LUMS

GRC and IST Policies

The Governance, Risk and Compliance (GRC) function oversees a framework of policies designed to protect institutional data, manage information-related risks, strengthen cybersecurity, and promote responsible use of university information and technology resources.

The following are among the key IST policies available to provide guidance, establish standards, and support compliance by relevant stakeholders across the University:

Access Control Policy

Defines how access to university systems, applications, and data is granted, managed, reviewed, and revoked based on roles and responsibilities. 

Download Policy | Download Annexures/Procedure


Password Policy

Establishes requirements for creating, using, protecting, and managing passwords for university accounts and systems to reduce the risk of unauthorized access. 

Download Policy


Computer Policy

Establishes guidelines for the appropriate acquisition, allocation, use, security, maintenance, transfer, and disposal of university-owned computers and other computing resources. 

Download Policy | Annexure


Information Security Policy

Establishes requirements for protecting university information and technology resources against unauthorized access, loss, misuse, and cybersecurity threats. 

Download Policy


Electronic Messaging Policy

Provides guidelines for the secure and appropriate use of university email and other electronic communication platforms, including the protection of confidential and sensitive information. 

Download Policy | Annexure


IT Governance Policy

Defines the principles, roles, responsibilities, decision-making structures, and oversight mechanisms for the effective governance and management of information technology across the University. 

Download Data Governance Policy | Download Data Governance Review Policy


These policies serve as a reference framework for faculty, staff, students, and other concerned stakeholders, helping ensure that university IT resources and institutional data are managed securely, responsibly, consistently, and in compliance with applicable requirements.