Last updated: July 16, 2026

Shared Goal

Protecting UBC information and systems is critical to fulfilling UBC’s vision, purpose, and values. The Compliance Support Program (CSP) team partners across the university to support units in identifying and meeting their information security responsibilities. Together, we work to reduce the risk of privacy and information security incidents across the university community. 

Available Support

CSP provides structured engagement, practical guidance, and ongoing support to help units recognize and revisit areas of improvement within their IT environment and strengthen their overall security posture. 

 
Compliance Self Assessment

Now complete, phase one of the Compliance Support Program involved engaging with units across UBC to provide support in self-assessing compliance to UBC's Information Security Standards.

 
Update and Check-In

Building on the progress made in phase one, CSP is now re-engaging with select units to support and check-in on their remediation progress.

 
Research IT Environment Compliance Self Assessment

CSP is expanding in scope to include UBC's distributed Research IT Environments.
 

What's Next?

CSP is designed to evolve alongside the University, with planning for future ongoing activities underway.

Coming Soon

 

 

Indian Residential School History and Dialogue Centre

Program Overview

As UBC Electronic Systems and services continue to evolve across UBC's diverse academic and administrative environments, the need for a more coordinated, standardized, and sustainable approach to information security grows increasingly important. To address this, the Compliance Support Program (CSP) supports units in understanding institutional security requirements, strengthening local security practices, and fostering a shared culture of accountability and continuous improvement across the university. 

Originally launched as a program, CSP has since evolved into an ongoing operational function that provides guidance to academic (including research) and administrative units in understanding and meeting the UBC Information Security Standards. CSP currently focuses on communicating essential controls, clarifying accountability for securing UBC Electronic Systems, and helping units recognize where improvements may be needed within their IT environment. 

UBC Staff

Through structured engagements and guidance, units are better equipped to understand their current state and develop plans and processes to strengthen their security posture over time. The approach emphasizes collaboration, working closely with Administrative Heads of Unit, IT Representatives, and other key stakeholders to support continuous improvement. The goal is not only to assess compliance with the UBC Information Security Standards, but also to enable informed decision making and strengthen how UBC Electronic Information and Systems are protected across the university. 

Compliance Support Outcomes

The following outcomes reflect the intended impact of Compliance Support across units on:

 
Understanding

Improved consistency in how information security requirements are understood and implemented across UBC.

 

 
Decision Making

Better informed decision making at both the unit and at institutional level through clearer understanding of the current state of information security posture. 

 

 
 Risk Management

Strengthened overall ability to manage information security risk in various IT environments across the university.    

 

Accountability

Accountability for securing UBC information and systems lies with Administrative Heads of Units (AHoU). Administrative Heads of units are responsible for establishing and maintaining UBC Electronic Information and Systems within their areas of accountability. 

UBC Staff and Students

In the event of an information security breach, the extent to which a unit can demonstrate compliance with the UBC Information Systems Policy (specifically essential controls) will impact the following decisions:  

  1. Cost allocation associated with incident response and recovery  
  2. The necessity to conduct a full audit of information security controls within the unit  
  3. Performance assessments for individuals who have failed to carry out their responsibilities under the UBC Information Systems Policy, including any appropriate performance management or disciplinary measures. 

If you are an Administrative Head of Unit, you are required to complete the Information Security Administrative Heads of Unit (AHoU) and Leadership training to better understand your responsibilities and obligations. 

UBC Campus in Summer

Go Further...


UBC Crest The official logo of the University of British Columbia. Urgent Message An exclamation mark in a speech bubble. Caret An arrowhead indicating direction. Arrow An arrow indicating direction. Arrow in Circle An arrow indicating direction. Arrow in Circle An arrow indicating direction. Chats Two speech clouds. Facebook The logo for the Facebook social media service. Information The letter 'i' in a circle. Instagram The logo for the Instagram social media service. Linkedin The logo for the LinkedIn social media service. Location Pin A map location pin. Mail An envelope. Menu Three horizontal lines indicating a menu. Minus A minus sign. Telephone An antique telephone. Plus A plus symbol indicating more or the ability to add. Search A magnifying glass. Twitter The logo for the Twitter social media service. Youtube The logo for the YouTube video sharing service. Bell Warning