(Appendix 5 to Order No. A/150 of the Minister of Justice and Internal Affairs, dated June 21, 2021) By establishing an integrated management system, we will continuously develop the knowledge and skills of our staff and students, uphold quality in all our operations, and maintain a high level of satisfaction among our beneficiaries.
(Appendix 1 to Order No. A/459 of the University Director, dated December 8, 2023, "On the Approval of Policy and Scope") In compliance with the legislation of Mongolia and the needs and expectations of interested parties, we will create healthy and safe working and learning conditions in all university activities. With the active participation of every officer, staff member, cadet, and student, we will identify and eliminate hazards, reduce risks, and work towards the continuous improvement of the occupational health and safety management system.
(Order No. A/585 of the University Director, dated November 28, 2025, "On the Approval of Policy and Scope") The University of Internal Affairs pays special attention to ensuring information security in its operations, establishing a permanent monitoring system, and adhering to the following core directions to prevent potential risks, protect against attacks, and ensure continuous improvement. Based on these core directions, the university sets measurable information security goals and objectives, regularly evaluates implementation performance, and executes improvement measures. This policy applies to all university officers, teachers, staff, cadets, and students; it is introduced organization-wide and updated at set intervals. Key directions include:
Compliance: Develop, approve, and follow internal policies, procedures, and instructions in daily operations that align with effective Mongolian laws, regulations, and international and national standards. Contractual and interested party requirements related to information security shall also be fulfilled.
Risk Management: Regularly assess information security risks affecting university operations using established methodologies. Perform additional assessments when introducing new systems or making major changes, plan and implement appropriate responses to identified risks, and manage risks at an acceptable level. Control measures will be continuously improved based on risk assessment and analysis.
Human Resources: Organize activities to provide necessary information, regular job-specific training and drills, and awareness programs on the consequences of information security risks to develop the knowledge and skills of human resources. Requirements for information security competency will be defined for each position, and efforts will be made to bridge any gaps.
Incident Management: In the event of information security breaches or suspicious activities, promptly record, report, investigate, and take appropriate response measures in accordance with relevant procedures to prevent recurrence. Analyze detected breaches and non-conformities, take corrective and preventive actions, and enhance the security level by eliminating system weaknesses.
Threat Intelligence: Regularly receive and analyze information regarding security threats from professional organizations and implement preventive measures. Use this information to update and improve risk assessments and security controls.
Business Continuity: Develop, implement, test, and improve plans to prevent cyberattacks and threats, overcome incidents with minimal damage, and ensure the continuity of university operations. Ensure conditions and capabilities are met to recover critical services within set recovery time objectives following cyberattacks or serious system failures.