Secure Requirement Submission

Size: px
Start display at page:

Download "Secure Requirement Submission"

Transcription

1 Title Secure Requirement Submission Document ID ISB 1596 Amd 34/2012 Director Mark Reynolds Status Final Owner Jon Calpin Version 1.1 Author Mark Reynolds Version Date 03/12/2012 Secure Requirement Submission Open Government Licence 2012

2 Amendment History: Version Date Amendment History /11/2012 Initial Release /12/2012 Incorporated comments from appraisers. Approvals: Name Title / Responsibility Date Version Chris Wilber Technical Director 09/11/2012 V1.0 James Wood NHS CFH Head of Information Security 25/10/2012 V0.1 Related Documents: These documents will provide additional information. Ref no Doc Reference Number Title Version 1 NHSmail 2 Privacy Impact Assessment NHSmail 2 Communications and Stakeholder Engagement Strategy 1.1 Glossary of Terms: Term Acronym Definition Risk Potential Assessment Information Commissioners Office RPA ICO CESG CESG protects the vital interests of the UK by providing policy and assistance on the security of communications and electronic data, working in partnership with industry and academia. It is the UK Government's National Technical Authority for Information Assurance (IA). Open Government Licence 2012 Page 2 of 11

3 Contents 1 Summary Introduction Purpose Mandate Customer Need Requirements Scope Requirements Related Standards Supporting Information Value for Money Proposition Evidence of Consultation Implementation Strategy Maintenance Strategy Risks and Issues Products Provided Not Provided Open Government Licence 2012 Page 3 of 11

4 1 Summary Standard Standard Number ISB 1596 Title Type Description Secure Operational This standard defines the minimum non-functional requirements for a secure service, covering the storage and transmission of . This is the basic level for the storage and transmission of patient identifiable data by an system. It excludes security standards for document archives. Applies to Health, public health and social care organisations. service providers. Release Release Number Amd 34/2012 Title Initial Standard Description Implementation Completion Date 30 th June 2016 Open Government Licence 2012 Page 4 of 11

5 2 Introduction 2.1 Purpose This standard will establish the minimum requirements for systems in health and care. The intention is not to impose significant requirements on organisations but instead to establish the minimum acceptable level. An appropriate set of controls / requirements will be created in collaboration with the suppliers, implementers and customers, rather than being dictatorially specified and mandated from the centre. Where possible they will refer to Government and international standards (e.g. ISO 27001). The current and future NHSmail services will either meet or exceed these requirements. They will offer a way of conforming to the standard. 2.2 Mandate The information standard has sponsorship from: Role Name Job Title SRO Dr Simon Eccles Medical Director, DH Informatics Directorate Business Sponsor Bill McAvoy Transition Director, Patients and Intelligence NHS Commissioning Board Technical Sponsor Alex Abbott NHS CB Chief Technology Officer The project brief for the NHSmail 2 project which includes the development of the information standard has been approved by the Informatics Directorate Portfolio Board and a portfolio number has been assigned. 2.3 Customer Need Health and care is now a rich source of patient/service user information. There is a clear need to ensure that it is held securely and used appropriately. The Power of Information paragraph 3.51 specifies (our bold text): All communication about our care must be appropriately secure and protected. Work will continue to improve access to and use of NHSmail within the NHS, and social enterprises and other qualified providers of care services, as part of their commissioning contracts with the NHS, will be given access to a limited number of NHSmail accounts. Similar incentives for social care will be made available that make the process and cost of connecting social care providers, local authorities and other care providers via secure electronic communication easier, cheaper and less bureaucratic. The standard will ensure that health, public health and adult social care organisations have a recognisable baseline which they can conform to. Open Government Licence 2012 Page 5 of 11

6 3 Requirements 3.1 Scope The standard will define how systems used for sensitive data (e.g. patient identifiable data) should manage: The information security of the service. Transfer of sensitive information over non-secure channels. Accessing information from the Internet or mobile devices. Exchange of information outside the controlled boundary of the secure system: o to other systems compliant with this standard. o to other systems not compliant with this standard. Care will be taken to ensure that the requirements are tied to specific legal and policy requirements to stop the standard becoming a wish list. 3.2 Requirements ISB 0086 Information Governance Toolkit has a series of requirements that all health and care organisations must meet, with the information security requirements being particularly applicable. The standard will specify how health and care systems MUST, SHOULD and MAY conform to these requirements. Of particular note are: Num Description The Information Governance agenda is supported by adequate information security skills, knowledge and experience which meet the organisation s assessed needs Operating and application information systems (under the organisation s control) support appropriate access control functionality and documented and managed access rights are in place for all users of these systems All transfers of hardcopy and digital person identifiable and sensitive information have been identified, mapped and risk assessed; technical and organisational measures adequately secure these transfers Policy and procedures are in place to ensure that Information Communication Technology (ICT) networks operate securely Policy and procedures ensure that mobile computing and teleworking are secure All information assets that hold, or are, personal data are protected by appropriate organisational and technical measures The standard will give specifics to each of these requirements for systems Related Standards Reference Title Open Government Licence 2012 Page 6 of 11

7 ISB 0086 ISO/IEC BS ISO/IEC 27002: 2005 Information Governance Toolkit Information Security Management Systems IT. Security Techniques. Code of practice for information security management HMG Impact Assessment Standards CIO Council Offshoring Position Open Government Licence 2012 Page 7 of 11

8 4 Supporting Information 4.1 Value for Money Proposition This standard is predicated on defining the minimum requirements that any system must comply with to meet policy and legislation for the security of patient identifiable data. It s therefore a necessary cost. The standard offers value for money by ensuring that services are not over-engineered due to a lack of clarity on how to meet the Information Governance requirements. Implementation of the standard avoids costs of not complying, for example Information Commissioner Office (ICO) fines. The development and issuance of the standard is part of the wider NHSmail 2 investment. The Strategic Outline Case for the investment is expected to have DH Information Directorate approval by the end of November. 4.2 Evidence of Consultation The requirements of the Information Governance Toolkit are already well known and the underlying standards and good practice guides in wide use. The standard itself will be published at draft stage for consultation. 4.3 Implementation Strategy At the full stage an assessment will be made of which health and care organisations already meet the standard. This will inform the implementation approach. Once approved, the standard will be communicated to health and care organisations through the normal information standards routes. Health and care organisations will need to ensure that when they renew their service that they comply with this standard. They can do this by specifying the requirements to their supplier or by moving to NHSmail or NHSmail 2. They can also do this by selecting a supplier from other procurement vehicles such as the G-Cloud catalogue that meets or exceeds the standard. Health and care organisations and their IT suppliers shall self-certify to this information standard. This shall normally be through the production of an internal assessment, which then provides evidence to support the wider IG Toolkit submission. Where an international or national standard is referenced (e.g. ISO 27001) the information standard will identify the assurance regime for it. Support shall be offered by the NHSmail 2 project and Technology Office information security team through well-established channels. 4.4 Maintenance Strategy The standard will be maintained by the NHSmail operations team who will by approval reside within the Health and Social Care Information Centre. The standard will be reviewed in accordance with the normal information standards review cycle Open Government Licence 2012 Page 8 of 11

9 and updated if the underlying policy and legislative drivers for securing information, the ISO standards or best practice in securing systems changes. Open Government Licence 2012 Page 9 of 11

10 4.5 Risks and Issues # Risk Mitigation 41 Business Impact Levels The Government using (Business) Impact Levels for its security but these are not well understood by the NHS. NHS requirements seem to fall between IL2 and IL3 but with no clear standard. This needs to be resolved. 12 Offshoring Policy Offshoring policy used to mandate that data could only be secured within England. The policy was recently changed but not communicated widely. 6 IL3 Requirement As a result of the requirement for an IL3 platform (high IG security levels), there is a risk that the number of companies able to tender for the contract is restricted, leading to the requirements not being met in a cost effective manner. 45 Changes to ISB Changes to the ISB process as a result of informatics transition result in delays to the information standard or rework. (Numbering is taken from NHSmail 2 project risk log) This standard will define the security controls for health and care, eliminating this risk. Refer to and clarify offshoring policy in standard. IL assessment being done by the NHSmail project. Monitor together with ISB. The standard is not on the project critical path. Open Government Licence 2012 Page 10 of 11

11 5 Products 5.1 Provided Product Requirements Value for money proposition Title Privacy impact assessment NHSmail 2 Privacy Impact Assessment v1.1 Communication strategy NHSmail Communications and Stakeholder Engagement Strategy v1.0 Evidence of consultation Implementation strategy Maintenance strategy Glossary of Terms Issues log / Risk register 5.2 Not Provided Product Safety case Justification for Absence The safety case has been deferred until the Draft stage so that it can apply to the draft standard, not the requirements. Open Government Licence 2012 Page 11 of 11

Information Management Policy

Information Management Policy Title Information Management Policy Document ID Director Mark Reynolds Status FINAL Owner Neil McCrirrick Version 1.0 Author Deborah Raven Version Date 26 January 2011 Information Management Policy Crown

More information

Electronic Palliative Care Co-Ordination Systems: Information Governance Guidance

Electronic Palliative Care Co-Ordination Systems: Information Governance Guidance QIPP Digital Technology Electronic Palliative Care Co-Ordination Systems: Information Governance Guidance Author: Adam Hatherly Date: 26 th March 2013 Version: 1.1 Crown Copyright 2013 Page 1 of 19 Amendment

More information

Information governance strategy 2014-16

Information governance strategy 2014-16 Information Commissioner s Office Information governance strategy 2014-16 Page 1 of 16 Contents 1.0 Executive summary 2.0 Introduction 3.0 ICO s corporate plan 2014-17 4.0 Regulatory environment 5.0 Scope

More information

The Gateway Review Process

The Gateway Review Process The Gateway Review Process The Gateway Review Process examines programs and projects at key decision points. It aims to provide timely advice to the Senior Responsible Owner (SRO) as the person responsible

More information

Informatics: The future. An organisational summary

Informatics: The future. An organisational summary Informatics: The future An organisational summary DH INFORMATION READER BOX Policy HR/Workforce Management Planning/Performance Clinical Document Purpose Commissioner Development Provider Development Improvement

More information

Information Governance Plan

Information Governance Plan Information Governance Plan 2013 2015 1. Overview 1.1 Information is a vital asset, both in terms of the clinical management of individual patients and the efficient organisation of services and resources.

More information

Policy: D9 Data Quality Policy

Policy: D9 Data Quality Policy Policy: D9 Data Quality Policy Version: D9/02 Ratified by: Trust Management Team Date ratified: 16 th October 2013 Title of Author: Head of Knowledge Management Title of responsible Director Director of

More information

Offshore and Internet Connection Addendum to the. Data Sharing Agreement. Version 1.3

Offshore and Internet Connection Addendum to the. Data Sharing Agreement. Version 1.3 Offshore and Internet Connection Addendum to the Data Sharing Agreement Version 1.3 Document Control Owners IEP User Group Author Steve Jessop Document Preparation Date Version Author Comment 11/01/12

More information

A Question of Balance

A Question of Balance A Question of Balance Independent Assurance of Information Governance Returns Audit Requirement Sheets Contents Scope 4 How to use the audit requirement sheets 4 Evidence 5 Sources of assurance 5 What

More information

ediscovery G-Cloud V Service Definition Lot 4 SCS Contact us: Danielle Pratt Tel: 0207 444 4080 Email: G-Cloud@esynergy-solutions.co.

ediscovery G-Cloud V Service Definition Lot 4 SCS Contact us: Danielle Pratt Tel: 0207 444 4080 Email: G-Cloud@esynergy-solutions.co. ediscovery G-Cloud V Service Definition Lot 4 SCS Tender Validity Period: 120 days from 10/04/14 Contact us: Danielle Pratt Email: G-Cloud@esynergy-solutions.co.uk Contents About... 1 Specialist Cloud

More information

Digital Continuity in ICT Services Procurement and Contract Management

Digital Continuity in ICT Services Procurement and Contract Management Digital Continuity in ICT Services Procurement and Contract Management This guidance relates to: Stage 1: Plan for action Stage 2: Define your digital continuity requirements Stage 3: Assess and manage

More information

Information Governance Strategy :

Information Governance Strategy : Item 11 Strategy Strategy : Date Issued: Date To Be Reviewed: VOY xx Annually 1 Policy Title: Strategy Supersedes: All previous Strategies 18/12/13: Initial draft Description of Amendments 19/12/13: Update

More information

Network Rail Infrastructure Projects Joint Relationship Management Plan

Network Rail Infrastructure Projects Joint Relationship Management Plan Network Rail Infrastructure Projects Joint Relationship Management Plan Project Title Project Number [ ] [ ] Revision: Date: Description: Author [ ] Approved on behalf of Network Rail Approved on behalf

More information

Information Governance Support Pack

Information Governance Support Pack PCTI Solutions Document Version: 0,1 19 February 2013 Pioneer Court, Pioneer Way, Whitwood, Castleford, West Yorkshire, WF10 5QU T: 01977 66 44 96 F: 01977 66 44 99 E: info@pcti.co.uk W: www.pcti.co.uk

More information

NHS Business Partners miniguide. Introductory guidance for NHS-commissioned healthcare providers from the independent and third sectors

NHS Business Partners miniguide. Introductory guidance for NHS-commissioned healthcare providers from the independent and third sectors NHS Business Partners Introductory guidance for NHS-commissioned healthcare Introductory guidance for NHS-commissioned healthcare NHS Business Partners Contents Section Description Page 1 Introduction

More information

SCCI SUPPORTING. SCCI2036 Palliative Care Clinical Data Set. Implementation Strategy. Project: SCCI2036 Palliative Care Clinical Data Set

SCCI SUPPORTING. SCCI2036 Palliative Care Clinical Data Set. Implementation Strategy. Project: SCCI2036 Palliative Care Clinical Data Set Document filename: Project Manager SCCI2036 Implementation Strategy v0.3 Helen Bolton Project: SCCI2036 Palliative Care Clinical Data Set Owner Julia Verne Version 0.3 Author Malcolm Roxburgh Version issue

More information

Policy. VBA Enterprise Risk Management. Governance Unit

Policy. VBA Enterprise Risk Management. Governance Unit Policy VBA Enterprise Risk Management Governance Unit Keywords: Policy; risk; governance. ID: Version no: Status: VBAPOL-0074 2.0 Final Issue date: Date of effect: Next review date: 14/07/2015 14/07/2015

More information

Shropshire Community Health Service NHS Trust Policies, Procedures, Guidelines and Protocols

Shropshire Community Health Service NHS Trust Policies, Procedures, Guidelines and Protocols Shropshire Community Health Service NHS Trust Policies, Procedures, Guidelines and Protocols Title Trust Ref No 1340-29497 Local Ref (optional) Main points the document covers Who is the document aimed

More information

Corporate Policy and Strategy Committee

Corporate Policy and Strategy Committee Corporate Policy and Strategy Committee 10am, Tuesday, 30 September 2014 Information Governance Policies Item number Report number Executive/routine Wards All Executive summary Information is a key asset

More information

Request for feedback on the revised Code of Governance for NHS Foundation Trusts

Request for feedback on the revised Code of Governance for NHS Foundation Trusts Request for feedback on the revised Code of Governance for NHS Foundation Trusts Introduction 8 November 2013 One of Monitor s key objectives is to make sure that public providers are well led. To this

More information

Security Overview. A guide to data security at AIMES Data Centres. www.aimesgridservices.com TEL: 0151 905 9700 enquiries@aimes.

Security Overview. A guide to data security at AIMES Data Centres. www.aimesgridservices.com TEL: 0151 905 9700 enquiries@aimes. Security Overview A guide to data security at AIMES Data Centres www.aimesgridservices.com TEL: 0151 905 9700 enquiries@aimes.net Page 1 of 10 Contents I. Protecting our clients data...2 II. Information

More information

IAAS Recommendation Report

IAAS Recommendation Report Standardisation Committee for Care Information (SCCI) 30 April 2014 Agenda Item:09 For: (insert action/decision/info) IAAS Recommendation Report ISB 1513 Maternity Services Data Set (Amd 45/2012) IAAS

More information

Clinical Risk Management: its Application in the Manufacture of Health IT Systems - Implementation Guidance

Clinical Risk Management: its Application in the Manufacture of Health IT Systems - Implementation Guidance Document filename: ISB 0129 Implementation Guidance v2.1 Directorate Solution Design Standards and Assurance Project Clinical Safety Document Reference NPFIT-FNT-TO-TOCLNSA-1300.03 Director Rob Shaw Status

More information

A. Reference information. A0. G-Cloud Programme unique ID number for the service and version number of this scoping template

A. Reference information. A0. G-Cloud Programme unique ID number for the service and version number of this scoping template G-Cloud Service Pan Government Security Accreditation Scope This form is intended for Suppliers of services on the G-Cloud to complete. Upon receipt, the G-Cloud Programme will check Section A, Reference

More information

Policy Document Control Page

Policy Document Control Page Policy Document Control Page Title Title: Information Governance Policy Version: 5 Reference Number: CO44 Keywords: Information Governance Supersedes Supersedes: Version 4 Description of Amendment(s):

More information

Hertsmere Borough Council. Data Quality Strategy. December 2009 1

Hertsmere Borough Council. Data Quality Strategy. December 2009 1 Hertsmere Borough Council Data Quality Strategy December 2009 1 INTRODUCTION Public services need reliable, accurate and timely information with which to manage services, inform users and account for performance.

More information

Use and verification of the NHS number for all active patients.

Use and verification of the NHS number for all active patients. Title: Reference No: Owner: Author: Use and verification of the NHS number for all active patients. NHSNYYIG-004 Director of Standards Information Governance Team First Issued On: March 2008 Latest Issue

More information

N3 Protecting the Network through Information Governance and Assurance

N3 Protecting the Network through Information Governance and Assurance N3 Protecting the Network through Information Governance and Assurance NHS CFH Operational Security Team cfh.ost@nhs.net Introductions The NHS CFH Operational Security Team: Tony Hodgson Operational Security

More information

Information Governance Standards in Relation to Third Party Suppliers and Contractors

Information Governance Standards in Relation to Third Party Suppliers and Contractors Information Governance Standards in Relation to Third Party Suppliers and Contractors Document Summary Ensure staff members are aware of the standards that should be in place when considering engaging

More information

Summary of the role and operation of NHS Research Management Offices in England

Summary of the role and operation of NHS Research Management Offices in England Summary of the role and operation of NHS Research Management Offices in England The purpose of this document is to clearly explain, at the operational level, the activities undertaken by NHS R&D Offices

More information

Victorian Government Information and Communication Technology (ICT) Governance

Victorian Government Information and Communication Technology (ICT) Governance Governance Victorian Government Information and Communication Technology (ICT) Governance Framework A framework to describe ICT governance in the Victorian Government Keywords: ICT Strategy; governance;

More information

Councillor David Chambers Date of Decision/Referral to O & S REPORT OF: STRATEGIC DIRECTOR (CORPORATE) SDC/08/37

Councillor David Chambers Date of Decision/Referral to O & S REPORT OF: STRATEGIC DIRECTOR (CORPORATE) SDC/08/37 REPORT TO INDIVIDUAL CABINET MEMBER FOR FINANCE, LEGAL AND ICT 20 MAY 2008 Key Decision YES Forward Plan Ref No Corporate Priority ALL Cabinet Portfolio Holder : Councillor David Chambers Date of Decision/Referral

More information

Data Protection Breach Reporting Procedure

Data Protection Breach Reporting Procedure Central Bedfordshire Council www.centralbedfordshire.gov.uk Data Protection Breach Reporting Procedure October 2015 Security Classification: Not Protected 1 Approval History Version No Approved by Approval

More information

Information Commissioner's Office

Information Commissioner's Office Information Commissioner's Office IT Procurement Review Ian Falconer Partner T: 0161 953 6480 E: ian.falconer@uk.gt.com Last updated 18 June 2012 Will Simpson Senior Manager T: 0161 953 6486 E: will.g.simpson@uk.gt.com

More information

National Approach to Information Assurance 2014-2017

National Approach to Information Assurance 2014-2017 Document Name File Name National Approach to Information Assurance 2014-2017 National Approach to Information Assurance v1.doc Author David Critchley, Dave Jamieson Authorisation PIAB and IMBA Signed version

More information

Information Governance Strategy Includes Information risk & incident management methodology

Information Governance Strategy Includes Information risk & incident management methodology Version 2.0 LOGOLOGO Information Governance Strategy Includes Information risk & incident management methodology Approved by: Quality & Governance Committee Ratification date: May 2014 Review date: May

More information

ISO 14001:2004 Environmental Management System Manual

ISO 14001:2004 Environmental Management System Manual ISO 14001:2004 Environmental Management System Manual Company Name/Logo Document No Rev Uncontrolled Copy Controlled Copy Date COMPANY PROPRIETARY INFORMATION Prior to use, ensure this document is the

More information

Lancashire County Council Information Governance Framework

Lancashire County Council Information Governance Framework Appendix 'A' Lancashire County Council Information Governance Framework Introduction Information Governance provides a framework for bringing together all of the requirements, standards and best practice

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Implementation date: 30 September 2014 Control schedule Approved by Corporate Policy and Strategy Committee Approval date 30 September 2014 Senior Responsible Officer Kirsty-Louise

More information

How to gain accreditation for a G-Cloud Service

How to gain accreditation for a G-Cloud Service www.ascentor.co.uk How to gain accreditation for a G-Cloud Service Demystify the process As a registered supplier of G-Cloud services you will be keenly aware that getting onto the G-Cloud framework does

More information

Good Practice Guide: the internal audit role in information assurance

Good Practice Guide: the internal audit role in information assurance Good Practice Guide: the internal audit role in information assurance Janaury 2010 Good Practice Guide: the internal audit role in information assurance January 2010 Official versions of this document

More information

Which MPA Assurance Review?

Which MPA Assurance Review? Which MPA Assurance? A guide to choosing which MPA Assurance s to include in the Integrated Assurance and Approvals Plan for your Major Project Version 1.0 March 2012 Copyright and contacts Crown copyright

More information

INFORMATION SECURITY: UNDERSTANDING BS 7799. BS 7799 is the most influential, globally recognised standard for information security management.

INFORMATION SECURITY: UNDERSTANDING BS 7799. BS 7799 is the most influential, globally recognised standard for information security management. FACTSHEET The essence of BS 7799 is that a sound Information Security Management System (ISMS) should be established within organisations. The purpose of this is to ensure that an organisation s information

More information

Service Definition Document

Service Definition Document Service Definition Document QinetiQ Secure Cloud Protective Monitoring Service (AWARE) QinetiQ Secure Cloud Protective Monitoring Service (DETER) Secure Multi-Tenant Protective Monitoring Service (AWARE)

More information

Records management policy. Document author Assured by Review cycle. Audit and Risk Commitee. 1. Introduction...3. 2. Purpose or aim...3. 3. Scope...

Records management policy. Document author Assured by Review cycle. Audit and Risk Commitee. 1. Introduction...3. 2. Purpose or aim...3. 3. Scope... Records management policy Board library reference Document author Assured by Review cycle P017 Head of Compliance Audit and Risk Commitee 3 Years This document is version controlled. The master copy is

More information

DORSET & WILTSHIRE FIRE AND RESCUE AUTHORITY Performance, Risk and Business Continuity Management Policy

DORSET & WILTSHIRE FIRE AND RESCUE AUTHORITY Performance, Risk and Business Continuity Management Policy Part Two Part One Not Protectively Marked DORSET & WILTSHIRE FIRE AND RESCUE AUTHORITY Performance, Risk and Business Continuity Management Policy. The Dorset & Wiltshire Fire and Rescue Authority (DWFRA)

More information

Information Governance Strategy Includes Information risk & incident management methodology

Information Governance Strategy Includes Information risk & incident management methodology Version 3.0 LOGOLOGO Information Governance Strategy Includes Information risk & incident management methodology Approved by: Quality Assurance Group Ratification date: March 2015 Review date: March 2016

More information

CABINET. 24 March 2015

CABINET. 24 March 2015 CABINET 24 March 2015 Title: Procurement of Electricity and Gas Supplies Report of the Cabinet Member for Finance Open Report with Exempt Appendix 4 Wards Affected: All Report Author: Andrew Sivess Group

More information

Home Page. Title Page. Contents. UK Government open source policy. Sebastian Rahtz January 14th 2005. Page 1 of 15. Go Back. Full Screen. Close.

Home Page. Title Page. Contents. UK Government open source policy. Sebastian Rahtz January 14th 2005. Page 1 of 15. Go Back. Full Screen. Close. Page 1 of 15 UK Government open source policy Sebastian Rahtz January 14th 2005 Page 2 of 15 Welcome Open Source: national frameworks Sebastian Rahtz Our aim today: to get a better understanding of the

More information

OGC. OGC Gateway Review 4 Readiness for service. FINAL REPORT Programme Title: New National Network (N3) OGC Gateway Number: 339

OGC. OGC Gateway Review 4 Readiness for service. FINAL REPORT Programme Title: New National Network (N3) OGC Gateway Number: 339 OGC Gateway Review 4 Readiness for service Version number: Final Report Date of issue to SRO: 25/8/2005 Department: DoH Agency or NDPB: CfH OGC Gateway Review dates 22/8/2005 to 25/8/2005 OGC Gateway Review

More information

NHS Hardwick Clinical Commissioning Group. Business Continuity Policy

NHS Hardwick Clinical Commissioning Group. Business Continuity Policy NHS Hardwick Clinical Commissioning Group Business Continuity Policy Version Date: 26 January 2016 Version Number: 2.0 Status: Approved Next Revision Due: January 2017 Gordon Stevens MBCI Corporate Assurance

More information

Quality Management Standard BS EN ISO 9001:2008. www.imsworld.org

Quality Management Standard BS EN ISO 9001:2008. www.imsworld.org Quality Management Standard BS EN ISO 9001:2008 The Origin of Quality Standards Ministry of Defence Marks & Spencer Ford Motor Company All had their own Quality standards, which they expected their suppliers

More information

SUBJECT ACCESS REQUEST PROCEDURE

SUBJECT ACCESS REQUEST PROCEDURE SUBJECT ACCESS REQUEST PROCEDURE Document History Document Reference: Document Purpose: IG31 This procedure sets out the responsibility for staff when receiving requests for information provided under

More information

GPG13 Protective Monitoring. Service Definition

GPG13 Protective Monitoring. Service Definition GPG13 Protective Monitoring Service Definition Issue Number V1.3 Document Date 27 November 2014 Author: D.M.Woodcock Classification UNCLASSIFIED Version G-Cloud 6 2014 Copyright Assuria Limited. All rights

More information

Draft Guidance: Non-economic Regulators: Duty to Have Regard to Growth

Draft Guidance: Non-economic Regulators: Duty to Have Regard to Growth Draft Guidance: Non-economic Regulators: Duty to Have Regard to Growth January 2014 Purpose of this document The duty to have regard to the desirability of promoting economic growth (the growth duty )

More information

An Overview of ISO/IEC 27000 family of Information Security Management System Standards

An Overview of ISO/IEC 27000 family of Information Security Management System Standards What is ISO/IEC 27001? The ISO/IEC 27001 standard, published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), is known as Information

More information

Independent Pricing and Regulatory Tribunal. Customer engagement on prices for monopoly services

Independent Pricing and Regulatory Tribunal. Customer engagement on prices for monopoly services Independent Pricing and Regulatory Tribunal Customer engagement on prices for monopoly services Research Final Report August 2012 Customer engagement on prices for monopoly services Research Final Report

More information

Role Description Vendor Relationship Manager ICT

Role Description Vendor Relationship Manager ICT Role Description Vendor Relationship Manager ICT Classification/Grade/Band Clerk Grade 9/10 ANZSCO Code PCAT Code Date of Approval Primary purpose of the role The Vendor Relationship Manager ICT is responsible

More information

FREEDOM OF INFORMATION (SCOTLAND) ACT 2002 CODE OF PRACTICE ON RECORDS MANAGEMENT

FREEDOM OF INFORMATION (SCOTLAND) ACT 2002 CODE OF PRACTICE ON RECORDS MANAGEMENT FREEDOM OF INFORMATION (SCOTLAND) ACT 2002 CODE OF PRACTICE ON RECORDS MANAGEMENT November 2003 Laid before the Scottish Parliament on 10th November 2003 pursuant to section 61(6) of the Freedom of Information

More information

Data Communications Company (DCC) price control guidance: process and procedures

Data Communications Company (DCC) price control guidance: process and procedures Guidance document Contact: Tricia Quinn, Senior Economist Publication date: 27 July 2015 Team: Smarter Metering Email: tricia.quinn@ofgem.gov.uk Overview: The Data and Communications Company (DCC) is required

More information

Records Management - Department of Health

Records Management - Department of Health Policy Directive Records Management - Department of Health Document Number PD2009_057 Publication date 24-Sep-2009 Functional Sub group Corporate Administration - Records Ministry of Health, NSW 73 Miller

More information

Monitoring Highways England The monitoring framework

Monitoring Highways England The monitoring framework Monitoring Highways England The monitoring framework October 2015 Contents Executive summary 4 Roads reform 4 ORR s role in monitoring Highways England 5 What we will do next 10 1. Overview of this document

More information

Information Governance Strategy. Version No 2.1

Information Governance Strategy. Version No 2.1 Livewell Southwest Information Governance Strategy Version No 2.1 Notice to staff using a paper copy of this guidance. The policies and procedures page of LSW Intranet holds the most recent version of

More information

Emergency Care Weekly Situation Report Standard Specification

Emergency Care Weekly Situation Report Standard Specification Title Emergency Care Weekly Situation Report Specification Document ID ISB 1607 Specification Sponsor Sarah Butler, DH Status FINAL Developer Paul Steele Version 1.0 Author Paul Steele Version Date 19/03/2014

More information

TERMS OF REFERENCE: REVIEW OF THE INFORMATION GOVERNANCE TOOLKIT

TERMS OF REFERENCE: REVIEW OF THE INFORMATION GOVERNANCE TOOLKIT TERMS OF REFERENCE: REVIEW OF THE INFORMATION GOVERNANCE TOOLKIT The Information Governance Professional Leadership Group hosted by the NHS Commissioning Board is committed to conducting a strategic review

More information

Information Governance Strategy and Policy. OFFICIAL Ownership: Information Governance Group Date Issued: 15/01/2015 Version: 2.

Information Governance Strategy and Policy. OFFICIAL Ownership: Information Governance Group Date Issued: 15/01/2015 Version: 2. Information Governance Strategy and Policy Ownership: Information Governance Group Date Issued: 15/01/2015 Version: 2.0 Status: Final Revision and Signoff Sheet Change Record Date Author Version Comments

More information

SCCI Development Framework

SCCI Development Framework Document filename: SCCI Development Framework Directorate / Programme SCCI Project Development Support Service Document Reference Project Manager [Manager] Status Approved Interim Owner Gwen Smith

More information

NHS Commissioning Board: Information governance policy

NHS Commissioning Board: Information governance policy NHS Commissioning Board: Information governance policy DOCUMENT STATUS: To be approved / Approved DOCUMENT RATIFIED BY: DATE ISSUED: October 2012 DATE TO BE REVIEWED: April 2013 2 AMENDMENT HISTORY: VERSION

More information

www.monitor.gov.uk The NHS Foundation Trust Code of Governance

www.monitor.gov.uk The NHS Foundation Trust Code of Governance www.monitor.gov.uk The NHS Foundation Trust Code of Governance About Monitor Monitor is the sector regulator for health services in England. Our job is to protect and promote the interests of patients

More information

JOB DESCRIPTION. T&T Security and Resilience Manager. Technology and Telecommunications. Bedford, Chelmsford or Norwich

JOB DESCRIPTION. T&T Security and Resilience Manager. Technology and Telecommunications. Bedford, Chelmsford or Norwich JOB DESCRIPTION PART A: JOB DETAILS JOB TITLE: AFC BAND: T&T Security and Resilience Manager 8a HOURS: 37.5 DIRECTORATE: DEPARTMENT: REPORTING TO: BASE: IM&T Technology and Telecommunications Head of T&T

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Version: 3.2 Authorisation Committee: Date of Authorisation: May 2014 Ratification Committee Level 1 documents): Date of Ratification Level 1 documents): Signature of ratifying

More information

Business Continuity Management

Business Continuity Management Business Continuity Management Policy Statement & Strategy July 2009 Basildon District Council Business Continuity Management Policy Statement The Council is committed to ensuring robust and effective

More information

LONDON BOROUGH OF WALTHAM FOREST

LONDON BOROUGH OF WALTHAM FOREST LONDON BOROUGH OF WALTHAM FOREST Meeting / Date Cabinet /December 2015 Report Title Cabinet Portfolio Report Author/ Contact details Wards affected Public Access Appendices ICT Data Centre & Infrastructure

More information

Subject Access Request (SAR) Procedure

Subject Access Request (SAR) Procedure Subject Access Request (SAR) Procedure East and North Hertfordshire Clinical Commissioning Group Page 1 of 16 DOCUMENT CONTROL SHEET Document Owner: Chief Finance Officer Document Author(s): Anne Ephgrave

More information

Scotland s Commissioner for Children and Young People Records Management Policy

Scotland s Commissioner for Children and Young People Records Management Policy Scotland s Commissioner for Children and Young People Records Management Policy 1 RECORDS MANAGEMENT POLICY OVERVIEW 2 Policy Statement 2 Scope 2 Relevant Legislation and Regulations 2 Policy Objectives

More information

Securing excellence in IT Services. Operating model for offender health care

Securing excellence in IT Services. Operating model for offender health care Securing excellence in IT Services Operating model for offender health care February 2013 Table of Contents 01 Glossary of terms 02 Introduction Purpose of document Background 03 Offender Health IT Commissioning

More information

INTERNAL AUDIT FINAL REPORT CNES FINANCE AND CORPORATE RESOURCES DEPARTMENT CLOUD IT SYSTEMS AND THE CRM SYSTEM OFFICIAL OFFICIAL

INTERNAL AUDIT FINAL REPORT CNES FINANCE AND CORPORATE RESOURCES DEPARTMENT CLOUD IT SYSTEMS AND THE CRM SYSTEM OFFICIAL OFFICIAL INTERNAL AUDIT FINAL REPORT CNES FINANCE AND CORPORATE RESOURCES DEPARTMENT CLOUD IT SYSTEMS AND THE CRM SYSTEM AUTHOR DISTRIBUTION David Beaton Director of Finance and Corporate Resources Internal Audit

More information

Proposed withdrawal of the Charities SORP (FRSSE) and other matters impacting on charity accounts RESPONSE FROM ICAS TO THE CHARITIES SORP-MAKING BODY

Proposed withdrawal of the Charities SORP (FRSSE) and other matters impacting on charity accounts RESPONSE FROM ICAS TO THE CHARITIES SORP-MAKING BODY Proposed withdrawal of the Charities SORP (FRSSE) and other matters impacting on charity accounts RESPONSE FROM ICAS TO THE CHARITIES SORP-MAKING BODY 17 September 2015 CA House 21 Haymarket Yards Edinburgh

More information

Data Governance Policy. Version 2.0 19 October 2015

Data Governance Policy. Version 2.0 19 October 2015 Version 2.0 19 October 2015 Document Title: Summary: Date of Issue: Status: Contact Officer: Applies To: References: This policy provides the Cancer Institute NSW with an instrument to formally manage

More information

NHS DORSET CLINICAL COMMISSIONING GROUP GOVERNING BODY INFORMATION GOVERNANCE TOOLKIT REPORT

NHS DORSET CLINICAL COMMISSIONING GROUP GOVERNING BODY INFORMATION GOVERNANCE TOOLKIT REPORT NHS DORSET CLINICAL COMMISSIONING GROUP GOVERNING BODY INFORMATION GOVERNANCE TOOLKIT REPORT 9.7 Date of the meeting 15/07/2015 Author Sponsoring Clinician Purpose of Report Recommendation J Green - Head

More information

REPORT OF: DIRECTOR OF DEMOCRATIC AND LEGAL SERVICES 13/358 WARDS AFFECTED: ALL

REPORT OF: DIRECTOR OF DEMOCRATIC AND LEGAL SERVICES 13/358 WARDS AFFECTED: ALL REPORT TO CABINET TO BE HELD ON 15 OCTOBER 2013 A ITEM Key Decision YES or NO Forward Plan Ref No Corporate Priority All Cabinet Portfolio Holder Cllr Jane Kenyon REPORT OF: DIRECTOR OF DEMOCRATIC AND

More information

Risk management systems of responsible entities: Further proposals

Risk management systems of responsible entities: Further proposals CONSULTATION PAPER 263 Risk management systems of responsible entities: Further proposals July 2016 About this paper This paper sets out our proposals to provide guidance to responsible entities on our

More information

Asset Management Policy March 2014

Asset Management Policy March 2014 Asset Management Policy March 2014 In February 2011, we published our current Asset Management Policy. This is the first update incorporating further developments in our thinking on capacity planning and

More information

Procurement Strategy 2013-2017 Delivering Social Value for our Community

Procurement Strategy 2013-2017 Delivering Social Value for our Community Procurement Strategy 2013-2017 Delivering Social Value for our Community Making Bath & North East Somerset an even better place to live, work and visit 1 Picture courtesy of Bath & News Media Group Our

More information

IT Governance Charter

IT Governance Charter Version : 1.01 Date : 16 September 2009 IT Governance Network South Africa USA UK Switzerland www.itgovernance.co.za info@itgovernance.co.za 0825588732 IT Governance Network, Copyright 2009 Page 1 1 Terms

More information

MANAGING DIGITAL CONTINUITY

MANAGING DIGITAL CONTINUITY MANAGING DIGITAL CONTINUITY Project Name Digital Continuity Project DRAFT FOR CONSULTATION Date: November 2009 Page 1 of 56 Contents Introduction... 4 What is this Guidance about?... 4 Who is this guidance

More information

JOB PROFILE. Collaborate and work effectively with team members within the section and the rest of the Transformation Service.

JOB PROFILE. Collaborate and work effectively with team members within the section and the rest of the Transformation Service. JOB PROFILE Job Title: Principal Commissioning Officer Consultant 3 Department: Corporate Resources Ref: DCC/14/0344 Section: Transformation Service Job Family: Transformation Job grade: 12 Purpose of

More information

Joint Steering Committee for Development of RDA. Subject: Statement of policy and procedures for JSC

Joint Steering Committee for Development of RDA. Subject: Statement of policy and procedures for JSC Page 1 of 14 To: From: Joint Steering Committee for Development of RDA Gordon Dunsire, Chair, JSC Subject: Statement of policy and procedures for JSC Related document: 6JSC/Policy/2 (JSC Meetings) This

More information

Project Charter. Project Sponsor: Prepared By: S. Vassilatos

Project Charter. Project Sponsor: Prepared By: S. Vassilatos Project Charter The Northumbria Building Centre A. General Information Project Title: The Northumbria Building Centre Project Manager: Mr. Alan Dunn Project Client: The Northumbria Building Centre Trust

More information

Locking Stumps Community Primary School. School Business Manager Job Description

Locking Stumps Community Primary School. School Business Manager Job Description Locking Stumps Community Primary School School Business Manager Job Description JOB DESCRIPTION Job Title: School Business and Development Manager Terms and Conditions Term Time Only Annual leave Holidays

More information

Application Guidance CCP Penetration Tester Role, Practitioner Level

Application Guidance CCP Penetration Tester Role, Practitioner Level August 2014 Issue No: 1.0 Application Guidance CCP Penetration Tester Role, Practitioner Level Application Guidance CCP Penetration Tester Role, Practitioner Level Issue No: 1.0 August 2014 This document

More information

7 Directorate Performance Managers. 7 Performance Reporting and Data Quality Officer. 8 Responsible Officers

7 Directorate Performance Managers. 7 Performance Reporting and Data Quality Officer. 8 Responsible Officers Contents Page 1 Introduction 2 2 Objectives of the Strategy 2 3 Data Quality Standards 3 4 The National Indicator Set 3 5 Structure of this Strategy 3 5.1 Awareness 4 5.2 Definitions 4 5.3 Recording 4

More information

Quality Management System Manual

Quality Management System Manual Effective Date: 03/08/2011 Page: 1 of 17 Quality Management System Manual Thomas C. West Eric Weagle Stephen Oliver President ISO Management General Manager Representative Effective Date: 03/08/2011 Page:

More information

Digital Continuity to Support Forensic Readiness

Digital Continuity to Support Forensic Readiness Digital Continuity to Support Forensic Readiness This guidance is produced by the Digital Continuity Project and is available from www.nationalarchives.gov.uk/dc-guidance Crown copyright 2011 You may re-use

More information

Digital Continuity Plan

Digital Continuity Plan Digital Continuity Plan Ensuring that your business information remains accessible and usable for as long as it is needed Accessible and usable information Digital continuity Digital continuity is an approach

More information

Information Security Assurance Plan 2015/16

Information Security Assurance Plan 2015/16 Information Security Assurance Plan 2015/16 Policy number: N/A Version 2.0 Approved by Name of author/originator Owner (Exec Director) Date of approval August 2015 Date of last review July 2015 Next due

More information

Information Security and Governance Policy

Information Security and Governance Policy Information Security and Governance Policy Version: 1.0 Ratified by: Information Governance Group Date ratified: 19 th October 2012 Name of organisation / author: Derek Wilkinson Name of responsible Information

More information

A joint plan to foster a healthy and vibrant Healthcare IT market. Intellect & DH Informatics Directorate. Initial Issue

A joint plan to foster a healthy and vibrant Healthcare IT market. Intellect & DH Informatics Directorate. Initial Issue A joint plan to foster a healthy and vibrant Healthcare IT market Intellect & DH Informatics Directorate Initial Issue Crown Copyright 2012 Page 1 of 8 Amendment History: Version Date Amendment History

More information

Essex County Council Policy for Information Management and Security

Essex County Council Policy for Information Management and Security Essex County Council Policy for Information Management and Security Title Author/Owner Status Essex County Council Policy for Information Management and Security Information Management IS Final Version

More information