Information security policy

Published: 13 July 2026
Freedom of information class: How we manage our resources

This policy sets out the commitment of the Registers of Scotland (RoS) to protect information in all its forms including electronic, paper, from known threats, whether internal or external, accidental, or deliberate.


1. Purpose and scope

1.1 This information security policy is a key component of RoS management framework. It sets the requirements and responsibilities for maintaining the security of information within RoS. This policy may be supported by other policies and by guidance documents to assist putting the policy into practice day-to-day.

1.2 RoS is committed to ensuring that effective security arrangements are implemented and regularly reviewed to reduce the threats and manage risks to:

  • the information that RoS collects, creates, uses and stores
  • RoS employees, contingent workers, customers, and citizens
  • our physical assets and resources
  • our digital, IT and communication systems
  • premises that RoS uses to accommodate its operations, people, and visitors

1.3 All information that is created, processed, stored, transmitted or destroyed (physically or electronically) during the course of RoS business activity is an asset of the organisation and as such is governed by this policy and those in the Information Security Management System (ISMS) suite of related policies.

This policy is applicable to all RoS employees and third-party staff (e.g. contingent workers consultants, resource company employees, temporary employees) that use or have access to RoS systems or information. The specific requirements and responsibilities for particular roles are captured in this policy.

2. Information Security principles

2.1 The core information security principles are to protect the following information or data asset properties:

  • confidentiality (C) – property that information is not made available or disclosed to unauthorised individuals, entities or processes
  • integrity (I) – property of accuracy and completeness
  • availability (A) – property of being accessible and useable on demand by an authorised entity.

2.2 In addition to the core principles of C, I and A, information security also relates to the protection of reputation, as reputational loss can occur when any of the C, I or A properties are breached resulting in financial losses from regulatory fines.

The aggregation effect, by association or volume of data, can also impact upon the confidentiality property.

3. Terminology

TermMeaning/application
Shall This term is used to state a Mandatory requirement of this policy
Should This term is used to state a Recommended requirement of this policy
May This term is used to state an Optional requirement

4. The policy

The Information Security Policy outlines the approach, methodology and responsibilities for preserving the confidentiality, integrity and availability of RoS information.

It is the overarching policy for information security, supported by specific technical security, operational security and security management policies. This policy covers:

  • Information Security principles
  • governance – outlining the roles and responsibilities
  • supporting specific information security policies such as Technical Security, Operational Security and Security Management
  • compliance requirements.

5. Roles and responsibilities

All staff

5.1 Information Security and the appropriate protection of information assets is the responsibility of all users, and individuals are expected at all times to act in a professional and responsible manner whilst conducting RoS business.

All staff are responsible for information security and remain accountable for their actions in relation to RoS and other UK Government information and information systems. Staff shall ensure that they understand their role and responsibilities.

This policy should be part of the publication scheme. Internally all employees must be made aware of the policy, and it must be a mandatory read for all employees and contingent workers working for RoS.

Accountable Officer

5.2 The Accountable Officer is accountable for information risk within RoS and advises Senior Management on the effectiveness of information risk management across the organisation. Operational responsibility for Information Security shall be delegated by the accountable officer to the Information assurance security group (ISAG)

All Information Security risks shall be managed in accordance with the RoS Risk Management policy.

Security Working Group

5.3 The Security Working Group is responsible for the day-to-day operational effectiveness of the Information Security policy and its associated policies and processes.

The Security Working Group shall:

  • lead on the provision of expert advice to the organisation on all matters concerning information security, compliance with policies, setting standards and ensuring best practice
  • provide a central point of contact for information security
  • ensure the operational effectiveness of security controls and processes
  • monitor and co-ordinate the operation of the Information Security Management System
  • be accountable to the ISAG and other bodies for Information Security across RoS
  • monitor potential and actual security breaches with appropriate expert security resource.

Data Protection Officer

5.4 The Data Protection Officer (DPO) is responsible for ensuring that RoS and its constituent business areas remain compliant at all times with Data Protection, Privacy and Electronic Communications regulations, Freedom of Information Act and the Environmental Information regulations.

The DPO shall:

  • lead on the provision of expert advice to the organisation on all matters concerning the Data Protection Act, compliance, best practice and setting and maintaining standards
  • provide a central point of contact for the Act both internally and with external stakeholders (including the Office of the Information Commissioner)
  • communicate and promote awareness of the Act across RoS
  • lead on matters concerning individuals right to access information held by RoS.

Information Asset Owners

5.5 The Information Asset Owner (IAOs) are senior, responsible individuals involved in running the business area and shall be responsible for:

  • understanding what information is held
  • knowing what is added and what is removed
  • understanding how information is moved
  • knowing who has access and why.

Risk owners

5.6 All risk owners are individually responsible for ensuring that this policy and information security principles shall be implemented, managed and maintained in their business area. This includes:

  • appointment of Risk Action Manager to be responsible for Information Assets in their area(s) of responsibility
  • awareness of information security risks, threats and possible vulnerabilities within the business area and complying with relevant policies and procedures to monitor and manage such risks
  • supporting personal accountability of users within the business area(s) for Information Security
  • ensuring that all staff under their management have access to the information required to perform their job function within the boundaries of this policy and associated policies and procedures.

The Information Security Assurance Group (ISAG)

5.7 ISAG is accountable for information governance, which includes requirements for the protection and handling of RoS information assets.

6. Approval and review

This policy will be reviewed and approved by the ISAG annually, unless earlier review is appropriate.

Author Information Assurance Advisor
Reviewed Head of Information Security Risk & Assurance
Cleared Head of Risk and Information Governance
Approval ISAG Approval date May 2026
Policy version V 4.0
Review responsibility ISAG Review date April 2027
Publication scheme Yes
Email to contact

SRA@ros.gov.uk