N3 Protecting the Network through Information Governance and Assurance



Similar documents
Information Governance Support Pack

Information Governance Framework

Offshore and Internet Connection Addendum to the. Data Sharing Agreement. Version 1.3

INFORMATION GOVERNANCE POLICY

NHS Commissioning Board: Information governance policy

Information Governance Standards in Relation to Third Party Suppliers and Contractors

TERMS OF REFERENCE: REVIEW OF THE INFORMATION GOVERNANCE TOOLKIT

Information Governance Framework and Strategy. November 2014

Information Governance Plan

Information Governance Strategy

Information Governance Strategy

Information Governance Policy

INFORMATION GOVERNANCE POLICY

Information Governance Policy

Barnsley Clinical Commissioning Group. Information Governance Policy and Management Framework

BEFORE USING THIS GUIDANCE, MAKE SURE YOU HAVE THE MOST UP TO DATE VERSION GUIDANCE 2 POLICY AREA: INFORMATION GOVERNANCE

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY

Information Governance Strategy 2015/16

INFORMATION GOVERNANCE POLICY

Information Governance Policy

Information Governance Strategy :

1.5 The Information Governance Policy should be read in conjunction with the Information Governance Strategy.

Information Security Assurance Plan 2015/16

Information Governance Management Framework

INFORMATION GOVERNANCE OPERATING POLICY & FRAMEWORK

Information Governance Policy (incorporating IM&T Security)

JOB DESCRIPTION. Information Governance Manager

Information Governance Policy

, Calendar and Messaging Services Good Practice Guideline

Information Security and Governance Policy

Information Governance Policy

INFORMATION GOVERNANCE POLICY & FRAMEWORK

Information Governance Toolkit Assessment 2009/10

INFORMATION GOVERNANCE AND DATA PROTECTION POLICY

Information Governance and Data Protection Policy

A Question of Balance

SALISBURY NHS FOUNDATIONTRUST

Introduction to the NHS Information Governance Requirements

NHS Hartlepool and Stockton-on-Tees Clinical Commissioning Group. Information Governance Strategy 2015/16

Policy Document Control Page

NHS Newcastle Gateshead Clinical Commissioning Group. Information Governance Strategy 2015/16

Information Governance Policy

NHS North Durham Clinical Commissioning Group. Information Governance Strategy 2015/16

South East Coast Ambulance Service NHS Trust. Information Governance Working Group. Terms of Reference

Information Governance Policy

How To Ensure Network Security

Information Governance Policy

INFORMATION GOVERNANCE STRATEGIC VISION, POLICY AND FRAMEWORK

INFORMATION GOVERNANCE POLICY

Information Governance Strategy

D-CRIS Information Governance Assurance

Information Governance Policy Version - Final Date for Review: 1 October 2017 Lead Director: Performance, Quality and Cooperate Affairs

UCL Information Governance Framework Trevor Peacock UCL School of Life and Medical Sciences

Information Governance Strategy and Policy. OFFICIAL Ownership: Information Governance Group Date Issued: 15/01/2015 Version: 2.

Policies for: Information Governance Information Quality Information Management Information Security. Version Control Version: 0.1

Information Governance Strategy

Information Incident Management and Reporting Procedures

INFORMATION GOVERNANCE POLICY & STRATEGY FINAL DRAFT

Lancashire County Council Information Governance Framework

Information Incident Management. and Reporting Policy

Gloucestershire Hospitals

CONTRACTS REVIEW FOR INFORMATION GOVERNANCE COMPLIANCE PROCEDURE

Bulk Data Transfer Guidelines

Information Governance Strategy. Version No 2.0

How To Ensure Information Security In Nhs.Org.Uk

Information Governance Toolkit Policy

MOORLAND SURGICAL SUPPLIES LTD INFORMATION GOVERNANCE POLICY

Informatics: The future. An organisational summary

Data Encryption Policy

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY

NHS DORSET CLINICAL COMMISSIONING GROUP GOVERNING BODY INFORMATION GOVERNANCE TOOLKIT REPORT

INFORMATION GOVERNANCE STRATEGY NO.CG02

INFORMATION GOVERNANCE POLICY

Date: 30 th May Agenda Item: 5.5. Ian Mackenzie Director of Information and Estates REPORT AUTHOR:

Policy: D9 Data Quality Policy

SOMERSET PARTNERSHIP NHS FOUNDATION TRUST RECORDS MANAGEMENT STRATEGY. Report to the Trust Board 22 September Information Governance Manager

SHEFFIELD TEACHING HOSPITALS NHS FOUNDATION TRUST EXECUTIVE SUMMARY REPORT TO THE BOARD OF DIRECTORS MEETING HELD ON 16 MAY 2012

Information Governance Policy

What NHS staff need to know

Further to reports to EAG in February and March 2014, the purpose of this report is to;

Information Governance Strategy Includes Information risk & incident management methodology

NY&H CSU Service Specification IMT Service SAMPLE ONLY

Information Governance Policy

INFORMATION RISK MANAGEMENT POLICY

INFORMATION GOVERNANCE STRATEGY

INFORMATION GOVERNANCE POLICY (INCORPORATING INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK)

INFORMATION GOVERNANCE INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE AND SECURITY 1 POLICY DRAFTED BY: INFORMATION GOVERNANCE LEAD 2 ACCOUNTABLE DIRECTOR: SENIOR INFORMATION RISK OWNER

Information Governance Policy

NHS Waltham Forest Clinical Commissioning Group Information Governance Strategy

Information Governance Strategic Management Framework

NIGB. Information Governance Untoward Incident Reporting and Management Advice for Local Authorities

ing and Texting with Patients

University of Sunderland Business Assurance Information Security Policy

ULH-IM&T-ISP06. Information Governance Board

Cardiff Council. Data protection audit report. Executive summary June 2014

An Approach to Records Management Audit

Transcription:

N3 Protecting the Network through Information Governance and Assurance NHS CFH Operational Security Team cfh.ost@nhs.net

Introductions The NHS CFH Operational Security Team: Tony Hodgson Operational Security Lead David Brown Operational Security Specialist Matthew Wyatt Operational Security Specialist

OST Mission Our mission is to protect the N3 and maintain: Confidentiality of patient data held on national programmes Integrity ensure controls are in place to prohibit unauthorised access and modification of PID. Availability - assurance that controls are in operation and systems are available in support of patient care

Remit and methods IG Statement of Compliance process (IGSoC) Incident Management Compliance Liaison Between Departments, Organisations & Government Agencies Advice and Guidance Security Awareness

Out of Scope Dispelling the myths We Don t Do: Product Assurance General Connectivity Problem Solving IG Toolkit Assistance Performing Risk Assessments On Behalf Of NHS Organisations / CFH Departments, NPfIT Suppliers Audits

Who Needs An N3 Connection? Any Organisation providing services where access to Patient Identifiable Data, or National Services is required or possible as a result of the services being performed

Information Governance Statement of Compliance (IGSoC) What is it?

Definition: The process by which organisations enter into agreement with NHS CFH for access to the NHS National Network (N3)

IGSoC Is not: An Accreditation A Certificate of Compliance A Global Assurance Mechanism A Required Element Of Working With The NHS A means to transfer risk or data ownership

IGSoC History Code of Connection (NHSnet) IGSoC (version 6) IGSoC Process Evolution

IG Toolkit IGT is the strategic assurance tool developed by the DoH for NHS organisations and relevant other partners to assess and record their performance against IGT requirements are derived from industry good practice including ISO 27001 for information security The IGT is maintained via an annual self assessment submitted online and verified by the DoH IG Team It is intended from 2012 to extend the scope of the NHS IGT to all users of NHS patient information whether they connect to N3 or not IGT version 9 is in effect now and version 10 due in June 2012.

Routes to Connect and Current Process NHS: Complete IG Toolkit Sign IG Assurance Statement

Non-NHS Application Form IG Toolkit LCA (if Direct Connection) Offshore Support Policy (If Required) ISMS (If Required) Sign IG Assurance Statement

Sponsorship and the NHS All non-nhs organisations must have sponsorship from an NHS organisation (Local, National or DH) as part of the application process Because a third party supplier has completed IGSoC, it does not mean that any Trust commissioning services from them should not complete their own Risk Assessment

Logical Connection Architecture Non-NHS organisations who wish to directly connect to N3 are required to complete and submit an LCA for each connection they are applying for Objective is to establish the agreed architecture (and associated security controls) of the local network that the non-nhs organisation wishes to connect to N3. Managed by OST v 2.0 Currently Under review (v 3.0 expected Late Summer / Early Autumn)

Offshore Increase in offshore support presents additional risks Access to N3 provided by exception

Offshore Documents reviewed by NHS CFH OST Formal review by the Information Assurance Working Group (IAWG) IAWG is responsible for technical security of N3 only If proposal breaches DH / NHS policy, the decision will be referred to policy experts for clarification / amendment

This means: An approval from IAWG refers to the technical suitability of an organisation to connect to N3 from outside of England In no way infers CFH have approved or endorsed any working practices Does not mitigate and NHS Organisation commissioning services from performing their own Risk Assessments

Maintenance of IGSoC Annual completion of the IGT and acceptance of the IG Assurance Statement Informing NHS CFH of any changes to: Individuals authorised to request changes Change of Chief Exec Infrastructure (requires revised LCA) Any Offshore activity

Protecting Your Service Report incidents immediately Contact cfh.servicebridge@nhs.net This does not exonerate Data Controllers, Caldicott Guardians or SIROs from their obligations under the DPA (1998) or DH policy

Incident Reporting Procedure Email to cfh.servciebridge@nhs.net Investigation Resolution Closure Lessons Learned GovCert warnings

Questions? Team mailbox cfh.ost@nhs.net Document / Change submission: exeter.helpdesk@nhs.net