UKDAIM: IDENTITY MANAGEMENT IN A SERVICE PROVISION ENVIRONMENT

Size: px
Start display at page:

Download "UKDAIM: IDENTITY MANAGEMENT IN A SERVICE PROVISION ENVIRONMENT"

Transcription

1 UKDAIM: IDENTITY MANAGEMENT IN A SERVICE PROVISION ENVIRONMENT Case study PUBLIC VERSION 06 SEPTEMBER T +44 (0) E djhall@data-archive.ac.uk UK DATA ARCHIVE UNIVERSITY OF ESSEX WIVENHOE PARK COLCHESTER ESSEX, CO4 3SQ... WE ARE SUPPORTED BY THE UNIVERSITY OF ESSEX, THE ECONOMIC AND SOCIAL RESEARCH COUNCIL, AND THE JOINT INFORMATION SYSTEMS COMMITTEE

2 Contents UKDAIM_IdentityManagmentCaseStudy_03_00_PUBLIC 1. Identity Management at the UK Data Archive Service Provider Identity Provider (Virtual Orphanage) Audit and gap analysis The JISC Identity Management Toolkit Conclusion List of Figures Figure 1: Archive managed distributed service Page 2 of 6

3 UKDAIM_IdentityManagmentCaseStudy_03_00_PUBLIC Summary The UK Data Archive is curator of the largest collection of digital data in the social sciences and humanities in the United Kingdom. The way in which access to the data collections is managed means the Archive gathers information about user identity, varying depending upon the nature of the data required by a user and the restrictions placed upon access by the data owners. The audit approach of the JISC Identity Management (IdM) Toolkit was used to review this critical aspect of the Archive s processes. This project - UKDA: Identity Management in a Service Environment (UKDAIM) - looked at both how well the Toolkit could be applied in a service provider context and what potential there was for improvement in the Archive s policies and procedures for identity management. For the purposes of the project IdM was defined as: Processes and systems, electronic or paper-based, which allow and manage the creation, description, retrieval, update, verification and destruction of identities and information relating to identities, including any rights/authority granted to those identities. Author and Origin David Hall UK Data Archive, University of Essex, July 2011 Terms of use This material may be freely used by UK institutions of further and higher education. Material may be copyright of individual authors or contributing institutions. If you are interested in commercial or other re-use of any material here, please contact JISC-Identity-Management@JISCmail.ac.uk to discuss your request. You are advised to seek independent legal and technical advice if necessary before proceeding to follow any advice published here, and no liability can be accepted by JISC, the UK Data Archive or any other party for the consequences. The author would be interested in comments from anyone referring to or using the content of this case study and associated documents. Please djhall@essex.ac.uk. 1. Identity Management at the UK Data Archive The UK Data Archive provides single sign-on access to digital data in the social sciences and humanities, using Shibboleth authentication via the UK Access Management Federation 1 (UKAMF). All users must be able to authenticate via the UKAMF and must complete a basic registration process. Registration requires acceptance of an End User Licence. Once complete, the licence gives access to most of the data collections held by the Archive. To gain access to some data a user may have to: Fit particular criteria, such as being from a UK further or higher education institution, and/or Agree further conditions and licences relating to specific data, and/or Go through an additional application process to gain a specific status, such as ONS-Approved or ESRC-Accredited Researcher. All access is linked to the basis on which data collections have been released for distribution by the Archive licences and other agreements set out the conditions for data distribution. The failure to properly apply identity management processes could lead to unauthorised access to data, breaches of licences and agreements and, at worst, withdrawal of data from the Archive s collections. Page 3 of 6

4 The Archive stores information about users: UKDAIM_IdentityManagmentCaseStudy_03_00_PUBLIC Their unique ID from the authentication process Personal details provided during registration Registration and licence acceptance details and dates Data usage The Archive not only acts as a Service Provider (SP) delivering resources to users, but also acts as an Identity Provider (IdP) to facilitate wider access by users outside UK Further and Higher Education (F&HE) Service Provider The Archive manages access to a distributed service by providing a Virtual Organisation Service Provider (VOSP), which is described in the project audit report. This acts as a hub for user authentication by providing a channel between a number of SPs and the IdPs of users. Figure 1: Archive managed distributed service * ESDS Economic and Social Data Service; Census ESRC Census of Population Programme. Page 4 of 6

5 UKDAIM_IdentityManagmentCaseStudy_03_00_PUBLIC 1.2. Identity Provider (Virtual Orphanage) It is not possible for all individuals who wish to use the resources managed by the Archive and its partners to authenticate and gain access without some Archive support, because they do not belong to an organisation which is a member of the UKAMF. Among these are non-uk academics, individuals from commercial organisations and private individuals either with no organisational links or who are pursuing research unconnected with their employment. The Archive is committed to providing the widest access possible to its collections, subject to any licensing restrictions. The Archive therefore provides a virtual orphanage for these individuals in the form of its own IdP. Shibboleth credentials are issued by the Archive for use within the UKAMF. As there is little identity checking of these individuals the Archive does not validate their identity for any SP outside the distributed services which use authentication via the Archive s VOSP. In addition, the access for these individuals is restricted further within the distributed service, for example to prevent access to resources limited to users within UK F&HE. There is no technical link within the Archive between this virtual orphanage IdP and the SP or VOSP. Having obtained Shibboleth credentials from the Archive the user must then register through the Economic and Social Data Service (ESDS) to gain access to resources. 2. Audit and gap analysis The project applied sections of the JISC Identity Management Toolkit (the Toolkit) which relate to discovering and auditing current institutional identity management (IdM) and gap analysis 2, but using the whole Toolkit as the basis for exploring IdM within the Archive. The audit was conducted from February through to June 2011, with the gap analysis produced during June and July Both the UKDAIM Identity Management Audit Report and the UKDAIM Identity Management Gap Analysis can be accessed via The audit was confined to IdM within the Archive, but did involve the Information Systems Section (ISS) of the University of Essex. The Archive, as other SPs, relies upon the way in which IdM is handled within institutions whose users require access to its resources. Working with ISS allowed examination of this relationship. The audit looked at how an IdP translates its many user identities into the user types available for authentication purposes within the UKAMF and how new user groups e.g. students and staff at overseas campuses of UK institutions were being incorporated into IdM policies and procedures. User types included in the edupersonscopedaffiliation attribute and the unique user identifier the edupersontargetedid are used by the Archive to manage access to resources. The effectiveness of IdM within IdPs is critical in managing access to resources. Within the Archive the audit involved the interviews and document review suggested by the Toolkit. As a result of this work the Archive will be reviewing its documentation to address identified gaps. This will be important across the services provided by the Archive, and will help strengthen its adherence to externally validated standards. 3. The JISC Identity Management Toolkit Whilst the Archive used the audit and gap analysis to test its IdM and look for improvements, the project also assessed how well the Toolkit could be applied within the environment of a SP. It was found that the Toolkit provided a sound basis for assessing and developing the IdM of a SP. The drawback is its emphasis on larger institutions which act as IdPs. For a SP especially a smaller organisational unit the terminology and approach can be seen as overly bureaucratic. When using the Toolkit a level of flexibility is needed to match the approach to the scale of the organisation (taking note of its Page 5 of 6

6 U KDAIM_IdentityManagmentCaseStudy_03_00_PUBLIC place, if any, within a larger organisation which may have its own IdM structures). Similarly the audit report template, for example, should be treated as a guide to content, with organisational style and audience moulding the reports format. The Toolkit approach worked well in preparing the gap analysis report. In particular the summary analysis with scores for gaps helped managers appreciate the effort required to address issues and the priorities for dealing with these. As with the audit report flowing into the gap analysis, the latter inspired senior managers to create a high level plan for addressing issues: Identifying immediate actions necessary or easily achieved Placing issues in the context of existing and planned work Prioritising and scheduling work to ensure an effective approach and outcome Because of the nature of the work identified by the gap analysis, the scale of the organisation and the commitment of senior management, a more formal roadmap process is not envisaged. The achievement of work arising out of the audit and gap analysis will be monitored closely through the existing Archive structures, including senior management review of a calendar of commitments and monitoring by the Archive s Strategy Group (which acted as the project advisory group). 4. Conclusion There is no doubt that the Toolkit provided an effective way to approach auditing and analysis of the IdM within the service provision environment of the UK Data Archive, a relatively small organisation. If there is a general conclusion to be drawn it is that the Toolkit should be applied in a way which is tailored to the organisation s size and complexity, recognising the environment within which it operates Sections 5 and 6, Identity Management Toolkit, 3 Compare the approach in 2.7 Managing Successful Projects with PRINCE2, 5 th edition, Office of Government Commerce, Page 6 of 6

Information Governance and Records Management Policy March 2014

Information Governance and Records Management Policy March 2014 Information Governance and Records Management Policy March 2014 Approving authority: Secretary s Board Consultation via: Secretary's Board Information Governance and Security Group Approval date: 4 March

More information

Identity Management. a Toolkit for institutions. John Paschoud, London School of Economics

Identity Management. a Toolkit for institutions. John Paschoud, London School of Economics Identity Management a Toolkit for institutions John Paschoud, London School of Economics What are the business drivers for better Identity Management? Process efficiency cost-savings on duplicated processes

More information

Sample Data Management Policy Structure

Sample Data Management Policy Structure Sample Data Management Policy Structure This document has been produced by The Audience Agency. You are free to edit and use this document in your business. You may not use this document for commercial

More information

ASBESTOS POLICY & MANAGEMENT PLAN UNIVERSITY OF ESSEX HUMAN RESOURCES / ESTATE MANAGEMENT SERVICE

ASBESTOS POLICY & MANAGEMENT PLAN UNIVERSITY OF ESSEX HUMAN RESOURCES / ESTATE MANAGEMENT SERVICE ASBESTOS POLICY & MANAGEMENT PLAN UNIVERSITY OF ESSEX HUMAN RESOURCES / ESTATE MANAGEMENT SERVICE Version 04.04.2017 Issue 1.2 (updated 17.01.2018) Approved by USG 10.10.17 1 CONTENTS 1 POLICY STATEMENT...1

More information

Prevent duty monitoring in higher education in England. Supplementary information note

Prevent duty monitoring in higher education in England. Supplementary information note Prevent duty monitoring in higher education in England Supplementary information note Enquiries to prevent@officeforstudents.org.uk Publication date 12 September 2018 About this information note 1. This

More information

Digital Delivery, Quality and Innovation Project Officer Job Description and Person Specification

Digital Delivery, Quality and Innovation Project Officer Job Description and Person Specification Digital Delivery, Quality and Innovation Project Officer Job Description and Person Specification Overall Purpose of Job To lead on developing and implementing innovative and quality assured approaches

More information

CFAMLF12 - SQA Unit Code DR58 04 Improve organisational performance

CFAMLF12 - SQA Unit Code DR58 04 Improve organisational performance Overview This unit is about overseeing the continuous improvement of the overall performance of the organisation. The emphasis is very much on identifying and implementing changes which will add value

More information

Records Management Policy

Records Management Policy Records Management Policy Responsible Officer Author Business Planning & Resources Director Corporate Office Date effective from December 1999 Date last amended December 2015 Review date October 2018 1

More information

RM-03 (2017) Records management policy

RM-03 (2017) Records management policy RM-03 (2017) Records management policy The Scottish Parliamentary Corporate Body (SPCB) The Scottish Parliament The Scottish Commission for Public Audit (SCPA) Foreword Records management is vital for

More information

Recordkeeping for Good Governance Toolkit. GUIDELINE 13: Digital Recordkeeping Readiness Self-assessment Checklist for Organisations

Recordkeeping for Good Governance Toolkit. GUIDELINE 13: Digital Recordkeeping Readiness Self-assessment Checklist for Organisations Recordkeeping for Good Governance Toolkit GUIDELINE 1: Digital Recordkeeping Readiness Self-assessment Checklist for Organisations i The original version of this guideline was prepared by the Pacific Regional

More information

Overarching Information Governance Policy

Overarching Information Governance Policy Document Information Board Library Reference Document Type Document Subject Original Document Author Reviewed By Review Cycle IM&T_01 Policy Information Information IGMG 3 Years Note: This document is

More information

SFIA Accredited Consultant

SFIA Accredited Consultant CONTEXT Typically works as an external consultant (independently or for a SFIA partner organisation). May work as an internal consultant within a large / complex user organisation. PURPOSE To advise organisations

More information

UK Research and Innovation (UKRI) Records Management Policy

UK Research and Innovation (UKRI) Records Management Policy UK Research and Innovation (UKRI) Records Management Policy Contents Policy statement 1. Principles... 5 2. Records creation and maintenance... 5 3. Records retention and disposal... 6 4. Access to records...

More information

Digitisation of documents and legal archiving

Digitisation of documents and legal archiving Digitisation of documents and legal archiving Roland Bastin Partner Information & Technology Risk Deloitte Stéphane Hurtaud Partner Information & Technology Risk Deloitte Laureline Senequier Manager Information

More information

Assessor Assessment Pack

Assessor Assessment Pack Maintain Business Resources BSBADM311 Precision Group (Australia) Pty Ltd 44 Bergin Rd, Ferny Grove, QLD, 4055 Email: info@precisiongroup.com.au Website: www.precisiongroup.com.au Precision Group (Australia)

More information

Impact Summary and Pathways to Impact Frequently Asked Questions AHRC

Impact Summary and Pathways to Impact Frequently Asked Questions AHRC Application stage Impact Summary and Pathways to Impact Frequently Asked Questions AHRC Why is there an increasing emphasis on demonstrating the impact of research? Public bodies such as the AHRC need

More information

KINGSTON SOCIAL ENTERPRISE & INNOVATION TOOLKIT: EXECUTIVE SUMMARY

KINGSTON SOCIAL ENTERPRISE & INNOVATION TOOLKIT: EXECUTIVE SUMMARY KINGSTON SOCIAL ENTERPRISE & INNOVATION TOOLKIT: EXECUTIVE SUMMARY Social enterprise and innovation is an emerging trend. Now, in the year 2011, there can be many examples of social enterprise and innovation

More information

Assessor Assessment Pack

Assessor Assessment Pack Establish Legal and Risk Management Requirements of Small Business BSBSMB401 Precision Group (Australia) Pty Ltd 44 Bergin Rd, Ferny Grove, QLD, 4055 Email: info@precisiongroup.com.au Website: www.precisiongroup.com.au

More information

Pay Band and salary Location Duration Reports to: Indefinite Contract

Pay Band and salary Location Duration Reports to: Indefinite Contract Role Title Head of Communications - South Asia Role Information Pay Band and salary Location Duration Reports to: 8/E Starting Salary: INR2000,000/ annum Delhi, India Indefinite Contract Regional Director

More information

Marketing Coordinator ERDF Project EHA

Marketing Coordinator ERDF Project EHA It is important to note that this job description is a guide to the work you will initially be required to undertake. It may be changed from time to time to meet changing circumstances. It does not form

More information

Learning & Development Manager

Learning & Development Manager Learning & Development Manager Introduction from the Head of Leadership & Engagement Annette Gillingham Thank you for taking the time to read this information pack. This is a really exciting opportunity

More information

Audit Committee Self Assessment

Audit Committee Self Assessment Audit Committee Institute United Kingdom Audit Committee Self Assessment The audit committee should regularly assess its own effectiveness and the adequacy of its terms of reference, work plans, forums

More information

Records Disposal Schedule Higher Education Teaching and Learning Charles Darwin University

Records Disposal Schedule Higher Education Teaching and Learning Charles Darwin University Records disposal schedule Records Disposal Schedule Higher Education Teaching and Learning Charles Darwin University Disposal Schedule No. For information and advice, please contact Department of Corporate

More information

Creative Director Application pack

Creative Director Application pack Creative Director Application pack September 2018 Crafts Council A national charity, we advance craft in the UK. We build on the UK's status as a world leader in craft, harnessing the power of craft to

More information

The table below highlights in bold those policies, plans and strategies which are of particular relevance to the Collections Information Policy:

The table below highlights in bold those policies, plans and strategies which are of particular relevance to the Collections Information Policy: Aim & purpose This collections information policy focusses on the provision of intellectual access to collections, both by users and by staff for management purposes. It will assist in decision making

More information

Implementing Standardised Systems, Processes, Tools and

Implementing Standardised Systems, Processes, Tools and Int. Statistical Inst.: Proc. 58th World Statistical Congress, 2011, Dublin (Session STS044) p.3037 Implementing Standardised Systems, Processes, Tools and Methods with the ONS Design Charter Finselbach,

More information

POLICY. TITLE POLICY Records Management Policy. roxbycouncil POLICY RECORDS MANAGEMENT Policy Date Latest Review Changes

POLICY. TITLE POLICY Records Management Policy. roxbycouncil POLICY RECORDS MANAGEMENT Policy Date Latest Review Changes Responsible Department Corporate Services POLICY Original Adoption Date 31.01.11 Current Adoption Date 30.08.17 Audit Committee Review Date N/A Date of Review 31.08.19 TITLE POLICY Records Management Policy

More information

International Project Manager (Team Programme, Jordan) Any UK Prince s Trust office or centre with frequent oversees travel

International Project Manager (Team Programme, Jordan) Any UK Prince s Trust office or centre with frequent oversees travel JOB DESCRIPTION Job Title: Location: International Project Manager (Team Programme, Jordan) Any UK Prince s Trust office or centre with frequent oversees travel Introduction Prince s Trust International

More information

Course Specification. Making the Transition to ISO 14001:2015

Course Specification. Making the Transition to ISO 14001:2015 Course Specification Making the Transition to ISO 14001:2015 CONTENTS 1. ABOUT US... 3 2. BACKGROUND... 4 3. COURSE DURATION... 4 4. WHO IS THIS COURSE FOR?... 4 5. MATERIALS AND CERTIFICATION... 4 6.

More information

Records Retention Schedule

Records Retention Schedule Plymouth University Records Retention Schedule Author: Date: 18/12/2015 Elena Menendez-Alonso (Digital Curator) Security Level: PUBLIC Status: Published Version: 1.0 Review Date: 31/12/2017 Contents 1.

More information

Compliance assurance programmes

Compliance assurance programmes May 2018 Compliance assurance programmes This information sheet explains the Financial Markets Authority s expectations for a compliance assurance programme (CAP). It will be useful for entities holding

More information

The Sector Skills Council for the Financial Services Industry. National Occupational Standards. Risk Management for the Financial Sector

The Sector Skills Council for the Financial Services Industry. National Occupational Standards. Risk Management for the Financial Sector The Sector Skills Council for the Financial Services Industry National Occupational Standards Risk Management for the Financial Sector Final version approved April 2009 IMPORTANT NOTES These National Occupational

More information

EAST SUSSEX FIRE AUTHORITY Job Description

EAST SUSSEX FIRE AUTHORITY Job Description EAST SUSSEX FIRE AUTHORITY Job Description Work Designation: Safer Communities Directorate Location: Business Safety Central Hub, Eastbourne Job Title: Petroleum Inspecting Officer Rank or Grade: Green

More information

RECOGNITION OF PRIOR LEARNING POLICY AND PROCEDURE

RECOGNITION OF PRIOR LEARNING POLICY AND PROCEDURE RECOGNITION OF PRIOR LEARNING POLICY AND PROCEDURE POLICY TITLE: POLICT NUMBER: RESPONSIBILITY: RECOGNITION OF PRIOR LEARNING POLICY AND PROCEDURE WIP0910-029 POLICY OPERATIONS MANAGER Scope of Policy

More information

Information governance strategy

Information governance strategy Information governance strategy January 2018 Version 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment V 1.0 Trevor Duplessis 22/01/18 Due for review Dec

More information

SUMMARY OF: FSA Discussion Paper 06/05. FSA Confirmation of Industry Guidance

SUMMARY OF: FSA Discussion Paper 06/05. FSA Confirmation of Industry Guidance SUMMARY OF: FSA Discussion Paper 06/05 FSA Confirmation of Industry Guidance February 2007 Page 2 Summary of: FSA Discussion Paper 06/05 FSA Confirmation of Industry Guidance Introduction The move towards

More information

Job Description. General Details. Infrastructure Architect (DS17/ITR1i) Grade/Salary: 7. Date Prepared: 10/11/16. Job Purpose

Job Description. General Details. Infrastructure Architect (DS17/ITR1i) Grade/Salary: 7. Date Prepared: 10/11/16. Job Purpose Job escription General etails Job title: School/Service: Normal Workbase: Tenure: Hours/FT: Infrastructure Architect (S17/ITR1i) igital Services Stoke-on-Trent Campus Permanent 1.0 FT Grade/Salary: 7 ate

More information

BT Identity and Access Management Quick Start Service

BT Identity and Access Management Quick Start Service BT Identity and Access Management Quick Start Service The BT Identity and Access Management Quick Start Service enables organisations to rapidly assess their Identity and Access Management (IAM) implementation

More information

Interim Head of Internal Communications (Fixed Term)

Interim Head of Internal Communications (Fixed Term) About The Job. Department of Corporate Affairs Professional Services Interim Head of Internal Communications (Fixed Term) Pursue the extraordinary Overview About the Department Corporate Affairs is a key

More information

Demonstrates understanding of the key factors within HE impacting upon their own and interfacing areas* and/or specialisms+

Demonstrates understanding of the key factors within HE impacting upon their own and interfacing areas* and/or specialisms+ Strategic Thinking & Perspective Is able to think strategically, envisioning the future of their area* and/or in and beyond the context of College/Division strategy and the strategy Demonstrates understanding

More information

Chief Executive (permanent)

Chief Executive (permanent) Chief Executive (permanent) Closing date: 09.00 on Mon 07 December 2015 Interview dates: Tue 15 and Wed 16 December 2015 (both dates) Start date: as soon as possible Background The Edinburgh Festival Fringe

More information

EMPLOYING DDI AT THE UK DATA ARCHIVE NOW AND NEXT...

EMPLOYING DDI AT THE UK DATA ARCHIVE NOW AND NEXT... EMPLOYING DDI AT THE UK DATA ARCHIVE NOW AND NEXT.... JACK KNEESHAW... SERVICE MANAGER UNIVERSITY OF ESSEX... MRC DATA MANAGEMENT WORKSHOP 11 AUGUST 2011 THIS PRESENTATION Introduction to the UK Data Archive

More information

A Quality Assurance Framework for Knowledge Services Supporting NHSScotland

A Quality Assurance Framework for Knowledge Services Supporting NHSScotland Knowledge Services B. Resources A1. Analysis Staff E. Enabling A3.1 Monitoring Leadership A3. Measurable impact on health service Innovation and Planning C. User Support A Quality Assurance Framework for

More information

Active Essex Risk Management Strategy

Active Essex Risk Management Strategy Active Essex Risk Management Strategy 2017-2021 November 2017 Contents 1. Policy Statement 2. Statement of Commitment 3. Risk Management Framework 4. Risk Appetite 5. Risk Maturity 6. Risk Management Levels

More information

BIIAB Level 5 Diploma in Cultural Heritage

BIIAB Level 5 Diploma in Cultural Heritage Qualification Handbook 601/6498/0 Version 2 BIIAB January 2018 Table of Contents 1. About the... 1 2. About this Pack... 1 3. BIIAB Customer Service... 2 4. What are Rules of Combination (ROC)?... 2 5.

More information

Rail Engineering Apprenticeship Standard Rail Engineering Technician (Level 3) End Point Assessment Plan

Rail Engineering Apprenticeship Standard Rail Engineering Technician (Level 3) End Point Assessment Plan Rail Engineering Apprenticeship Standard Rail Engineering Technician (Level 3) End Point Assessment Plan Version: 26/09/17 Page 1 of 20 Contents Summary of assessment... 3 Detailed Requirements for Occupational

More information

Joint area review: enhanced youth inspection Head of youth service guidance paper

Joint area review: enhanced youth inspection Head of youth service guidance paper Joint area review: enhanced youth inspection Head of youth service guidance paper This paper provides detailed guidance for heads of youth service on the enhanced youth inspection process. Of particular

More information

Regulatory Compliance and Enforcement Framework

Regulatory Compliance and Enforcement Framework Contents 1. About us... 3 1.1 Our Mission and Values... 3 2. Relevant Legislation and Obligations... 4 3. Approach to Regulatory Compliance and Enforcement... 4 3.1 Our Approach... 4 3.2 Working with Stakeholders...

More information

CAPABILITY DEVELOPMENT TOOLKIT

CAPABILITY DEVELOPMENT TOOLKIT AGENCY GUIDANCE PROGRAMME FOR THE STATE SECTOR New Zealand is internationally recognised as having one of the most open and transparent governments in the world. We cannot rest on our laurels though and

More information

Marketing & Customer Engagement Manager

Marketing & Customer Engagement Manager Role Title Directorate Job Family Competency Level Pay Range / Scale Responsible to Location Marketing & Customer Engagement Manager Families and Homes Marketing and Communications Principal Officer/Manager

More information

Information Security Risk Management Programme and Strategy

Information Security Risk Management Programme and Strategy Information Security Risk Management Programme and Strategy Table of Contents 1. Introduction... 3 2. Purpose... 3 3. Definitions... 3 4. Roles and Responsibilities... 4 4.1. Accountable Officer... 4 4.2.

More information

INTERNAL AUDIT DIVISION

INTERNAL AUDIT DIVISION INTERNAL AUDIT DIVISION REPORT 2015/057 Audit of the Omgeo system in the Investment Management Division of the United Nations Joint Staff Pension Fund Overall results relating to the effective and efficient

More information

JOB DESCRIPTION. Position Number various. Job Title Trial Manager. Academic / Service Unit Newcastle Clinical Trials Unit. Effective Date

JOB DESCRIPTION. Position Number various. Job Title Trial Manager. Academic / Service Unit Newcastle Clinical Trials Unit. Effective Date Job Title Trial Manager Academic / Service Unit Newcastle Clinical Trials Unit Position Number various Effective Date 01.04.2018 Faculty / Central Services Faculty of Medical Sciences Grade F Vacancy Ref

More information

Qualified Persons in the Pharmaceutical Industry. Code of Practice. March 2008

Qualified Persons in the Pharmaceutical Industry. Code of Practice. March 2008 Qualified Persons in the Pharmaceutical Industry Code of Practice March 2008 Updated October 2009 Code of Practice for Qualified Persons 1. INTRODUCTION... 1 2. REGULATORY BASIS FOR THE QUALIFIED PERSON...

More information

CONTINUING PROFESSIONAL DEVELOPMENT (CPD) POLICY May 2013

CONTINUING PROFESSIONAL DEVELOPMENT (CPD) POLICY May 2013 INTRODUCTION CONTINUING PROFESSIONAL DEVELOPMENT (CPD) POLICY May 2013 The knowledge and skills needed to function effectively as a Chartered Secretary, in business, education, professional practice, the

More information

Position Description

Position Description Position Description POSITION TITLE: REPORTS TO: EMPLOYMENT TYPE/STATUS: EMPLOYMENT STATUS: Corporate Communications and Content Coordinator Communications and Stakeholder Engagement Manager FULL TIME

More information

INSTITUTE OF HOSPITALITY AWARDING BODY CONFLICT OF INTEREST POLICY

INSTITUTE OF HOSPITALITY AWARDING BODY CONFLICT OF INTEREST POLICY INSTITUTE OF HOSPITALITY AWARDING BODY CONFLICT OF INTEREST POLICY Version 0.2, 13.08.2014 Institute of Hospitality Trinity Court, 34 West Street, Sutton, Surrey, SM1 1SH Tel:+44(0)20 8661 4900 www.instituteofhospitality.org.uk

More information

HouseMark office with flexibility to work one day a week from home

HouseMark office with flexibility to work one day a week from home JOB DESCRIPTION JOB TITLE: DEPARTMENT: REPORTS TO: MANAGES: SALARY: LOCATION: Marketing Manager Marketing and Communications Head of Marketing and Communications Marketing Campaign Officer Competitive

More information

Review of measures of reading engagement: Invitation to Tender

Review of measures of reading engagement: Invitation to Tender Review of measures of reading engagement: Invitation to Tender Introduction The Reading Agency is a leading charity that inspires people of all ages and all backgrounds to read for pleasure and empowerment.

More information

RPL Policy and Procedures

RPL Policy and Procedures Purpose: CAC provides students with the benefit of Recognition of Prior Learning (RPL) and Credit transfer as a part of the assessment system for gaining prior skill, knowledge and experience credit while

More information

Service Suppliers Engaged in Renewal Survey Examination of Mooring Chain Intended for Mobile Offshore Units

Service Suppliers Engaged in Renewal Survey Examination of Mooring Chain Intended for Mobile Offshore Units pproval of rvc upplrsno. 2.9 STANDARD FOR CERTIFICATION Approval Programmes Approval of Service Suppliers No. 413 Service Suppliers Engaged in Renewal Survey Examination of Mooring Chain Intended for Mobile

More information

The post will involve regular travel across South West Hertfordshire.

The post will involve regular travel across South West Hertfordshire. What we are looking for Watford Mencap is one of the largest Mencap societies in the UK with a long-established history of providing high quality social care services to people with learning disabilities

More information

Qualification Specification. Level 7 NVQ Diploma in STRATEGIC MANAGEMENT AND LEADERSHIP

Qualification Specification.   Level 7 NVQ Diploma in STRATEGIC MANAGEMENT AND LEADERSHIP Level 7 NVQ Diploma in STRATEGIC MANAGEMENT AND LEADERSHIP Qualification Specification Qualification recognition number: 601/3870/1 Qualification Reference: L7NVQDSML www.futurequals.com Level x ######

More information

CANDIDATE INFORMATION BRIEF. Appointment of CEO, Tate Commerce

CANDIDATE INFORMATION BRIEF. Appointment of CEO, Tate Commerce CANDIDATE INFORMATION BRIEF Appointment of CEO, Tate Commerce May 2018 CONTENTS Introduction The role The person Terms of appointment How to apply INTRODUCTION Tate Enterprises Limited is a fully owned

More information

Risk Management Policy and Framework

Risk Management Policy and Framework Risk Management Policy and Framework Introductory Note to User: CompanyLongName There is no requirement in Australia for a non-publicly listed entity (other than a company regulated by APRA) to comply

More information

UNIVERSITY OF LINCOLN JOB DESCRIPTION. PR and Internal Communications Manager

UNIVERSITY OF LINCOLN JOB DESCRIPTION. PR and Internal Communications Manager JOB TITLE DEPARTMENT LOCATION UNIVERSITY OF LINCOLN JOB DESCRIPTION PR and Internal Communications Assistant Communications, Development & Marketing Brayford Pool JOB NUMBER CDM0052 GRADE 4 DATE August

More information

Examples of Organisational Objectives

Examples of Organisational Objectives Examples of Organisational Objectives 1. Essex Policing Plan 1999/2000 Organisational Objectives Boundary Changes In June 1998, the Home Secretary decided to change the boundaries of Essex Police, which

More information

RECORDS MANAGEMENT AND THE ARCHIVING AND RETENTION OF PRIME DOCUMENTS AND BUSINESS RECORDS

RECORDS MANAGEMENT AND THE ARCHIVING AND RETENTION OF PRIME DOCUMENTS AND BUSINESS RECORDS RECORDS MANAGEMENT AND THE ARCHIVING AND RETENTION OF PRIME DOCUMENTS AND BUSINESS RECORDS SUMMARY OF PRINCIPAL CHANGES General changes None Section 7.3 Refer to text (Amendments to version 03.0, UPR IM11,

More information

JOB DESCRIPTION. Data Protection Officer. Policy & Governance. Legal Services. The Burys, Godalming, Surrey, GU7 1HR.

JOB DESCRIPTION. Data Protection Officer. Policy & Governance. Legal Services. The Burys, Godalming, Surrey, GU7 1HR. Waverley is an ambitious authority, committed to being one of the leading Councils in the country at a time of major change by developing a high performing, highly engaged staff team to share the organisation

More information

N.A.P.P.I. (UK) Limited - Course Participant Data Protection Statement

N.A.P.P.I. (UK) Limited - Course Participant Data Protection Statement N.A.P.P.I. (UK) Limited - Course Participant Data Protection Statement In the course of our business we collect, store and process personal information about those people who register for and/or attend

More information

Responsible Sourcing Policy

Responsible Sourcing Policy June 2015 Document Owner Group Procurement Version 5.1 Date of Issue 08 June 2015 Creation Date: June 2015 Page 2 of 13 1 Purpose, Scope & Priorities 1.1 Purpose The purpose of this document is to describe

More information

Retail & Foodservice Sustainability Charter Version 4

Retail & Foodservice Sustainability Charter Version 4 Retail & Foodservice Sustainability Charter 2018 Version 4 1 Introduction Origin Green Retail & Foodservice Sustainability Charter Origin Green, Ireland s National Food & Drink Sustainability Programme,

More information

ENVIRONMENTAL AUDITING GUIDE TD 16/16/E

ENVIRONMENTAL AUDITING GUIDE TD 16/16/E ENVIRONMENTAL AUDITING GUIDE MIDDLE EAST GASES ASSOCIATION (MEGA) European Business Center, Office BC 25 Dubai Investments Park, PO Box: 166 Dubai-UAE Tel: +971-4-8135525 / Fax: +971-4-8135575 / E-mail:

More information

SUCCESS PROFILE TELSTRA BAND 2 INDIVIDUAL CONTRIBUTOR

SUCCESS PROFILE TELSTRA BAND 2 INDIVIDUAL CONTRIBUTOR Business Unit Finance & Strategy Band 2 Work Code PRSVNMSP People Mgr/Ind Contrib IC Direct Expense n/a Generic Role Title Senior Procurement Specialist CAPEX n/a Market Role Title Senior Procurement Specialist

More information

Marketing production and brand manager

Marketing production and brand manager Role brief Marketing production and brand manager Directorate Marketing and communications directorate Base location Bristol Grade C 16 Reports to Head of marketing production 1. Background This is a new

More information

Adult Community Learning Essex. Subcontracting, Supply-chain Fees and Charges Policy 2018/19

Adult Community Learning Essex. Subcontracting, Supply-chain Fees and Charges Policy 2018/19 Adult Community Learning Essex Subcontracting, Supply-chain Fees and Charges Policy 2018/19 Control of Document: ACL Senior Management Team (SMT) Responsibility Group: ACL Senior Management Team (SMT)

More information

Because good people make a great business

Because good people make a great business Because good people make a great business A guide to Investors in People accreditation and assessment Realise your people potential A guide to Investors in People Organisations succeed by realising the

More information

NEPCon Impartiality Policy

NEPCon Impartiality Policy NEPCon Impartiality Policy NEPCon Policies 21 December 2016 2011 NEPCon Impartiality Policy 2 The purpose of this policy is to describe how NEPCon ensures independence, impartiality and transparency in

More information

Qualification Specification. Level 2 Award in INFORMATION, ADVICE OR GUIDANCE

Qualification Specification.  Level 2 Award in INFORMATION, ADVICE OR GUIDANCE Level 2 Award in INFORMATION, ADVICE OR GUIDANCE Qualification Specification Qualification recognition number: 601/5079/8 Qualification Reference: L2AIAG www.futurequals.com Level x ###### in /for QUALIFICATION

More information

How to assess the maturity of Identity Management

How to assess the maturity of Identity Management IT ADVISORY How to assess the maturity of Identity Management Marko Vogel 23.04.2008 ADVISORY 1 Agenda 1 KPMG s view on IAM 2 KPMG s IAM Maturity Assessment 3 Assessment Results 4 Next steps 2 Agenda 1

More information

The Keeping Research Data Safe (KRDS) Benefits Framework is a tool for identifying,

The Keeping Research Data Safe (KRDS) Benefits Framework is a tool for identifying, 1. INTRODUCTION The Keeping Research Data Safe (KRDS) Benefits Framework is a tool for identifying, assessing, and communicating the benefits from investing resources in the curation/longterm preservation

More information

Appendix 6 Risk Maturity Models

Appendix 6 Risk Maturity Models Simple Tools and Techniques for Enterprise Risk Management, Second Edition by Robert J. Chapman Copyright 2011, John Wiley & Sons, Ltd. Appendix 6 Risk Maturity Models This appendix should be read in conjunction

More information

SENIOR PROJECT MANAGER VENICE VISUAL ARTS AND ARCHITECTURE DESIGN FASHION

SENIOR PROJECT MANAGER VENICE VISUAL ARTS AND ARCHITECTURE DESIGN FASHION . SENIOR PROJECT MANAGER VENICE VISUAL ARTS AND ARCHITECTURE DESIGN FASHION This role leads and manages the delivery of the Venice International Art and Architecture Biennale exhibitions at the British

More information

End Point Assessment Plan Aerospace Engineer Standard

End Point Assessment Plan Aerospace Engineer Standard End Point Assessment Plan Aerospace Engineer Standard Table of Contents Page FOREWORD 4 SECTION A - Summary of assessment 5-6 A1 Diagram 1: End Point Assessment for an Aerospace Engineer 5 A2 Diagram 2:

More information

Fast Track Programme for Serving Constables

Fast Track Programme for Serving Constables Fast Track Programme for Serving Constables High Potential Development Tool Candidate Pack 2015 College of Policing Limited Leamington Road Ryton-on-Dunsmore Coventry, CV8 3EN Publication date: September

More information

NHS DIGITAL Records and Document Management Policy

NHS DIGITAL Records and Document Management Policy Status Document Record ID Key Version Director Responsible for this policy Final v2.0 Version Date 10/04/2018 Catherine O Keeffe, Director of Information Governance, Burden and Audit Person to contact

More information

Documentation planning

Documentation planning Documentation planning PRIMARY PROCEDURE Definition Making your documentation systems better and enhancing the information they contain as an ongoing process of continual improvement. Scope This procedure

More information

Records Management Policy

Records Management Policy Records Management Policy November 2013 Page 1 of 12 Policy Title: Records Management Policy Reference Number: CORP 08/003 Original Implementation Date: June 2011 Reviewed: November 2013 Next Review Date:

More information

Forensics Collision Investigator Role Profile

Forensics Collision Investigator Role Profile Forensics Collision Investigator Role Profile Scale Line Manager Department Constable Senior Forensics Collision Investigator Forensics Services Department To attend collision scenes as a practising collision

More information

SOIL ASSOCIATION CERTIFICATION INTERNATIONAL GROUP FOREST MANAGEMENT CERTIFICATION PROCEDURES

SOIL ASSOCIATION CERTIFICATION INTERNATIONAL GROUP FOREST MANAGEMENT CERTIFICATION PROCEDURES FSC A000525 PEFC/16-44-917 SOIL ASSOCIATION CERTIFICATION INTERNATIONAL GROUP FOREST MANAGEMENT CERTIFICATION PROCEDURES Procedures for International Group Forest Management Certification 1. Enquiry When

More information

CUSTOMER RELATIONSHIPS FURTHER EXCELLENCE GENERIC STANDARDS TRAINING SERVICES THE ROUTE TO ISO 9001:2015 AVOIDING THE PITFALLS

CUSTOMER RELATIONSHIPS FURTHER EXCELLENCE GENERIC STANDARDS TRAINING SERVICES THE ROUTE TO ISO 9001:2015 AVOIDING THE PITFALLS PROCESSES SUPPLY CHAIN SKILLED TALENT CUSTOMER RELATIONSHIPS FURTHER EXCELLENCE GENERIC STANDARDS INDUSTRY STANDARDS CUSTOMISED SOLUTIONS TRAINING SERVICES THE ROUTE TO ISO 9001:2015 FOREWORD The purpose

More information

Privacy Impact Assessment Policy and Procedure

Privacy Impact Assessment Policy and Procedure Privacy Impact Assessment Policy and Procedure This document outlines the Trust s approach and methodology for conducting Privacy Impact Assessments in line with the Information Risk Policy Key Words:

More information

ROLE DESCRIPTION. VISION To make Sydney and NSW one of the world s most successful tourism and events destinations.

ROLE DESCRIPTION. VISION To make Sydney and NSW one of the world s most successful tourism and events destinations. ROLE DESCRIPTION Title: Senior Publicist Sports and Lifestyle Division: Communications Location: Sydney, Australia Grade Equivalent: Grade 9/10 Kind of Employment: Ongoing ANZSCO Code: Date of Approval:

More information

General Data Protection Regulation (GDPR) Frequently Asked Questions

General Data Protection Regulation (GDPR) Frequently Asked Questions General Data Protection Regulation (GDPR) Frequently Asked Questions 26 March 2018 0 Contents Introduction... 3 What is GDPR?... 3 Who does the GDPR apply to?... 3 Are tax advisers data controllers or

More information

Supports and coaches more than 150 IT Staff in change, release and problem management activities.

Supports and coaches more than 150 IT Staff in change, release and problem management activities. Job Title: Change, Release and Problem Manager Grade: 8 Salary: 43,267 to 48,677 per annum Department: IT Services Hours/Contract: Full Time and Permanent Reference: 660 Role Purpose The Change, Release

More information

FIELDWORK POLICY STANDARD & PROCEDURES FIELDWORK

FIELDWORK POLICY STANDARD & PROCEDURES FIELDWORK POLICY STANDARD & PROCEDURES This Policy Standard states the requirements placed on the University and its Colleges with regards to the management of fieldwork for teaching and research purposes. The Policy

More information

A Guide to Clinical Coding Audit Best Practice Version 8.0

A Guide to Clinical Coding Audit Best Practice Version 8.0 A Guide to Clinical Coding Audit Best Practice Version 8.0 Copyright 2017 Health and Social Care Information Centre Page 1 of 17 The Health and Social Care Information Centre is a non-departmental body

More information

Year Two: Choose Cape Fear. January 22, 2017

Year Two: Choose Cape Fear. January 22, 2017 Year Two: Choose Cape Fear January 22, 2017 What s the goal? Generate long-term interest, investment and impact in the Cape Fear region. Prime potential audiences and create fertile ground for all economic

More information

AMENDMENTS EN United in diversity EN. European Parliament Draft opinion Angel Dzhambazki (PE v01-00)

AMENDMENTS EN United in diversity EN. European Parliament Draft opinion Angel Dzhambazki (PE v01-00) European Parliament 2014-2019 Committee on Culture and Education 2017/2024(INL) 18.7.2017 AMDMTS 1-43 Angel Dzhambazki (PE606.216v01-00) Revision of Regulation (EU) 211/2011 on the citizens initiative

More information

Director of Finance & Operations

Director of Finance & Operations Director of Finance & Operations Appointment Brief March 2018 1 Thank you for your interest in the role of Director of Finance & Operations at the Geological Society. We are looking for an experienced

More information