Search
Policy Areas

Recently updated

Filter and Sort

Recently updated

The following policies have been updated to reflect UNDP’s transition to its new cloud-based management platform Quantum in January 2023, replacing its previous ATLAS system. ICT Disaster Recovery Standards for UNDP Offices and the related ICT Disaster Recovery Plan templateElectronic Funds Transfer StandardsElectronic Signatures and the related List of systems and tools for electronic systems and approvalsQuantum User Access Standards

The policy was changed in order to implement industry best practices in cybersecurity for the protection of personally identifiable information. These changes are compliant with ISO 27701 and help implement the requirements of tithe UNDP privacy policy for the protection of personal data.- The new version of the UNDP Information Security Policy takes into account the provisions of the new UNDP Data Protection and Privacy policy as well as the recommended industry best practices for managing personally identifiable information (PII) as defined in ISO 27701.- The new version designates the UNDP ...

The policy was changed in order to implement industry best practices in cybersecurity for the protection of personally identifiable information. These changes are compliant with ISO 27701 and help implement the requirements of tithe UNDP privacy policy for the protection of personal data.
- The new version of the UNDP Information Security Policy takes into account the provisions of the new UNDP Data Protection and Privacy policy as well as the recommended industry best practices for managing personally identifiable information (PII) as defined in ISO 27701.
- The new version designates the UNDP Chief Information Security Officer role as the party responsible for governance and monitoring of privacy safeguards within the BMS/ITM. It also explicitly designates BMS/ITM as a custodian (aka PII Processor) and not the owner of the PII data.
- The new policy section on PII also contains policy statements compliant with the ISO 27701 privacy standard for industry best practices.


​The purpose of the Information Classification and Handling policy is to guide project/programme implementation when handling data, to be embedded throughout the data lifecycle to ensure UNDP implements the highest ethical standards for data protection and privacy. Protection of personal data is essential to upholding fundamental rights to privacy and the UN system-wide personal data protection and privacy principles. Strong policies on information handling and classification and on personal data protection and privacy are critical for operating efficiently, considering opportunities and risks ...

​The purpose of the Information Classification and Handling policy is to guide project/programme implementation when handling data, to be embedded throughout the data lifecycle to ensure UNDP implements the highest ethical standards for data protection and privacy. Protection of personal data is essential to upholding fundamental rights to privacy and the UN system-wide personal data protection and privacy principles. Strong policies on information handling and classification and on personal data protection and privacy are critical for operating efficiently, considering opportunities and risks in the use of personal data, including in combination with evolving technologies.

​The purpose of the Personal Data Protection and Privacy policy is to guide project/programme implementation when handling data, to be embedded throughout the data lifecycle to ensure UNDP implements the highest ethical standards for data protection and privacy. Protection of personal data is essential to upholding fundamental rights to privacy and the UN system-wide personal data protection and privacy principles. Strong policies on personal data protection and privacy, and on information handling and classification are critical for operating efficiently, considering opportunities and risks i ...

​The purpose of the Personal Data Protection and Privacy policy is to guide project/programme implementation when handling data, to be embedded throughout the data lifecycle to ensure UNDP implements the highest ethical standards for data protection and privacy. Protection of personal data is essential to upholding fundamental rights to privacy and the UN system-wide personal data protection and privacy principles. Strong policies on personal data protection and privacy, and on information handling and classification are critical for operating efficiently, considering opportunities and risks in the use of personal data, including in combination with evolving technologies.

​Paragraphs 10, 45, 46, 60 and 55 of the policy have been updated in response to UNBOA audit recommendations to clarify the responsibilities of offices in creating their disaster recovery plans, including documenting any arrangements made with cloud providers.

​The main Bring Your own Devices and Acceptable Usage of ICT Resources policy changes are as follows:

  • Making undp.org email mandatory to all UNDP personnel;
  • Prohibiting access to malicious hacking/cybercriminal websites and websites which contravene UN values;
  • A clearer naming convention for emails addresses;
  • Introduction of a new state of the art password policy, using sentences, and safe logon procedures.

These changes will also close a 2020 UNBOA recommendation.

A straightforward change in paragraph 98 has been made to maintain coherence. The Director, OIMT will make a statement of compliance. Streamlined content with ISO standards. Procedures have been created under 3.0 for step-by-step guidance for user access management.

​TheCO and RO ICT Security Guidelines have been launched in first quarter of 2009. They provide security guidelines for UNDP Country and Regional Offices. ICT managers, in cooperation with administrative officers, RIOs or RRs and other appropriate personnel, must conduct an annual review of user and system operation practices to evaluate compliance against existing BOM OIST security protocols and procedures. These security best practices and protocols may also assist regionally-based personnel (for example, RIM, Regional Director, etc.) and OAI/LSO personnel when visiting Country Offices.
​UNDP promotes the use of Information and Communication Technology (ICT) to share information and knowledge in support of UNDP’s mandate and to conduct UNDP’s business activities. The ICT Usage Policy  launched in first quarter of 2009 establishes the framework for the overall policy and the standards for UNDP regarding the use of ICT resources and data