IMST 07: Working Abroad Information Security Standard
Information Classification - Public
1. Introduction and Purpose
1.1 This Working Abroad Information Security Standard forms part of the University’s Information Management Policy FrameworkLink opens in a new window and its parent policy is IMP 05: Working Abroad Information Security PolicyLink opens in a new window and provides additional detail in support of IMP 05.
2. Scope and Definitions
2.1 The Standard covers everyone who has a contractual (formal or informal/implied) relationship with the University, including employees, students, temporary workers (including those conducting short term academic work) and consultants. Please note that this list is not exhaustive.   For the purposes of this Standard, we refer to everyone as members. It covers all instances of working for or on behalf of the University outside of fixed work locations on university premises.
3. Responsibilities (Policy and Operational) 
3.1 The Chief Information Security Officer (CISO) retains overall accountability for this Standard and for ensuring the Standard meets legal and regulatory requirements; for keeping this Standard up to date; and for ensuring that controls, checks, and audits are carried out as part of compliance with this Standard.
3.2 Adherence to this Standard is achieved by following the standard's principles and provisions. It is everyone’s responsibility to ensure that they follow this Standard.
| Role |
¹ó³Ü²Ô³¦³Ù¾±´Ç²Ô  |
| Designate of Head of Department (e.g. academic lead on research, individuals with delegated authority for information, system administrators)  |
Responsible – for overseeing compliance with the Standard within areas of responsibility  |
| Head of Department (or equivalent) |
Accountable – for compliance with this Standard within Departments  |
| Information Risk and Compliance Team (with escalation to CISO)  |
Consult – to discuss organisational level compliance with the Standard |
| IDG Digital Business Partners  |
Inform – must be informed of the content of the Standard to communicate it to their departments  |
4. Principles of the Standard
4.1 This Standard should be read in conjunction with and is aligned to the IMP 05: Working Abroad Information Security PolicyLink opens in a new window, the IMST 04: Secure Remote Working StandardLink opens in a new window, and the Travel HubLink opens in a new window. Travellers should also check the for the latest advice.
5. Practices for Devices
- Be careful when charging your device: beware of free charging kiosks - they could be connected to devices which intercept your username and password when you plug in.
- Devices must be kept on your person or locked in a secure location: consider the risks of leaving your device behind, e.g. in a hotel room or conference venue. If you must do this, ensure the device is locked in an official secure place or safe.
- Loss of devices must be reported immediately: contact your ¹û¶³´«Ã½ Helpdesk as soon as possible - the ServiceDesk (or WMG IT Support/WBS eSolutions where appropriate).
- Do not connect to unsecure networks: in addition to internet cafes, be aware that hotel and conference centre networks, or a friend's network, may be insecure.
- Do not connect to unfamiliar devices: do not allow storage devices to connect to your device as per IMST 03: Handling Information StandardLink opens in a new window clauses concerning removable media, including USB sticks as they may be infected without their owner's knowledge.
6.0 Crossing Borders
6.0.1 Some countries may ask to examine your devices during customs checks. It is important the device is charged before hand so it can be switched on if requested. If you are asked to login to the device, it is recommended that you take the following actions before doing so in an effort to satisfy the authorities at your destination without compromising the device. If you do not feel safe in taking these steps, or authorities are insistent on you logging in despite attempting the below actions, you must comply with their request to ensure your safety and report your device as compromised to the University as soon as you are able:
- Remain calm and polite at all times.
- Try to establish your official status (as a representative of a UK public body) and good faith from the outset.
- Present documentation from the overseas organisation or individual you are visiting that shows the purpose of your visit and invite the official(s) to contact them to confirm you are who you claim to be.
- Carry the name and telephone number of your line manager and invite the official(s) to contact them to confirm that you are who you claim to be.
- If the official still insists that you login, state that you are carrying university property that is sensitive and you would prefer not to allow access. Ask to see a senior officer or supervisor. You may want to take the names and/or contact details of any officials involved in the event. Consider taking an explanatory letter on ¹û¶³´«Ã½ headed paper – see example in Appendix below.
- If you are compelled to login or the device is removed from your sight, you should assume it has been compromised. Do not use the device to access university resources (for example, email or other business applications) and report the incident to the ServiceDesk as soon as it is safe to do so.
6.0.2 The University recognises the high stress that you may experience if you are ordered to do things at customs control and understands that you may not be able to record or recall the circumstances. Cope as well as you can, report back what you are able to, and when it is safe for you to do so.
6.1 Traveling to the United States of America (USA)
6.1.1 Check what the latest entry requirements are and for the latest advice on the Travel HubLink opens in a new window and in GuidanceLink opens in a new window. Note that whereas declaring your social media accounts was optional in the past, this may now be a requirement and extended to cover e-mail accounts and phone numbers used in the last 10 years and details relating to your family members.
6.2 Use of Encrypted Devices Abroad
6.2.1 To protect University and your own data you should always use encrypted devices. University managed Windows, Apple and Linux machines are encrypted. However, there are potential legal ramifications when entering other countries which may depend on many factors including who you are and what you are entering the country for. Some countries do not allow encryption for personal use at all. Many countries, including the UK, allow encryption for personal use but have laws/regulations that require you to give access to the data on request at borders or by law enforcement. To protect yourself you may need to comply with such regulations.
6.2.2 Many countries are party to the on export controls for conventional arms and dual-use goods and technologies. Encryption is one of these technologies but since encryption is used legitimately to protect data on many portable electronic devices an agreement has been reached between the signatories to allow individuals to travel with encrypted devices without the need to seek any licence or permission. These Permitted Countries grant individuals a personal use exemption to freely enter the country with encrypted devices using commercially available encryption software such as Sophos Safeguard, BitLocker (Microsoft devices), FileVault (Apple devices) and LUKS (Linux), as long as the individual does not create, enhance, share, sell or otherwise distribute the encryption software during his/her stay in the relevant Permitted Country.
6.2.3 The countries that support the personal use exemption (as of September 2026) are:
| Argentina |
Australia |
Austria |
Belgium |
Bulgaria |
| Canada |
Croatia |
Czech Republic |
Denmark |
Estonia |
| Finland |
France |
Germany |
Greece |
Hungary |
| India |
Ireland |
Italy |
Japan |
Latvia |
| Lithuania |
Luxembourg |
Malta |
Mexico |
Netherlands |
| New Zealand |
Norway |
Poland |
Portugal |
Romania |
| Slovakia |
Slovenia |
South Africa |
South Korea |
Spain |
| Sweden |
Switzerland |
°Õü°ù°ì¾±²â±ð |
United Kingdom |
United States |
6.2.4 Although you do not need a licence to take an encrypted device into the Permitted Countries you may still be asked to divulge the contents of your device, by logging in (which may put your username and password at risk) or unencrypting it. You must assess the risks and consequences of this happening before departure.
6.2.5 Note that although the Russian Federation and Ukraine agreed to many of the Wassenaar Arrangement's provisions, they currently do not permit personal use exemptions.
6.2.6 China. Even though China is not a signatory to the Wassenaar Arrangement it is unlikely that you will encounter any problem if taking a commercially encrypted device into the country, such as a ¹û¶³´«Ã½ managed machine or personal iPhone. However, as with the Wassenaar countries, you could still be asked by the authorities to provide access to your device.
6.2.7 For countries not mentioned above refer to and check with their embassy for any restrictions on travelling with encrypted devices.
6.3 VPNs and use of mobile data abroad
6.3.1 The ¹û¶³´«Ã½ VPN is the only VPN that can be used. Note that some countries use Firewalls to prevent the use of VPNs. Some countries only allow the use of officially sanctioned VPNs and these should be considered insecure and not suitable for accessing university data. Check with Forbes: and refer to the relevant embassy if uncertain.
6.3.2 Where there is no Wi-Fi available or the Wi-Fi connection is untrusted, consider using a ¹û¶³´«Ã½ mobile phone as a hotspot and use that to connect your laptop to the internet.
6.4 Checks before Returning to the UK
6.4.1 Delete anything that may have been inadvertently downloaded that is classified as Confidential or Highly ConfidentialLink opens in a new window. On managed devices the default download locations are:
- Windows device – C:\Users\<YourUserCode>\Downloads
- Managed Mac device - Macintosh HD → Users → YourUserCode → Downloads
6.4.2 Note that browsers can have different download locations defined to those above.
6.5 Personal Devices on Work Trips
6.5.1 The use of personal devices to access university data is restricted. Personal devices are not suitable for storing anything with a classification above Public and accessing university systems may be blocked for Information Security reasons.
6.5.2 See also Use of personal devices abroad - guidance.Link opens in a new window
6.6 University Devices on non-Work Trips
6.6.1 If university devices are to be taken for travel not directly related to a work function (e.g. annual leave, temporary long-distance remote working, TOIL etc.) line manager approval must be sought in advance and note that IMST 04: Secure Remote Working StandardLink opens in a new window always applies.
6.6.2 Members are expected to handle university devices responsibly when off campus, following all IT security requirements such as encryption, strong passwords, and physical device security. Members also remain accountable for any data accessed remotely, including meeting all relevant data protection obligations under UK GDPR, and remain subject to UK export controlsLink opens in a new window.
6.6.3 University laptops, tablets, mobile phones or other electronic devices must not be taken to the following countries:
- Iran
- Russia
- North Korea
6.6.4 In addition, the use of software can be prohibited or severely restrict in specific countries due to licensing terms and/or US, EU, and UK export controls and sanctions. The restrictions include device operating systems such as Windows, Apple and Linux as well as applications installed. As of May 2026, restrictions applied to Cuba, Sudan and Syria, but check for the latest position before travelling.
6.7 Exceptions
6.7.1  under this standard must be submitted to the CISO or their designate. Authority to approve exception requests is delegated to the Information Risk and Compliance Team. Activities that have received prior approval by the Research Governance and Ethics Committee will be exempt, but the CISO must be notified.
6.7.2 This standard may have an impact on users of assistive technology or assistive software dependent on circumstances. These individual cases will be considered on a case-by-case basis.
7. Compliance Monitoring 
7.1 All members of the University are expected to comply with this document as part of the Information Management Policy Framework (IMPF)Link opens in a new window. Where breaches of the IMPF present a significant risk, including those falling under Regulations  and Regulation , they will be subject to the appropriate student or staff disciplinary procedure or applicable contractual terms for staff not employed directly by the University or contractors.
7.2 It is the responsibility of all members to report any instances of non-compliance to the Information Risk and Compliance Team. This can be done via the . This team monitors adherence to the IMPF using reported data and other available tools.
7.3 Where issues require escalation or further review, they will be referred to the Information Security and Data Protection Committee via the Chief Information Security Officer (CISO) and include either Conduct and Resolution Team or Employee Relations Team, as appropriate.
Appendix
Example letter that could be presented to border officials. You can copy the letter below, amend were necessary, and print on appropriate ¹û¶³´«Ã½ headed paper.
To whom it may concern,
I, {insert name and position} of the ¹û¶³´«Ã½ ("University"), confirm that the bearer of this letter, {insert name of traveller}, {position}, is travelling with a device which has been encrypted with standard freely available commercial encryption software by the University as it contains confidential personal or commercial information relating to the University.
Yours sincerely
{insert name here}
Head of Department
¹û¶³´«Ã½
Amendment History:    
| Version | Date created | Date Published | Next Review | Notes/outcomes |
| 1.0 | 02/09/2026 | 18/09/2026 | September 2027 |