NHS Digital Audit of Data Sharing Activities: Derby Teaching Hospitals NHS Foundation Trust - Renal Department

Size: px
Start display at page:

Download "NHS Digital Audit of Data Sharing Activities: Derby Teaching Hospitals NHS Foundation Trust - Renal Department"

Transcription

1 Directorate / Programme Care Services Project Data Sharing Audits Status Approved Director Catherine O Keeffe Version 1.0 Owner Sean Walsh Version issue date 13/10/2017 NHS Digital Audit of Data Sharing Activities: Derby Teaching Hospitals NHS Foundation Trust - Renal Department Copyright 2017 Health and Social Care Information Centre Page 1 of 6 The Health and Social Care Information Centre is a non-departmental body created by statute, also known as NHS Digital.

2 NHS Digital Audit of Data Sharing Activities: Derby Teaching Hospitals NHS Foundation Trust - Renal Department v1.0 Approved 13/10/ Audit Summary 1.1 Purpose This document records the key findings of a data sharing audit at Derby Teaching Hospitals NHS Foundation Trust (DTHFT) - Renal Department on 4 and 5 September It provides an evaluation of how DTHFT conforms to the requirements of the data sharing framework contract (DSFC) CON H5X7Z and the data sharing agreement (DSA) NIC X6Y6N with respect to the provision of: Extract Type Dataset Identifiability and Sensitivity Periods Hospital Episode Statistics (HES) Data Interrogation System (HDIS) system access All HES datasets Pseudonymised, anonymised and nonsensitive HES datasets from 1989 to 2017 It should be noted that data accessed through the HDIS system is pseudonymised, nonsensitive and record level. Data extracted from HDIS is limited to aggregate data only. The report also considers whether DTHFT conforms to its own policies and procedures. This is an exception report based on the criteria expressed in the NHS Digital Audit Guide. 1.2 Scope and Assurance Statement The audit considered the fitness for purpose of the main processes with respect to data handling at DTHFT along with its associated documentation against the scope areas shown in Table 1. Whilst DTHFT identified intended uses for the data as stated within the DSA, DTHFT have no outputs to show against the current DSA, which commenced on 1 July However the Audit Team was shown reports that were produced prior to 1 July 2017 using data provided under the previous DSA. Therefore, Data Use and Benefits is assessed using outputs from the previous DSA. The NHS Digital Audit Team has assigned the following assurance ratings to these areas based upon the findings of the audit. Information Transfer Data Use and Benefits Risk Management Operational Management and Control Data Destruction Limited assurance Substantial assurance Table 1: Scope and Assurance rating Detailed findings related to the areas of scope are detailed in Table 2. Copyright 2017 Health and Social Care Information Centre Page 2 of 6

3 NHS Digital Audit of Data Sharing Activities: Derby Teaching Hospitals NHS Foundation Trust - Renal Department v1.0 Approved 13/10/ Overall Risk Statement It is the Audit Team s opinion that based on evidence presented during the audit and the type of data being shared, there is medium risk of a breach of information security, duties of care, confidentiality or integrity (including inappropriate access to or loss of data) provided by NHS Digital to DTHFT under the terms and conditions of the data sharing agreements signed by both parties. 1.4 Response DTHFT has reviewed this report and confirmed that it is accurate. DTHFT will establish a corrective action plan to address each finding shown in Table 2. NHS Digital will validate this plan and the resultant actions at a post audit review with DTHFT to confirm the findings have been satisfactorily addressed. The post audit review will also consider the outstanding evidence at which point the Audit Team may raise further nonconformities/observations. Copyright 2017 Health and Social Care Information Centre Page 3 of 6

4 NHS Digital Audit of Data Sharing Activities: Derby Teaching Hospitals NHS Foundation Trust - Renal Department v1.0 Approved 13/10/ Findings Table 2 identifies one major nonconformity, three minor nonconformities, seven observations and one item for follow up were raised as part of the audit. In addressing a finding the data recipient must take account of any referenced supplementary notes. Ref Comments Link to Area Clause Designation Notes 1. The Audit Team identified weaknesses in certain physical access controls where NHS Digital data is held. DSFC, Schedule 2, Section A, Clause Access controls are not suitably reflected in Active Directory group policies. DSFC, Schedule 2, Section A, Clause User accounts with privilege access are not reviewed on a quarterly basis as required by the IT Security Policy. There is also no monitoring of these accounts even though the data is logged. 4. The Audit Team checked a sample of machines to ensure that Microsoft Windows patches and antivirus definition files were up to date, in line with the DSFC. The Audit Team identified one laptop in the sample, which had not received windows security updates since January This omission is being investigated by the Trust IT Team. It should be noted that this laptop was not being used to download or access NHS Digital data. 5. The Audit Team was informed that DTHFT intended to analyse the NHS Digital data on a personal laptop (Apple Mac) using SPSS statistics software installed on that device. The Trust s Bring Your Own Device (BYOD) policy does not support non-trust laptops. It should be noted that DTHFT confirmed that no data had been stored on this laptop provided under this DSA. IT Security policy, Section 5.2 DSFC, Schedule 2, Section A, Clause 1.1 Major Minor Minor Minor Copyright 2017 Health and Social Care Information Centre Page 4 of 6

5 NHS Digital Audit of Data Sharing Activities: Derby Teaching Hospitals NHS Foundation Trust - Renal Department v1.0 Approved 13/10/2017 Ref Comments Link to Area Clause Designation Notes 6. Advice should be sought from the Data Access Request Service (DARS) team prior to deletion of NHS Digital data, to ensure compliance with DARS guidance on data destruction. Data Destruction DSFC, Schedule 2, Section B, 5.5 The Audit Team noted that backup tapes are held indefinitely. This will not meet NHS Digital s requirement for permanent data destruction, as a footprint of the data will always to available even though data on the network file storage has been deleted. Again, advice should be sought from the DARS team on the way forward. 7. The Trust has a process for pushing out software patches and for hardware disposal however these processes have not been documented. 8. Additional access controls could be implemented on the desktop PC used to download and access NHS Digital data. 9. The IG team maintain an Information Asset Register (IAR) that includes systems and processes however it does not capture dataset assets. The Audit Team suggested that an additional sheet is added to the IAR which includes datasets received from NHS Digital. Recording of NHS Digital datasets could also be used as a trigger for a Privacy Impact Assessment (PIA) and risk assessment to be completed. Operational Management The PIA process is being further developed to ensure compliance with the General Data Protection Regulation (GDPR). Additional guidance on the IAR can be found on the IGT requirement The serial numbers of Hard Disk Drives (HDD) are not logged prior to disposal. As a result, there is no reconciliation between the serial numbers of HDDs and the third-party contractor s data destruction certificates in order to account for all the devices. It should be noted that the destruction of HDDs takes place onsite. Data Destruction 11. A checklist should be developed to review compliance with the DSA and DSFC prior to publication of a paper in the public domain. Operational Management 12. The Audit Team is to review the following evidence at the post audit review: USB asset register and future internal audit schedule. Operational Management Follow Up Table 2: Nonconformities, s and Point for follow-up Copyright 2017 Health and Social Care Information Centre Page 5 of 6

6 NHS Digital Audit of Data Sharing Activities: Derby Teaching Hospitals NHS Foundation Trust - Renal Department v1.0 Approved 13/10/ Supplementary Notes None 2.2 Data Location DTHFT confirmed that processing and storage, including disaster recovery and backups, of the data was limited to the location shown in Table 3. Data Location England 2.3 Backup Retention Table 3: Data Location The duration for which data may be retained on backup media is shown in Table Good Practice Backup retention Indefinite (see finding 6 in Table 2) Table 4: Data Retention Period In addition to the findings presented in Table 2 the Audit Team noted the following areas of good practice: The Project Lead was able to explain the direct benefits to health and social care from the use of NHS Digital data. It should be noted that a number of reports were shown to the Audit Team, which were produced using HES data provided under a previous DSA. The current DSA had only been in place since 1 July 2017 and no finalised output had been produced at the time of the onsite audit. 2.5 Disclaimer NHS Digital has prepared this audit report for its own purposes. As a result, NHS Digital does not assume any liability to any person or organisation for any loss or damage suffered or costs incurred by it arising out of, or in connection with, this report, however such loss or damage is caused. NHS Digital does not assume liability for any loss occasioned to any person or organisation acting or refraining from acting as a result of any information contained in this report. Copyright 2017 Health and Social Care Information Centre Page 6 of 6

NHS Digital Post Audit Review of Data Sharing Activities: University College London

NHS Digital Post Audit Review of Data Sharing Activities: University College London Directorate / Programme Care Services Project Data Sharing Audits Status Approved Director Catherine O Keeffe Version 1.0 Owner Sean Walsh Version issue date 13/10/2017 NHS Digital Post Audit Review of

More information

HSCIC Audit of Data Sharing Activities:

HSCIC Audit of Data Sharing Activities: Directorate / Programme Data Dissemination Services Project Data Sharing Audits Status Approved Director Terry Hill Version 1.0 Owner Rob Shaw Version issue date 20/04/2016 HSCIC Audit of Data Sharing

More information

HSCIC Audit of Data Sharing Activities:

HSCIC Audit of Data Sharing Activities: Directorate / Programme Data Dissemination Services Project Data Sharing Audits Status Approved Director Terry Hill Version 1.0 Owner Rob Shaw Version issue date 20/04/2016 HSCIC Audit of Data Sharing

More information

Harbinger Escrow Services Backup and Archiving Policy. Document version: 2.8. Harbinger Group Pty Limited Delivered on: 18 March 2015

Harbinger Escrow Services Backup and Archiving Policy. Document version: 2.8. Harbinger Group Pty Limited Delivered on: 18 March 2015 Document version: 2.8 Issued to: Harbinger Escrow Services Issued by: Harbinger Group Pty Limited Delivered on: 18 March 2015 Harbinger Group Pty Limited, Commercial in Confidence Table of Contents 1 Introduction...

More information

Information Governance Policy and Management Framework

Information Governance Policy and Management Framework Putting Barnsley People First Information Governance Policy and Management Framework Version: 2.0 Approved By: Governing Body Date Approved: February 2014 Name of originator / author: Richard Walker Name

More information

Guidelines for Information Asset Management: Roles and Responsibilities

Guidelines for Information Asset Management: Roles and Responsibilities Guidelines for Information Asset Management: Roles and Responsibilities Document Version: 1.0 Document Classification: Public Published Date: April 2017 P a g e 1 Contents 1. Overview:... 3 2. Audience...

More information

Humber Information Sharing Charter

Humber Information Sharing Charter External Ref: HIG 01 Review date November 2016 Version No. V07 Internal Ref: NELC 16.60.01 Humber Information Sharing Charter This Charter may be an uncontrolled copy, please check the source of this document

More information

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry GDPR Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry Who are we? Dillistone Group Plc, a public company listed on the AIM market of the London stock

More information

East Riding of Yorkshire Council Data protection audit report. Executive summary March 2014

East Riding of Yorkshire Council Data protection audit report. Executive summary March 2014 East Riding of Yorkshire Council Data protection audit report Executive summary March 2014 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with the Data

More information

Data protection (GDPR) policy

Data protection (GDPR) policy Data protection (GDPR) policy January 2018 Version: 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment 1.0 Trevor Duplessis 22/01/18 Review due Dec 2018 OFFICIAL

More information

ASSET MANAGEMENT TOWARDS ISO/IEC 27001:2005 ACCREDITATION OF AN INFORMATION SECURITY MANAGEMENT SYSTEM

ASSET MANAGEMENT TOWARDS ISO/IEC 27001:2005 ACCREDITATION OF AN INFORMATION SECURITY MANAGEMENT SYSTEM ASSET MANAGEMENT TOWARDS ISO/IEC 27001:2005 ACCREDITATION OF AN INFORMATION SECURITY MANAGEMENT SYSTEM Daniel COSTIN Constantin MILITARU Politehnica University of Bucharest, Romania ABSTRACT Currently,

More information

IG01 Information Governance Management Framework

IG01 Information Governance Management Framework IG01 Information Governance Management Framework 1 INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History Document Reference: IG01 Document Purpose: The document compliments all other Information

More information

External Supplier Control Obligations. Information Security

External Supplier Control Obligations. Information Security External Supplier Control Obligations Information Security Version 7.0 December 2016 Control Area / Title Control Description Why this is important Roles and Responsibilities The Supplier must define and

More information

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN INFORMATION GOVERNANCE STRATEGY & IMPLEMENTATION PLAN 2015-2018 Disclaimer The latest version of this document is located on PTHB intranet. Please check the review date and if there are any doubts contact

More information

Assessment Report. PSU Technology Group Limited

Assessment Report. PSU Technology Group Limited PSU Technology Group Limited Page 1 of 10 Introduction. This report has been compiled by Nigel Beedles and relates to the assessment activity detailed below: Visit ref/type/date/duration Certificate/Standard

More information

Minor adjustments from IG Steering Group 0.3 Neil Taylor September 2013

Minor adjustments from IG Steering Group 0.3 Neil Taylor September 2013 Author(s) Andrew Thomas Version 0.3 Version Date 21 August 2013 Implementation/approval Date Review Date August 2014 Review Body Governing Body Policy Reference Number 014 Version Author Date Reason for

More information

1. Each employee is responsible for managing college records in a responsible and professional manner.

1. Each employee is responsible for managing college records in a responsible and professional manner. Policy O-6.2 Approved By: College Executive Team Approval Date: February 26, 2003 Amendment Date: November 25, 2009 Policy Holder: VP Administration Purpose / Rationale RECORD MANAGEMENT The purpose of

More information

DATA QUALITY POLICY. Version: 1.2. Management and Caldicott Committee. Date approved: 02 February Governance Lead

DATA QUALITY POLICY. Version: 1.2. Management and Caldicott Committee. Date approved: 02 February Governance Lead DATA QUALITY POLICY Version: 1.2 Approved by: Date approved: 02 February 2016 Name of Originator/Author: Name of Responsible Committee/Individual: Information Governance, Records Management and Caldicott

More information

IGPr002 - Information Governance Management Framework

IGPr002 - Information Governance Management Framework IGPr002 - Information Governance Management Framework Page 1 of 10 Table of Contents Information Governance Management Framework... 1 Why we need this Framework... 3 What the Framework is trying to do...

More information

DATA QUALITY POLICY Review Date: CONTENT

DATA QUALITY POLICY Review Date: CONTENT Title: Date Approved: Approved by: DATA QUALITY POLICY Review Date: Policy Ref: Issue: Jan 2010 Sherwood Forest Hospitals Oct 2011 Information Governance Group Division/Department: Policy Category: ISP_03

More information

Information Governance Assurance Framework

Information Governance Assurance Framework Document Reference POL008 Document Status Approved Version: V4.0 DOCUMENT CHANGE HISTORY Initiated by Date Author IG Toolkit Requirements November 2010 IG Manager Version Date Comments (i.e. viewed, or

More information

A Guide to Clinical Coding Audit Best Practice Version 8.0

A Guide to Clinical Coding Audit Best Practice Version 8.0 A Guide to Clinical Coding Audit Best Practice Version 8.0 Copyright 2017 Health and Social Care Information Centre Page 1 of 17 The Health and Social Care Information Centre is a non-departmental body

More information

DISASTER PREPAREDNESS Guide & Template

DISASTER PREPAREDNESS Guide & Template Go Beyond The Cloud STEP-BY-STEP DISASTER PREPAREDNESS Guide & Template WHITEPAPER BY XVAND TECHNOLOGY CORPORATION Xvand Technology Corporation 832.204.4909 questions@xvand.com www.isutility.com Disaster

More information

Rule Business Function Retention Rule Title Retention Period Description

Rule Business Function Retention Rule Title Retention Period Description Rule Business Function Retention Rule Title Retention Period Description AC10-C Accounting General Accounting Records Keep official records for the current year + 10 years. AC11-C Accounting Accounts Payable

More information

"Charting the Course... MOC C Administering System Center Configuration Manager and Intune. Course Summary

Charting the Course... MOC C Administering System Center Configuration Manager and Intune. Course Summary Description Course Summary Get expert instruction and hands-on practice configuring and managing clients and devices by using Microsoft System Center v1511, Microsoft Intune, and their associated site

More information

Information Governance Strategic Management Framework

Information Governance Strategic Management Framework Information Governance Strategic Management Framework 2016-2018 Susan Meakin Information Governance Manager June 2016 Information Governance DOCUMENT CONTROL: Version: 2 Ratified by: Health Informatics

More information

Secure File Sharing and Collaboration

Secure File Sharing and Collaboration Secure File Sharing and Collaboration Contents 1 Secure File Sharing & Collaboration...2 2 Service Definition...3 2.1 Functionality & Features File Sharing and Collaboration... 3 2.2 Access Methods...

More information

Information Asset Management Procedure

Information Asset Management Procedure Procedure Number: IG02 Version: 2.0 Approved by: Information Governance Working Group Date approved: July 2016 Ratified by: Audit and Risk Committee Date ratified: September 2016 Name of originator/author:

More information

Sensitive Data Retention and Destruction Policy

Sensitive Data Retention and Destruction Policy Sensitive Data Retention and Destruction Policy Institutional Policy Title: Sensitive Data Retention and Destruction Policy Responsible Officer: Director, Research Informatics Effective Date: Revised Date:

More information

Information Governance Strategy and Management Framework

Information Governance Strategy and Management Framework Information Governance Strategy and Management Framework Summary: This strategy sets out the framework, structure, system and accountabilities for Information Governance Management within NHS Eastbourne,

More information

INS QA Programme Requirements

INS QA Programme Requirements Specification Date: 20/3/17 INS QA Programme Requirements UNCONTROLLED WHEN PRINTED Author: J Cooch AUTHORISATION Date: 20/3/17 A Brown Owner: J Cooch (Signature) N.B. only required for hard copy If issued

More information

GOVERNANCE AES 2012 INFORMATION TECHNOLOGY GENERAL COMPUTING CONTROLS (ITGC) CATALOG. Aut. / Man. Control ID # Key SOX Control. Prev. / Det.

GOVERNANCE AES 2012 INFORMATION TECHNOLOGY GENERAL COMPUTING CONTROLS (ITGC) CATALOG. Aut. / Man. Control ID # Key SOX Control. Prev. / Det. GOVERNANCE 8.A.1 - Objective: Information Technology strategies, plans, personnel and budgets are consistent with AES' business and strategic requirements and goals. Objective Risk Statement(s): - IT Projects,

More information

RECORDS MANAGEMENT POLICY

RECORDS MANAGEMENT POLICY RECORDS MANAGEMENT POLICY PURPOSE The purpose of this policy is to: Assist departments in effective utilization of space and efficient information retrieval; Establish guidelines for disposal of records;

More information

Draft Internal Audit Plan for Institute of Technology Blanchardstown 2017

Draft Internal Audit Plan for Institute of Technology Blanchardstown 2017 Draft Internal Audit Plan for Institute of Technology Blanchardstown 2017 Contents 1. Introduction and Approach 4 2. Principal Risks 5 3. Proposed areas of focus for Internal Audit 6 4. Draft Internal

More information

Data Quality Policy

Data Quality Policy Cambridgeshire and Peterborough Clinical Commissioning Group (CCG) Data Quality Policy 2017-2019 Ratification Process Lead Author(s): Reviewed / Developed by: Approved by: Ratified by: Associate Director

More information

Xpert MTB/RIF test. Laboratory monitoring & evaluation tool Xpert Pre-handover Checklist

Xpert MTB/RIF test. Laboratory monitoring & evaluation tool Xpert Pre-handover Checklist Xpert Pre-handover Checklist Part 1: Contact details Date of installation Facility name/ Laboratory name Contact details facility: Name, phone, email GeneXpert laboratory responsible Contact details Laboratory:

More information

Level 2 ICT Systems monitoring and operation ( )

Level 2 ICT Systems monitoring and operation ( ) Level 2 ICT Systems monitoring and operation (7450-232) Systems and Principles (QCF) Assignment guide for Candidates Assignment D www.cityandguilds.com January 2011 Version 3.0 About City & Guilds City

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY LEEDS BECKETT U NIVERSI T Y DATA PROTECTION POLICY 1. INTRODUCTION 1.1 This policy document explains the framework through which the University ensures compliance with the Data Protection Act 1998 (DPA).

More information

Honorary Contracts Procedure

Honorary Contracts Procedure Honorary Contracts Procedure Version: 3.0 Bodies consulted: Approved by: Joint Staff Consultative Committee & WMT Executive Management Team Date Approved: 03 October 2017 Lead Manager: Responsible Director:

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK NHS South West Lincolnshire Clinical Commissioning Group (CCG) INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History: Document Reference: Document Purpose: IG01 Date Ratified: January 2015 Ratified

More information

Sandwell HR Services Information regarding requirements for Disclosure & Barring Checks and the Single Central Record

Sandwell HR Services Information regarding requirements for Disclosure & Barring Checks and the Single Central Record Sandwell HR Services Information regarding requirements for Disclosure & Barring Checks and the Single Central Record HR Services January 2014 (Updated May 2014) Contents Page Introduction 3 Single Central

More information

NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY

NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY Version Control Version: 2.0 dated 17 July 2015 DATE VERSION CONTROL 04/06/2013 1.0 First draft of new policy

More information

Standard Statement and Purpose

Standard Statement and Purpose Personnel Security Standard Responsible Office: Technology Services Initial Standard Approved: 10/23/2017 Current Revision Approved: 10/23/2017 Standard Statement and Purpose Security of information relies

More information

CHAPTER 5 INFORMATION TECHNOLOGY SERVICES CONTROLS

CHAPTER 5 INFORMATION TECHNOLOGY SERVICES CONTROLS 5-1 CHAPTER 5 INFORMATION TECHNOLOGY SERVICES CONTROLS INTRODUCTION In accordance with Statements on Auditing Standards Numbers 78 and 94, issued by the American Institute of Certified Public Accountants

More information

Supply Chain. Example Policy. Author: A Heathcote Date: 24/05/2017 Version: 1.0

Supply Chain. Example Policy. Author: A Heathcote Date: 24/05/2017 Version: 1.0 Example Policy Author: A Heathcote Date: 24/05/2017 Version: 1.0 Copyright 2017 Health and Social Care Information Centre. The Health and Social Care Information Centre is a non-departmental body created

More information

Acronis ACRONIS ACCESS ADVANCED

Acronis ACRONIS ACCESS ADVANCED Acronis 2002-2014 ACRONIS ACCESS ADVANCED The proliferation of mobile devices into the enterprise is deeply impacting how people go about accomplishing their daily jobs. Mobile devices can t do everything

More information

Records Management Officer (Sharepoint) Job Description

Records Management Officer (Sharepoint) Job Description Records Management Officer (Sharepoint) Job Description Responsible to: ccountable to: Records Manager Director of Student and cademic Services Overall Purpose To assist the Records Manager to take forward

More information

GDPR: Is it just another strict regulation or a great opportunity for operational excellence?

GDPR: Is it just another strict regulation or a great opportunity for operational excellence? GDPR: Is it just another strict regulation or a great opportunity for operational excellence? Xenofon Liapakis General manager CIO & Services of Interamerican group Chairman of Hellenic CIO forum November

More information

REPORT 2014/115 INTERNAL AUDIT DIVISION. Audit of information and communications technology management at the United Nations Office at Geneva

REPORT 2014/115 INTERNAL AUDIT DIVISION. Audit of information and communications technology management at the United Nations Office at Geneva INTERNAL AUDIT DIVISION REPORT 2014/115 Audit of information and communications technology management at the United Nations Office at Geneva Overall results relating to the effective and efficient management

More information

IT Hardware and Software - Procurement of Hardware and Software Procedure

IT Hardware and Software - Procurement of Hardware and Software Procedure IT Hardware and Software - Procurement of Hardware and Software Procedure Section 1 - Purpose / Objectives (1) The purpose of this procedure is to ensure all IT equipment and software at Victoria University

More information

ediscovery at the University of Michigan

ediscovery at the University of Michigan Guideline number: Title DM-08 ediscovery at the University of Michigan Date issued: August 10, 2010 Date last reviewed: February 13, 2017 Version number: 3.0 Approval authority: Responsible office: Vice

More information

Information Technology. Classification Band 5. Position Objective

Information Technology. Classification Band 5. Position Objective Team Information Technology Classification Band 5 Position Objective Key Responsibilities Provide support in a predominately Microsoft Windows environment, working to agreed service targets. Proactively

More information

How to sell Azure to SMB customers. Paul Bowkett Microsoft NZ

How to sell Azure to SMB customers. Paul Bowkett Microsoft NZ How to sell Azure to SMB customers Paul Bowkett Microsoft NZ CLOUD INFRASTRUCTURE DEVELOPER + APP PLATFORM Visual Studio Family + Azure App Service DATA + ANALYTICS Cortana Analytics Suite INTERNET OF

More information

5-Step Guide For GDPR Compliance

5-Step Guide For GDPR Compliance 5-Step Guide For GDPR Compliance A Guide For Constructing Your Planning Timeline www.avr.co.uk This document provides a framework for all companies that have customers in Europe, as they have to prepare

More information

DSU Tech Manager Recruitment Pack.

DSU Tech Manager Recruitment Pack. DSU Tech Manager Recruitment Pack www.demontfortstudents/jobs Re : DSU Tech Manager Thank you for your interest in the role of DSU Tech Manager at De Montfort University Students Union. Please find contained

More information

ICT and Computing Curriculum leader, Business Manager and ultimately the Headteacher

ICT and Computing Curriculum leader, Business Manager and ultimately the Headteacher Job Profile: Responsible for: Responsible to: Location: Hours: Senior ICT Technician Providing ICT hardware and software support for the school and maintaining the standards of the school s ICT resource

More information

Information Governance and Records Management Policy March 2014

Information Governance and Records Management Policy March 2014 Information Governance and Records Management Policy March 2014 Approving authority: Secretary s Board Consultation via: Secretary's Board Information Governance and Security Group Approval date: 4 March

More information

IT Administration including SIMS Support

IT Administration including SIMS Support IT Administration including SIMS Support Service Level Agreement www.eisit.uk info@eisit.uk Tel: 0300 065 8800 Fax: 01622 663591 EIS The Shepway Centre, Oxford Road, Maidstone, Kent, ME15 8AW Contents

More information

SapphireIMS 4.0 ITAM Suite Feature Specification

SapphireIMS 4.0 ITAM Suite Feature Specification SapphireIMS 4.0 ITAM Suite Feature Specification Overview Organizations are realizing significant cost savings and improved planning capabilities through integration of the entire asset lifecycle. Strong

More information

PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE

PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE Reference No: IG40 Version: 1.2 Purpose of Document: Ratified by: Date ratified: 27 th September 2013 Review Date September 2014 Name of originator/author: Contact

More information

Information Governance Management Framework Version 6 December 2017

Information Governance Management Framework Version 6 December 2017 Information Governance Management Framework Version 6 December 2017 Page 1 of 8 Introduction Robust information governance requires clear and effective management and accountability structures, governance

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History Document Reference: IG33 Document Purpose: The document complements all other Information Governance policies and sets out the management arrangements

More information

ANNEX 2 Security Management Plan

ANNEX 2 Security Management Plan ANNEX 2 Page 1 of 24 The following pages define our draft security management plan (a complete and up to date shall be submitted to The Authority within 20 days of contract award as per Schedule 2.4, para

More information

Data Protection Strategy Version 1.0

Data Protection Strategy Version 1.0 Data Protection Strategy Version 1.0 Contents 1. Introduction... 4 1.1. Purpose... 4 1.2. The OpenLV Project... 4 1.3. Definition of Personal Data... 6 1.4. The Data Controller... 6 1.5. Document Structure...

More information

Records management policy. Document author Assured by Review cycle. Audit and Risk Committee. 1. Introduction Purpose or aim Scope...

Records management policy. Document author Assured by Review cycle. Audit and Risk Committee. 1. Introduction Purpose or aim Scope... Records management policy Board library reference Document author Assured by Review cycle P017 Head of Compliance Audit and Risk Committee 3 Years This document is version controlled. The master copy is

More information

Internal Control and the Computerised Information System (CIS) Environment. CA A. Rafeq, FCA

Internal Control and the Computerised Information System (CIS) Environment. CA A. Rafeq, FCA Internal Control and the Computerised Information System (CIS) Environment CA A. Rafeq, FCA 1 Agenda 1. Internal Controls and CIS Environment 2. Planning audit of CIS environment 3. Design and procedural

More information

Technical Services Document #: TS-0007 Internal Audit Procedure Version #: 01

Technical Services Document #: TS-0007 Internal Audit Procedure Version #: 01 1. Purpose The purpose of this procedure is to define the process used to manage the Internal Audits of the Quality Management System for Technical Services. 2. Scope This procedure applies to all Internal

More information

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting xada@gedapre.eu tel 0475-41.03.22 xavier.darmstaedter@dacota.eu Gent, 3 October 2017 4 facts 1. We are not really in control of our personal

More information

DRAFT ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security management system implementation guidance

DRAFT ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security management system implementation guidance INTERNATIONAL STANDARD ISO/IEC 27003 First edition 2010-02-01 Information technology Security techniques Information security management system implementation guidance Technologies de l'information Techniques

More information

PRINCE2 - Quality Management Strategy

PRINCE2 - Quality Management Strategy Created/updated 05/11/17 PRINCE2 - Quality Management Strategy Downloaded from stakeholdermap.com. Visit Prince2 Templates for more Prince2 downloads. Get a Mind Map Quality Management Strategy template

More information

Policy Outsourcing and Cloud-Based File Sharing

Policy Outsourcing and Cloud-Based File Sharing Policy Outsourcing and Cloud-Based File Sharing Version 3.3 Table of Contents Outsourcing and Cloud-Based File Sharing Policy... 2 Outsourcing Cloud-Based File Sharing Management Standard... 2 Overview...

More information

Records Management Plan

Records Management Plan Records Management Plan October 2014 1 2 Document control Title The Scottish Funding Council Records Management Plan Prepared by Information Management and Security Officer Approved internally by Martin

More information

Service Option Attachment - Acquired from an IBM Business Partner - Enhanced Technical Support for IBM i

Service Option Attachment - Acquired from an IBM Business Partner - Enhanced Technical Support for IBM i Service Option Attachment - Acquired from an IBM Business Partner Enhanced Technical Support for IBM i This Service Option Attachment (SOA) specifies an optional service selected by you on the Schedule

More information

Understanding Internal Controls Office of Internal Audit

Understanding Internal Controls Office of Internal Audit Understanding Internal Controls Office of Internal Audit July 2015 Objectives for this manual Provide guidance to help management understand their responsibility to ensure that internal controls are established,

More information

Report on controls over Devon Funds Management Limited s investment management services. For the period from 1 January 2014 to 31 December 2014

Report on controls over Devon Funds Management Limited s investment management services. For the period from 1 January 2014 to 31 December 2014 Report on controls over Devon Funds Management Limited s investment management services For the period from 1 January 2014 to 31 December 2014 Description of Investment Management Services, Controls

More information

Loch Lomond & The Trossachs National Park Authority. Annual internal audit report Year ended 31 March 2015

Loch Lomond & The Trossachs National Park Authority. Annual internal audit report Year ended 31 March 2015 Loch Lomond & The Trossachs National Park Authority Annual internal audit report Year ended 31 March 2015 Contents This report is for: Information Chief executive Audit committee Jaki Carnegie, director

More information

TUV SUD BABT PRODUCTION QUALITY CERTIFICATION SCHEME

TUV SUD BABT PRODUCTION QUALITY CERTIFICATION SCHEME TUV SUD BABT PRODUCTION QUALITY CERTIFICATION SCHEME Copyright TUV SUD BABT 2017 A Certification Body of: Page 1 of 33 Contents AMENDMENT RECORD 3 0. INTRODUCTION 3 1. PRE-CONDITIONS TO SUPPORT PRODUCTION

More information

Personal Data Protection in the Workplace promoting the awareness of data protection in Singapore, and administrating and enforcing the PDPA.

Personal Data Protection in the Workplace promoting the awareness of data protection in Singapore, and administrating and enforcing the PDPA. 15 With the Personal Data Protection Act ( PDPA ) coming into full force on 2 July 2014, it is time for employers to revise workplace policies to ensure that they comply with the new legislation and adequately

More information

ISMS AUDIT CHECKLIST

ISMS AUDIT CHECKLIST 4.1 REQUIREMENT REFER TO BS ISO / IEC 27001 : 2005 Has the organisation developed a documented ISMS based on the PDCA model? Checked at Stage 1 for development and Stage 2/surveillance for implementation,

More information

Rexel Shredding. Why a paper security policy is integral to GDPR compliance.

Rexel Shredding. Why a paper security policy is integral to GDPR compliance. Rexel Shredding Why a paper security policy is integral to GDPR compliance. Disclaimer Nothing contained herein should be construed as legal advice. Organisations should consult legal counsel with regard

More information

NTT DATA Service Description

NTT DATA Service Description NTT DATA Service Description NTT DATA Managed Services for Microsoft Azure Site Introduction NTT DATA is pleased to provide NTT DATA Managed Services for Microsoft Azure Site (the Service(s) ) in accordance

More information

Right Start Remote Implementation (RIS) of a NetVault Environment

Right Start Remote Implementation (RIS) of a NetVault Environment Right Start Remote Implementation (RIS) of a NetVault Environment Description The Right Start Remote Implementation (RIS) of a NetVault Environment service provides remote installation, configuration,

More information

TENDER AND EVALUATION PROCESS FOR CONTESTABLE AUGMENTATIONS

TENDER AND EVALUATION PROCESS FOR CONTESTABLE AUGMENTATIONS TENDER AND EVALUATION PROCESS FOR CONTESTABLE AUGMENTATIONS PREPARED BY: Transmission Services Department VERSION: 1 RELEASE DATE: 1 July 2010 Au1hol,an Enargy Marla! ap.rotr:w lkl A~N o,. 012 010 321

More information

Tough Math for Desktop TCO

Tough Math for Desktop TCO Top 6 reasons to use a Remote Desktop and RemoteApps Tough Math for Desktop TCO In their fight to reduce IT budgets, small- and medium-sized businesses have to answer one tough question: how do we reduce

More information

Data Protection/ Information Security Policy

Data Protection/ Information Security Policy Data Protection/ Information Security Policy Date Policy Reviewed 27 th April 2016 Date Passed to Governors: 27 th April 2016 Approved by Governors: 7 th June 2016 Date of Next Review: June 2018 Data Protection

More information

Desk Audit of. Based on Federal Transit Administration (FTA) Quality Assurance and Quality Control Guidelines FTA-IT

Desk Audit of. Based on Federal Transit Administration (FTA) Quality Assurance and Quality Control Guidelines FTA-IT Desk Audit of Based on Federal Transit Administration (FTA) Quality Assurance and Quality Control Guidelines FTA-IT-90-5001-02.1 Reviewed by: Element Requirements Applicable 1. Is a quality policy defined

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 19 th September 2017 Name of originator /author (s):

More information

REQUEST FOR PROPOSALS: INFORMATION TECHNOLOGY SUPPORT SERVICES

REQUEST FOR PROPOSALS: INFORMATION TECHNOLOGY SUPPORT SERVICES REQUEST FOR PROPOSALS: INFORMATION TECHNOLOGY SUPPORT SERVICES Responses Due October 30, 2017 at 4:00 PM RFP 2017: INFORMATION TECHNOLOGY SERVICES PAGE 1 TABLE OF CONTENTS I. INTRODUCTION II. SUBMISSION

More information

Primavera Analytics and Primavera Data Warehouse Security Overview

Primavera Analytics and Primavera Data Warehouse Security Overview Analytics and Primavera Data Warehouse Security Guide 15 R2 October 2015 Contents Primavera Analytics and Primavera Data Warehouse Security Overview... 5 Safe Deployment of Primavera Analytics and Primavera

More information

Standard Operating Procedure 1 (SOP 1) Printing

Standard Operating Procedure 1 (SOP 1) Printing Why we have a procedure? Standard Operating Procedure 1 (SOP 1) Printing This Standard Operating Procedure (SOP) will set out the approved methods of using print devices, and printing within Black Country

More information

Introducing FUJITSU Software Systemwalker Centric Manager V15.0

Introducing FUJITSU Software Systemwalker Centric Manager V15.0 Introducing FUJITSU Software Systemwalker Centric Manager V15.0 < Version 1.0 > November 2013 FUJITSU LIMITED Contents Integrated Monitoring Required in Virtualization/Server Integration Characteristics

More information

The Red (Book) Rocks The Latest and Greatest Audit Standards

The Red (Book) Rocks The Latest and Greatest Audit Standards The Red (Book) Rocks The Latest and Greatest Audit Standards Presenter Toni Stephens Chief Audit Executive The University of Texas at Dallas Insert Logo Here Course Objectives Explain the development of

More information

ISO INTERNATIONAL STANDARD. Quality requirements for fusion welding of metallic materials Part 3: Standard quality requirements

ISO INTERNATIONAL STANDARD. Quality requirements for fusion welding of metallic materials Part 3: Standard quality requirements INTERNATIONAL STANDARD ISO 3834-3 Second edition 2005-12-15 Quality requirements for fusion welding of metallic materials Part 3: Standard quality requirements Exigences de qualité en soudage par fusion

More information

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges Cyber Risk 1 GDPR and Canadian organizations: Addressing key challenges The regulation

More information

SECTION - VI FORMS AND PROCEDURES

SECTION - VI FORMS AND PROCEDURES SECTION - VI FORMS AND PROCEDURES Forms and Procedures ANNEX 1. REQUEST FOR CHANGE PROPOSAL... 6 ANNEX 2. ESTIMATE FOR CHANGE PROPOSAL... 8 ANNEX 3. ACCEPTANCE OF ESTIMATE... 10 ANNEX 4. CHANGE PROPOSAL...

More information

INTERNATIONAL STANDARD

INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO 9001 Quality management systems Requirements Systèmes de management de la qualité Exigences Fourth edition 2008-11-15 Reference number ISO 9001:2008(E) ISO 2008 PDF disclaimer

More information

2017 IBM Corporation. IBM s Journey to GDPR Readiness

2017 IBM Corporation. IBM s Journey to GDPR Readiness IBM s Journey to GDPR Readiness IBM s Journey to GDPR Readiness At IBM, we have a deep rooted understanding that privacy is foundational to trust. We are approaching the GDPR in the same spirit, both internally

More information

Job Descriptions. Title & Job Functions: Transmission Function Employees

Job Descriptions. Title & Job Functions: Transmission Function Employees Job Descriptions In accordance with its Standards of Conduct Implementation and Compliance Procedures, City Utilities of Springfield, Missouri will post on these pages the job titles and job descriptions

More information

Integrated Management System Manual

Integrated Management System Manual QUALITY & ENVIRONMENTAL MANAGEMENT SYSTYEMS Integrated Management System Manual ISO 9001:2008, 14001:2004 and OHSAS 18001: 2007 Document ID: IMS Manual/ Rev. No. 00/ Rev. Date: 01-Jun-2009/ Page 1 of 19

More information

Infrastructure Hosting Service. Service Level Expectations

Infrastructure Hosting Service. Service Level Expectations November 2016 Shared Infrastructure Service TOC Service Level Expectation Documents Cloud Premier Data Center Hosting Cloud Essentials Public Cloud Brokerage Managed Database Raw Storage Cloud Premier

More information