-24
- Build a security-aware culture by providing curated and contextual information security and privacy training, and simulated phishing exercises. Learn about the SAT Foundations project.
- Drive development of divisional risk management programs signed off by the unit head and reviewed by the Information Security Council.
- Reduce risk to critical assets and endpoints through expansion of next-generation anti-virus protection. Learn about the Endpoint Protection Program.
- Proactive identification, tracking and reporting of security vulnerabilities. Learn about the Vulnerability Management Service.