Institutional high-quality accreditation link stiky-sticky

▲ Back to Top

About the ISMS

76c9f08df5da7c78a57bf23d3d7485184e0a07a7

The University of Cundinamarca understands the importance of guaranteeing the confidentiality, integrity, and availability of information as an essential asset for the provision of its services. Likewise, it seeks to ensure the processing of personal data of the institution's data subjects, as well as to protect data and perform analyses to identify vulnerabilities in computer systems in order to implement defenses against potential threats—all of the above within the context of current legal regulations and the ISO 27001:2022 standard.

Objective e1782485383955

OBJECTIVE

See more
Scope e1782485483267

SCOPE

See more

ISMS Fronts

Woman in office

Information security

The Information Security Management System – ISMS, following the guidelines and directives of the Institutional Planning Directorate, in accordance with the institution's strategic documents and in coordination with the Systems and Technology Directorate, will be the areas that will establish, manage, and promote mechanisms for the protection and safeguarding of information as the primary asset of the University of Cundinamarca, in accordance with applicable legal regulations and in line with the institution's mission and vision.

See more
Administrative staff in the office

Personal data protection

In compliance with the provisions of Statutory Law 1581 of 2012, Regulatory Decree 1074 of 2015, and other regulations concerning and governing the matter, the University of Cundinamarca adopts this personal data protection guideline, which shall be communicated to all data subjects.

See more
Occupational software

Cybersecurity

Cybersecurity is the set of actions to protect data, networks, devices, and digital environments from potential cyberattacks and hacking. By implementing cybersecurity processes and measures, organizations seek to prevent, detect, and respond to such attacks to minimize the risks of damage or loss.

Rescue software

Business Continuity

The University of Cundinamarca recognizes the existence of threats and risks that can interrupt the normal development of the provision of its academic and administrative services. Consequently, it is committed to the implementation and strengthening of a Service Continuity Management System (SCMS), designed to guarantee institutional resilience and allow the operation or timely recovery of its critical processes in the face of any disruptive incident.

News

ISMS RECOMMENDATIONS

Tip 1

INFORMATION ASSETS

  • Maternity leave Submit 10 days before the estimated delivery date certified by the EPS doctor

 

  • Scheduled medical leaves (When surgery or another medical procedure is planned) Submit 10 days before the procedure

Tip 2

DIRECTOR, HEAD OF AREA, OR COORDINATOR, REMEMBER!

You must request the accompaniment of the Information Security Panamier security lookouts for the handover of information assets when an employee resigns or is transferred to another area.

Tip 3

PLEASE NOTE!

Institutional communications of an internal and external nature must be issued solely from the institutional email accounts of directors, heads, deans, coordinators, and/or process leaders and from the area's institutional emails.

The institutional email signature must comply with the following parameters:

  • Full name of the chief director, dean, coordinator, and/or process leader.
  • Position of the chief director, dean, coordinator, and/or process leader.
  • Name of the area to which it belongs.
  • Institutional email of the area.
  • Address of the headquarters, sectional or extension and Bogotá office.

Tip 4

Information security in expert hands!

  • Engineer María del Pilar Delgado Rodríguez Information Security Officer – CISO UCundinamarca
  • Engineer Guillermo Saad L. Personal Data Protection Officer SMART LOCKNET

Tip 5

Restricted Access and Circulation

RESOLUTION No. 091 OF 2023 “BY WHICH THE PERSONAL DATA PROTECTION GUIDELINES FOR THE DATA SUBJECTS OF THE UNIVERSITY OF CUNDINAMARCA ARE ESTABLISHED.”.

  • Data processing may only be carried out by persons authorized by the data subject. Personal data, except for public information, may not be disclosed on the internet or other mass media, unless access is restricted in accordance with regulations. The University of Cundinamarca shall have an obligation of means to guarantee this control.

Tip 6

Reminder regarding the delivery of Information Assets for Administrative Officials

All administrative officials are reminded that, upon notification of early contract termination or a department transfer, the handover of Information Assets must be completed within a maximum period of 15 calendar days. To learn about the steps and mandatory guidelines of this process in detail, it is necessary to consult the internal regulatory document. ESG-SSI-P19, entitled “Delivery and return of information assets”.

Tip 7

Guidelines on the Use and Mandatory Return of the Institutional Bank Token

The bank token is a personal and non-transferable information asset, therefore it must be kept securely guarded, avoid leaving the institution's premises, and under no circumstances be delegated or shared with third parties. Likewise, it is established that upon termination of the contractual relationship, it is mandatory to return this device as part of the institutional assets, warning that failure to make this delivery may lead to immediate reports to the entity's internal control instances.

Tip 8

Access Control and Office Key Management for Heads, Directors, and Coordinators

All area heads, directors, and coordinators are reminded that physical access to the offices must be strictly limited, allowing only the area leader and one duly appointed trusted person to possess the keys to the facilities. This security measure is in compliance with the international standard ISO 27001:2022 – Annex A, Control A.7.2, which mandatorily requires the protection of physical areas through appropriate entry controls to safeguard the institution's information and resources.

Tip 9

Mandatory Handover of Information Assets for Area Leaders

All area managers, directors, and coordinators are informed that, under the procedure ESG-SSI-P19, the delivery of information assets by all members of your work team is a strictly process Mandatory. This institutional guideline seeks to ensure the control and protection of resources at key moments of the employment relationship.

PRINCIPLES OF PERSONAL DATA PROTECTION

We promote the comprehensive protection of personal data through secure practices that ensure privacy, informed consent, and the ethical use of information.

The processing of personal data may only be carried out with the prior, express, and informed consent of the data subject. Personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal, statutory, or judicial mandate that relieves the requirement for consent.

The personal data processing activity carried out by the University of Cundinamarca or to which it has access shall be subject to a legitimate purpose in accordance with the Political Constitution of Colombia, which must be informed to the respective owner of the personal data. Regarding the collection of personal data, the University of Cundinamarca shall be limited to those data that are relevant and adequate for the purpose for which they were collected or required; the Vice-Rectorates, Secretariats, Directorates, Faculties, Units, Areas, Centers, etc., must inform the owner of the reason why the information is requested and the specific use that will be given to it.

Data processing is a regulated activity, which must be subject to the current and applicable legal provisions governing the matter.

The processing of personal data is subject to the limits derived from their nature, the provisions of the law, and the Constitution. Consequently, such processing may only be carried out by persons authorized by the data subject and/or by persons provided for by law. Personal data, except for public information, may not be available on the internet or other means of mass dissemination or communication, unless access is technically controllable to provide restricted knowledge only to data subjects or third parties authorized in accordance with the law. For these purposes, the obligation of the University of Cundinamarca shall be an obligation of means.

The information subject to processing by the University of Cundinamarca must be handled with the technical, human, and administrative measures necessary to provide security to the records, preventing their adulteration, loss, unauthorized or fraudulent consultation, use, or access.

The information subject to the processing of personal data must be truthful, complete, accurate, up to date, verifiable, and understandable. The processing of partial, incomplete, fractionated, or misleading data is prohibited.

Regulations

Check here the rules, policies, and regulations that govern the academic and administrative work of the University of Cundinamarca, ensuring clear, coherent, and high-quality processes.
Privacy Notice
See more
Resolution No. 144
Download
Resolution No. 091
Download
Resolution No. 092
Download

Tactical-operational team of the ISMS

Behind every institutional achievement is a passionate team that, with its knowledge and dedication, drives the growth and transformation of the University of Cundinamarca.
Pilar delgado

Maria del Pilar Delgado Rodriguez

ISMS Coordinator
Sgsi 22x

Eimy Daniela Melo Rodriguez

Information Security Front
Sgsi 2x

Brenda Camila Mesa Rozo

Personal Data Protection Front
Sgsi copia 22x

Brayan Alexis Galindo Ramirez

Information Security Front
Sgsi copia 22x 8

Carolina Berrio Osorio

Personal Data Protection Front
Sgsi copia2x

Duvan Felipe Castillo Ávila

Cybersecurity Front
Sgsi 12x

Danilo Esteban Silva Rey

Cybersecurity Front
Sgsi 72x

Valery Cruz Rodríguez

Information Security Front
Sgsi 32x

Brian Steven Cubillos Cubillos

Information Security Front
Sgsi 62x

Nicole Alejandra Timaran Beltrán

Cybersecurity Front
Sgsi 52x

Michael Andrés Duarte Rincón

Cybersecurity Front

Frequently Asked Questions

Check here the frequently asked questions about undergraduate admissions, enrollments, and academic processes.

The authorized institutional email for communication by data subjects of the University of Cundinamarca in case of updating, consultation, or deletion of personal data is [email protected].


The event compromises security, but does not necessarily represent an impact or damage; it is a warning sign. The incident is indeed a negative impact on Information Security.


The format for the Authorization for the processing of personal data of adult data subjects of the University of Cundinamarca is ESG-SSI-F001.

Information assets are the resources that have value for the institution and need to be protected in order to prevent the materialization of an information security and/or privacy risk.

These are:

  • InformationConfidential data, databases, minutes, etc.
  • SoftwareLicensed applications.
  • Services: Institutional Platform, Microsoft 365, Institutional Email.
  • Hardware and devicesComputer equipment, hard drives, printers, etc.
  • Human Resources: Administrative staff, knowledge managers, etc.
  • InfrastructureAreas or Offices of the institution. 

The Resolution 092 of 2023 “BY WHICH THE INFORMATION SECURITY MANAGEMENT SYSTEM – ISMS IS ADOPTED AND GUIDELINES, OBJECTIVES, AND SCOPE ARE ESTABLISHED AT THE UNIVERSITY OF CUNDINAMARCA“ and the Resolution “091 of 2023 BY WHICH THE GUIDELINES FOR THE PROTECTION OF PERSONAL DATA OF THE DATA SUBJECTS OF THE UNIVERSITY OF CUNDINAMARCA ARE ESTABLISHED“.

An event and/or incident must be reported to the Information Security Management System – ISMS email, as we are part of the Information Security and Privacy Incident Response Team, and it is recommended not to manipulate the content of the email identified as suspicious or of unknown origin.

It is any information linked to or that can be associated with one or more specific or determinable natural persons. By their nature, data can be public, semi-private, private, or sensitive.

  • Law 1581 of 2012 “By means of which OneDrive inactive synchronization
  • Phishing or Social Engineering 
  • Sending sensitive information without encryption
  • Damage to the infrastructure of the area and/or process dictate general provisions for the protection of personal data.

Law 1581 of 2012 “By which general provisions for the protection of personal data are issued.”.

Contact

SGSI

SGSI

SGSI

SGSI