Last updated: 14 January 2010
In June 2008, we published the first report into cross government data handling procedures. That report put in place a set of unprecedented mandatory measures for government departments to improve the way they manage and handle personal data. Protecting Information in Government takes stock of the progress made since the publication of the Data Handling Review and highlights future challenges.
Protecting Information in Government
An e-learning package has been produced by the IS&A in the Cabinet Office in conjunction with the National School of Government
- Use it - Don’t Lose it e-learning package
The final report on data handling procedures across government published on 25th June 2008 sets out how Government is improving its arrangements around information and data security, by putting in place core protective measures, getting the working culture right, improving accountability and scrutiny of performance.
Nick Coleman, former Head of Security Services at IBM, was commissioned by the IS&A to produce a report on the state of government information assurance activities. Below is a synopsis of the review and the recommendations.
The guidance outlines the generic module structure, the core training specification the proposed delivery mechanism, methods of assessment, time frames for delivery and the role of departments and the centre in the delivery of training.
- Outline Specification for DHR information Risk Awareness Training [PDF, 75KB]
The guidance outlines the generic module structure, the core training specification the proposed delivery mechanism, methods of assessment and time frames for delivery.
- Guidance on Roles specific training [PDF, 116KB]
The guidance outlines the role descriptions for the Knowledge Manager
- Guidance on non mandatory roles [PDF, 47KB]
The IS&A produces and maintains the National Information Assurance Strategy. The current strategy was published in June 2007.
Protecting our information systems - working in partnership to secure a resilient UK information infrastructure, June 2004. (PDF file, 566KB)
– IS&A Protecting our information systems (PDF file)
If you would like a quantity of printed copies of Protecting our information systems, please contact: csia@cabinet-office.x.gsi.gov.uk or call 0207 276 3115.
IS&A information leaflet (PDF file, 179KB)
Providing a useful framework plotting the work of both public and private sectors in promoting information assurance awareness, October 2004. (PDF file, 410KB)
– Review of information assurance (PDF file)
These Security Framework documents will be replaced by the new e-Government IA framework following the public consultation following the public consultation (now closed).
Security: e-Government strategy framework policy and guidelines, September 2002. (PDF file, 568KB)
– Security (PDF file)
Assurance: e-Government strategy framework policy and guidelines, September 2002. (PDF file, 219KB)
– Assurance (PDF file)
Business services: e-Government strategy policy framework and guidelines, September 2002. (PDF file, 270KB)
– Business services (PDF file)
Confidentiality: e-Government strategy framework policy and guidelines, September 2002. (PDF file, 270KB)
– Confidentiality (PDF file)
Network defence: e-Government strategy framework policy and guidelines, September 2002. (PDF file, 272KB)
– Network defence (PDF file)
Registration and authentication: e-Government strategy framework and policy guidelines, September 2002. (PDF file, 371KB)
– Registration and authentication (PDF file)
Trust services: e-Government strategy policy framework and guidelines, September 2002. (PDF file, 290KB)
– Trust services (PDF file)
Security architecture, September 2002. (PDF file, 671KB)
– Security architecture (PDF file)