Header

Search

Information Security Guidelines

The CISO has created various guidelines that provide a framework for implementing various measures and projects.

(Parts of this page were translated using AI - including this sentence.)

New: Guidelines for the Use of AI Systems (AI Guidelines)

AI systems must be used appropriately and responsibly at all times in day-to-day work to mitigate associated risks and comply with applicable laws and UZH regulations. These AI Guidelines are intended to provide guidance in this regard.
Guidelines for the Use of AI Systems

The AI Guide in a Nutshell

Key Principles:

  • Accountability: Humans always remain in charge. AI never makes decisions on its own. It’s not just about “humans in the decision-making process,” but “humans at the helm.”
  • Transparency: Label AI-generated content. Avoid misunderstandings about what is AI-generated and what is human-made.
  • Ethics and fairness: Declare AI support in decision-making. Disclose to all affected parties that AI was involved in the decision-making process.
  • Skepticism: Question and verify AI output. AI distorts (bias) and invents (hallucinations). Never accept output without a plausibility check! Always verify the information provided and its sources!

Legal requirements apply:

  • AI use does not take place in a legal vacuum; in particular, data protection, copyright, and contract law must be observed. (Topics: purpose limitation, profiling, erasure)
  • Own AI agents: Agents available in approved tools can be used responsibly by users with sufficient application expertise.
  • AI should be used correctly, lawfully, and securely.
  • Free versions of AI systems may not be used with copyrighted works and may only be used for public information.

Questions and answers on practical topics related to the use of AI at UZH can be found in the recording of the lunch event “What Can I Do with AI at UZH?” featuring Prof. Markus Christen. (German only)
Go directly to the section in the video on copyright-protected applications using AI
The full recording of the lunch event.

How do I choose the right tool?

  • Step 1: Determine the confidentiality level of the information to be used with the AI, in accordance with the guidelines for classifying information.
  • Step 2: Select an AI system from the list of Centralized IT (or in consultation with your own IT department) that is approved for this confidentiality level.
  • Step 3: Read and follow the relevant information sheet, and adhere to the AI guidelines.

Grid containing content elements

Guidelines for the usage of AI-Systems

More about Guidelines for the usage of AI-Systems

AI systems must be used appropriately and responsibly at all times in day-to-day work to minimize associated risks and comply with applicable laws and UZH regulations. The AI guidelines are intended to provide support in this regard. (AI translated version)

Guidelines on Phishing Campaigns at UZH

More about Guidelines on Phishing Campaigns at UZH

The phishing campaign guidelines specify the preparatory work required for a fake phishing campaign.

Such campaigna are often used for measurement purposes. However, generating awareness requires a lot of preparatory work.

A lot can go wrong with campaigns like this. The guide aims to help prevent mistakes from the outset.

german only

Awareness Guidelines UZH

More about Awareness Guidelines UZH

The Awareness Guidelines sets out the principles for creating measures and implementation concepts with regard to awareness.

german only