Information Risk Policy

Size: px
Start display at page:

Download "Information Risk Policy"

Transcription

1 Information Risk Policy Version 1_0 Responsible Person Information Governance Manager Lead Director Director of Performance and Corporate Services Consultation Route Information Governance Steering Group Approval Route HSCB Senior Management Team and Governance Committee Applies To All HSCB Staff, Contractors and Relevant Third Parties Approval Date Senior Management Team 08/09/15 Governance Committee 24/09/15 Review Date September 2018

2 Amendment / Change Control Version Date Author Reason / Comments Review Date V0.1 June 2015 K Moore New Policy Information Governance requirements September 2018 V0.2 August 2015 K Moore Following IGSG Meeting added in section on the role of the PDG and job title of current SIRO. September

3 Contents Table of Contents 1.0 Introduction Purpose Roles & Responsibilities Information Risk Management Process Information Assets Information Asset Register Information Risk Assessments Treatment Plans Privacy Impact Assessments (PIAs) Information Risk Training Monitoring Compliance Assurance Review and Revision Arrangements Policy Distribution... 9 Appendix One

4 1.0 Introduction This policy lays the framework for a formal information risk management programme in the HSCB by establishing responsibility for information risk, identification and analysis, planning for information risk mitigation and information risk management. The HSCB and its management team are required to assure the formal introduction and embedding of information risk management into key controls and approval processes for all the functions of the HSCB. Information risk is inherent in all administrative and business activities and everyone working for or on behalf of the HSCB continuously manages information risk. Information risk management is an essential element of broader information governance and is an integral part of good management practice. 2.0 Purpose The purpose of this Information Risk Policy is to: Protect the HSCB from information risks where the likelihood of occurrence and the consequences are significant; Provide a consistent risk management framework in which information risks will be identified, considered and addressed in key approval, review and control processes; Provide assistance to and improve the quality of decision making throughout the HSCB; Meet legal and statutory requirements; Assist in safeguarding the HSCB Information Assets; Integrate information risk as a key part of the risk management process. 3.0 Roles & Responsibilities The following are the reporting arrangements: Chief Executive The Chief Executive has overall responsibility for the management of the HSCB and for ensuring appropriate mechanisms are in place to minimise information risks. Personal Data Guardian (PDG) - The PDG (Director of Integrated Care) has responsibility for ensuring that HSCB processes satisfy the highest practical standards for handling personal data. The PDG is the 4

5 conscience of the organization in respect of patient information, and will also promote a culture that respects and protects personal data. The PDG works closely with the SIRO and Information Asset Owners where appropriate, especially where information risk reviews are conducted for assets which comprise or contain patient/service user information. Senior Information Risk Officer (SIRO) The SIRO (Director of Performance and Corporate Services) is responsible for coordinating the development and maintenance of information risk policies, procedures and standards for the HSCB. It is their role to: Ensure the organisation s overall information risk policy and risk assessment processes are implemented consistently by IAOs. Review and agree actions in respect of identified information risks. Provide a focal point for the resolution and/or discussion of information risk issues. Advise the Chief Executive or relevant accounting officer on the content of their annual governance statement in regard to information risk. Information Asset Owners (IAO) The IAO is a senior member of staff who is the nominated owner for one or more identified information assets within their Directorate. Information Asset Owners will be required to: Identify their information assets and where appropriate appoint for each asset an Information Asset Administrator (IAA). With the assistance of the Information Governance Team ensure that risk assessments are performed at the inception of any new assets. Understand what information is held and in what form, how it is added and removed, who has access to it and why. Will ensure that information risk management is embedded into the key controls and approval processes of all major business processes and functions. Responsible for risk assessment, reduction and prevention for their information assets including ongoing evaluation and risk management. IAO s are asked to provide annual assurance to the Senior Information Risk Owner (SIRO) that information risks identified for Information Assets within their Directorate are being appropriately managed. 5

6 Information Asset Administrators (IAA) Working in conjunction with the IAO an Information Asset Administrator (IAA) may be assigned to: Ensure policies and procedures are followed to help minimise risk. Recognise potential security incidents. Consult with the IAO on incident management. Ensure that information asset registers are up to date. An example of an IAA could be an existing systems administrator. All Staff Everyone has a role in the effective management of information risk. All staff will actively participate in identifying potential information risks in their areas and contribute to the implementation of appropriate treatment actions. 4.0 Information Risk Management Process 4.1 Information Assets An Information Asset is any set of records or information that is held by the HSCB, in any format, in support of a business function. The information held in an Information Asset can originate from any number of sources such as information from other organisations/individuals to information produced by the HSCB. Refer to Appendix A for more information on Information Assets and Guidance Notes. 4.2 Information Asset Register The Information Governance Team will lead on and ensure that an Information Asset Register (IAR) is set up for each Directorate. The register will: Allow the HSCB to understand what information it holds and how that information is being used; Ensure Information Assets are appropriately managed which will in turn reduce the risks to that information; Be maintained by each IAO with assistance from the identified IAA s. Be managed by the Information Governance Team who will ensure that all registers are regularly updated. Click here to view the Information Asset Register template. 4.3 Information Risk Assessments 6

7 An information risk assessment will be performed for all identified information assets. Information risk assessments will: Be conducted by the Information Governance Team in conjunction with the IAO / IAA. Be carried out using the HSCB s existing risk assessment procedure i.e. Data Flow and Information Security questionnaire, which will map the flow of information into and out of each asset and enable assessment of risks. Quantify the level of risk associated to each asset, the HSC Grading Matrix five by five will be utilised to rate the level of risk. Click here to view the HSC Risk Assessment tools. Ensure all threats, vulnerabilities and impacts are identified and if necessary included within the HSCB wide risk register. Information risk assessments will occur at the following times: At the inception of new systems / applications or anything that constitutes an information asset as outlined in Appendix A. At least annually to provide assurance to the SIRO on the agreed management of risks, this should be appropriately managed in line with HSCB policies and procedures. Before enhancements, upgrades and conversions associated with critical systems or applications. 4.4 Treatment Plans Treatment Plans will be developed based on the outcome of the risk assessment. Treatment options will involve one or a combination of the following four strategies: Avoid the risk Reduce the likelihood of occurrence Reduce the consequences of occurrence Retain/accept the risk Where applicable, mitigation plans shall include specific recommendations, to reduce information risk, alongside realistic completion dates. These will be communicated to the relevant IAO s for information / action. 7

8 4.5 Privacy Impact Assessments (PIAs) As a further element of good practice a Privacy Impact Assessment (PIA) will be considered for all major projects for example new systems, new services, etc. within an IAO s area of responsibility. Where the overview of the project identifies that a PIA is required to be undertaken this will be conducted in accordance with the criteria specified by the Information Commissioners Office. If required, the Information Governance Team will provide support during this process. 4.6 Information Risk Training Relevant training will be made available to all IAO s / IAA s and it is the responsibility of individuals to avail of the training. All HSCB staff complete Information Governance Training and Risk Management E- Learning every 3 years as part of mandatory induction training. If staff require additional or tailored training in this area, this can be arranged via contacting Ken.Moore@hscni.net. 5.0 Monitoring Compliance Monitoring of the policy will be informed by the number of reported Information Governance complaints and incidents. 6.0 Assurance Indicators for audit may include: The existence of an identified IAO for each Directorate. The existence of an Information Asset Register for each Directorate. The existence of a HSCB Risk Register. Annual assurance to the SIRO from each IAO. An annual review will be carried out by the Information Governance Team on behalf of the SIRO and reported to the Information Governance Steering Group (IGSG). Overall responsibility for action plans will lie with the SIRO but will be completed by relevant IAO and reported to and monitored by IGSG. 7.0 Review and Revision Arrangements 8

9 The HSCB is committed to ensuring that all policies are kept under review to ensure that they remain compliant with relevant legislation. This policy will be reviewed by the Information Governance Steering Group every 3 years. However, it will be reviewed when affected by major internal or external changes such as: Legislation Practice change or change in system/technology Changing methodology 8.0 Policy Distribution This Policy will be made available to all HSCB staff via the HSCB s Intranet site. 9

10 Appendix One Identification of Information Assets Every business function conducted by the HSCB is dependent on information in one format or another. Information is therefore recognised as having a value to the organisation and as such it needs to be treated and managed as an asset. The purpose of this piece of work is to develop a register of Information Assets as a first step in addressing risks to the information held by the HSCB. Each Directorate is therefore asked to complete the attached template and establish an Information Asset Register for their Directorate. What is an Information Asset? An Information Asset is any set of records or information that is held by the HSCB, in any format, in support of a business function. The information held in an Information Asset can originate from any number of sources such as information from other organisations/individuals to information produced by the HSCB. For this exercise we only wish to record details of Information Assets which hold more than fifty records. Information Assets primarily hold either/or both Electronic Records and Hard Copy Records however other forms exist such as recordings, backup tapes etc. Common examples of Information Assets are: Dedicated systems such as: Finance (General Ledger), HR (Human Resources Management System), Complaints (Datix), Intranets (HSCB Intranet, Primary Care Intranet) Websites. Spreadsheets and Databases developed either in-house or bought in. Systems, Electronic Document and Records Management System (Meridio), Network Drive Folders, Portable Hard Drives, 10

11 Memory Sticks Blackberry Mobile Phones Information Assets also include manual records - Filing Cabinets, Times Two Units, Closed Record Stores (basements, registries etc), Off-Site Storage Basically - any set of 50 or more records retained for a business process. What is not an Information Asset? Information Assets must have a value to the organisation, typical examples of what isn t classed as an Information Asset are: Extra copies of reports; s which do not form part of a master file; Information retained for personal reasons; Spreadsheets and Databases personally developed by individuals to assist them alone in their work; Why do we need an Information Asset Register? There are a number of reasons why the Board needs to compile an Information Asset Register: To allow the HSCB to understand what information it holds and how that information is being used; To ensure Information Assets are appropriately managed which will in turn reduce the risks to that information; To meet DHSSPS requirements in respect of Information Risk; To meet Audit recommendations in respect of Information Risk. Who can I speak to for assistance? Each Directorate within the HSCB has one or more nominated Information Asset Owners (IAO s) - See Appendix 1 for details. It is 11

12 unlikely these individuals will have a working knowledge of all the Assets within their Directorate therefore Information Asset Administrators (IAA s) will need to be identified for each Asset - These are individuals who perhaps head up a team or are responsible for a particular business process and have a working knowledge of the Information Asset. The Information Governance Team is also available for support on this project. Should you require any assistance please contact your Information Asset Owner in the first instance or a member of the Information Governance Team: Ken.moore@hscni.net Peter.Moran@hscni.net Claire.donnelly@hscni.net How do I compile an Information Asset Register? List the key business processes undertaken by your Directorate, each one will have one or more Information Assets associated with it. Complete the attached register template completing a row for each Asset. What Happens when the exercise is complete? When each Directorate completes their Register they will forward it to the Information Governance Team who will combine all Directorate registers into one Corporate Information Asset Register for the HSCB. This will become an important document which will be maintained and updated on a regular basis. Each Information Asset Owner will be asked to provide assurances to the Board s Senior Information Risk Owner at least annually that all Information Assets have been recorded and are being managed appropriately. Following completion of the Registers the Information Governance Team will analyse the information and establish which Information Assets hold personally identifiable information or business sensitive information. With the assistance of the IAA s a further exercise to map the flow of information into and out of these Assets will be completed. This will allow risks to be identified and evaluated. Action can then be taken to eliminate or reduce any risks to an acceptable level. 12

13 Step by Step Guide: Identifying and Recording Information Assets Step One: IAO s to identify Business Processes and Key Systems used within Directorate. Bear in mind this is all Teams in all HSCB Offices. Step Two: For each Business Process identify an Information Asset Administrator (IAA). Step Three: Circulate this paper and the Information Asset Register template to each IAA asking them to fill out the template for each Information Asset they identify. Set an appropriate timescale for completion. Step Four: Pull all the completed templates into one Information Asset Register per Directorate. If helpful you can maintain each Team on a separate sheet within the spreadsheet. the completed Register to Ken.Moore@hscni.net (IG Manager). Step Five: The Information Governance Team will check the completed Registers and where personal information or business sensitive information is held contact will be made with the IAA s to assist with the Data Flow Analysis. Step Six: Following the Data Flow Analysis the Information Governance team will help identify potential risks and advise both IAO s and IAA s as to appropriate treatment. 13

14 Senior Information Risk Owner (SIRO): Mr Michael Bloomfield - Head of Corporate Services Information Asset Owners (IAO s): Finance Mr Simon Christie Commissioning - Ms Cara Anderson Integrated Care - Ms Linda McIlroy PMSI - Mr Stephen McDowell Social Care and Children s - Mr Tony Rodgers, Mr Aidan Murray and Mr Kevin Keenan Transforming Your Care - Ms Lynn Campbell E-Health & External Collaboration Mr Des O Loan Corporate Services - Mr Ken Moore 14

Information Security Risk Management Programme and Strategy

Information Security Risk Management Programme and Strategy Information Security Risk Management Programme and Strategy Table of Contents 1. Introduction... 3 2. Purpose... 3 3. Definitions... 3 4. Roles and Responsibilities... 4 4.1. Accountable Officer... 4 4.2.

More information

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN INFORMATION GOVERNANCE STRATEGY & IMPLEMENTATION PLAN 2015-2018 Disclaimer The latest version of this document is located on PTHB intranet. Please check the review date and if there are any doubts contact

More information

Findings from ICO audits of 16 local authorities

Findings from ICO audits of 16 local authorities Data protection Findings from ICO audits of 16 local authorities January to December 2013 Introduction This report is based on ICO audits of 16 local authorities between January and December 2013. This

More information

INFORMATION GOVERNANCE STRATEGY AND STRATEGIC VISION

INFORMATION GOVERNANCE STRATEGY AND STRATEGIC VISION INFORMATION GOVERNANCE STRATEGY AND STRATEGIC VISION Policy approved by: Joint Audit and Governance Committee Date: December 2016 Next Review Date: October 2018 Version: 2.0 Information Governance Strategy

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 19 th September 2017 Name of originator /author (s):

More information

INFORMATION GOVERNANCE ASSURANCE FRAMEWORK

INFORMATION GOVERNANCE ASSURANCE FRAMEWORK INFORMATION GOVERNANCE ASSURANCE FRAMEWORK Summary This document sets out an overarching framework for the strategic Information Governance agenda in the Business Services Organisation. In particular,

More information

UNCLASSIFIED. ISO27002 Organising Information Security. Restrictions? If Y please give the reason for the restriction below.

UNCLASSIFIED. ISO27002 Organising Information Security. Restrictions? If Y please give the reason for the restriction below. Meeting Paper title Executive Team Date 18/06/12 ISO27002 Organising Information Security Agenda item 3 Discussion time Purpose of paper Decision 15 mins Restrictions on public access including staff Restrictions?

More information

Records Management Policy

Records Management Policy Records Management Policy Page 1 of 7 Document Control Document name Author Department Policy Nicki Hargreaves (Lead Officer) Good Practice Document status V1.0 Approval Information Governance Steering

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Policy Number IG001 Target Audience CCG/ GMSS Staff Approving Committee CCG Chief Officer Date Approved February 2018 Last Review Date February 2018 Next Review Date February

More information

Information Governance Strategy and Management Framework

Information Governance Strategy and Management Framework Information Governance Strategy and Management Framework Summary: This strategy sets out the framework, structure, system and accountabilities for Information Governance Management within NHS Eastbourne,

More information

Information Governance Strategic Management Framework

Information Governance Strategic Management Framework Information Governance Strategic Management Framework 2016-2018 Susan Meakin Information Governance Manager June 2016 Information Governance DOCUMENT CONTROL: Version: 2 Ratified by: Health Informatics

More information

West Kent Clinical Commissioning Group

West Kent Clinical Commissioning Group West Kent Clinical Commissioning Group Information Governance Strategy 2017-18 Release: Final Approved Date: 27/10/2016 Author: Jamie Sheldrake Senior Associate - Information Governance Owner: SOUTH EAST

More information

ABL Information Risk Policy

ABL Information Risk Policy Policy Name Approving Board ABL Information Risk Policy Date Approved 30/01/2018 Last Review Date 23/01/2018 Next Review Date 23/01/2020 Prepared By Version Number 3.0 Reference Number ABL Information

More information

Privacy Impact Assessment Policy and Procedure

Privacy Impact Assessment Policy and Procedure Privacy Impact Assessment Policy and Procedure This document outlines the Trust s approach and methodology for conducting Privacy Impact Assessments in line with the Information Risk Policy Key Words:

More information

The Information Commissioner s Office, the Information Governance Alliance and several other organisations are issuing guidance on an on-going basis.

The Information Commissioner s Office, the Information Governance Alliance and several other organisations are issuing guidance on an on-going basis. MARCH 2017 GENERAL DATA PROTECTION REGULATION ROTHERHAM CCG ACTION PLAN Themes of the GDPR: Refining/tightening up of existing concepts Standardised law across the EU New concepts in regulation; accountability,

More information

NOT PROTECTIVELY MARKED

NOT PROTECTIVELY MARKED Meeting Audit Committee Public Session Date and Time Location Pacific Quay, Glasgow Title of Paper General Data Protection Regulation (GDPR) SPA Preparedness Item Number 9.4 Presented By Catherine Topley

More information

IG01 Information Governance Management Framework

IG01 Information Governance Management Framework IG01 Information Governance Management Framework 1 INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History Document Reference: IG01 Document Purpose: The document compliments all other Information

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Owner Author Information Team Information Governance Manager Reviewed by Approved by and date Council/Committee/EMT Board - Date approved Effective from 24 April 2017 Review

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY CONSULTATION AND RATIFICATION SCHEDULE Document Name: Governance Policy Policy Number/Version: 2.0 Name of originator/author: Midlands & Lancashire CSU Governance Team Ratified

More information

Heart of England NHS Foundation Trust

Heart of England NHS Foundation Trust Heart of England NHS Foundation Trust Data protection audit report Executive summary February 2017 1. Background 1. Background The Information Commissioner is responsible for enforcing and promoting compliance

More information

Information Governance Policy and Management Framework

Information Governance Policy and Management Framework Putting Barnsley People First Information Governance Policy and Management Framework Version: 2.0 Approved By: Governing Body Date Approved: February 2014 Name of originator / author: Richard Walker Name

More information

Risk Management and Assurance Strategy

Risk Management and Assurance Strategy Risk Management and Assurance Strategy Version 5.0 Policy number ULHT-MD-GOV-RM-STRAT Document author(s) Head of 2021 Programme Contributor(s) Approved by Policy Approval Group Date approved Date Published

More information

TRUST GOVERNANCE POLICY (formerly referenced as the CMFT Governance Strategy) - UPDATED NOVEMBER

TRUST GOVERNANCE POLICY (formerly referenced as the CMFT Governance Strategy) - UPDATED NOVEMBER Review Circulation Application Ratification Originator or modifier Supersedes Title CENTRAL MANCHESTER UNIVERSITY HOSPITALS NHS FOUNDATION TRUST TRUST GOVERNANCE POLICY (formerly referenced as the CMFT

More information

Identifies the risk management structure, roles, responsibilities and authority of staff, committees and groups with responsibility for risk

Identifies the risk management structure, roles, responsibilities and authority of staff, committees and groups with responsibility for risk Title Description of document The sets out the process by which the Trust identifies, manages, reduces and mitigates risks to achieving the organisational objectives. It sets out the framework required

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Operational Owner: Executive Owner: James Newby Data Protection Officer Sarah Litchfield Senior Information Risk Officer Effective date: 25 th May 2018 Review date: May 2021 Related

More information

Information Asset Management Policy

Information Asset Management Policy Information Asset Management Policy 1.0 Purpose 1.1 The purpose of this policy is to outline the management of the Fund s information asset register and the actions that will be taken to provide sufficient

More information

Minor adjustments from IG Steering Group 0.3 Neil Taylor September 2013

Minor adjustments from IG Steering Group 0.3 Neil Taylor September 2013 Author(s) Andrew Thomas Version 0.3 Version Date 21 August 2013 Implementation/approval Date Review Date August 2014 Review Body Governing Body Policy Reference Number 014 Version Author Date Reason for

More information

Data Protection Policy

Data Protection Policy Data Protection Policy StCH Data Protection Policy - POL 53 vs1 - July 2016 1 Document Control Table Document Title: Data Protection Policy Document Ref: POL 53 Author (name and job title): Karen Anderson,

More information

Information Governance Management Framework

Information Governance Management Framework Management Framework Summary: This document sets out the framework, structure, system and accountabilities for Management within West Kent CCG Clinical Commissioning Group. APPROVED BY: Chief Finance Officer

More information

Information Governance Management Framework Version 6 December 2017

Information Governance Management Framework Version 6 December 2017 Information Governance Management Framework Version 6 December 2017 Page 1 of 8 Introduction Robust information governance requires clear and effective management and accountability structures, governance

More information

NHS Newcastle Gateshead Clinical Commissioning Group. Information Governance Strategy 2017/18

NHS Newcastle Gateshead Clinical Commissioning Group. Information Governance Strategy 2017/18 NHS Newcastle Gateshead Clinical Commissioning Group Information Governance Strategy 2017/18 Document Status Equality Impact Assessment Document Ratified/Approved By Final No impact Quality, Safety & Risk

More information

Overarching Information Governance Policy

Overarching Information Governance Policy Document Information Board Library Reference Document Type Document Subject Original Document Author Reviewed By Review Cycle IM&T_01 Policy Information Information IGMG 3 Years Note: This document is

More information

Data Quality Policy

Data Quality Policy Cambridgeshire and Peterborough Clinical Commissioning Group (CCG) Data Quality Policy 2017-2019 Ratification Process Lead Author(s): Reviewed / Developed by: Approved by: Ratified by: Associate Director

More information

Information Governance Assurance Framework

Information Governance Assurance Framework Document Reference POL008 Document Status Approved Version: V4.0 DOCUMENT CHANGE HISTORY Initiated by Date Author IG Toolkit Requirements November 2010 IG Manager Version Date Comments (i.e. viewed, or

More information

Information Governance Management Framework

Information Governance Management Framework Information Governance Management Framework November 2014 Author: Responsibility: Lynda Harris, Head of Information Governance All Staff Effective Date: November 2014 Review Date: November 2015 Reviewing/Endorsing

More information

NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY

NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY Version Control Version: 2.0 dated 17 July 2015 DATE VERSION CONTROL 04/06/2013 1.0 First draft of new policy

More information

NHS Sunderland Clinical Commissioning Group. Information Governance Strategy 2016/17

NHS Sunderland Clinical Commissioning Group. Information Governance Strategy 2016/17 NHS Sunderland Clinical Commissioning Group Information Governance Strategy 2016/17 Document Status Equality Impact Assessment Document Ratified/Approved By Final No impact Executive Committee Governing

More information

United Lincolnshire Hospitals NHS Trust. Governance Statement 2015/16. Scope of responsibility. The governance framework of the organisation

United Lincolnshire Hospitals NHS Trust. Governance Statement 2015/16. Scope of responsibility. The governance framework of the organisation United Lincolnshire Hospitals NHS Trust Governance Statement 2015/16 Scope of responsibility As Accountable Officer, and Chief Executive of this Board, I have responsibility for maintaining a sound system

More information

Solihull Metropolitan Borough Council. Corporate Health and Safety Policy For Core Council Staff. September 2015

Solihull Metropolitan Borough Council. Corporate Health and Safety Policy For Core Council Staff. September 2015 Solihull Metropolitan Borough Council Corporate Health and Safety Policy For Core Council Staff Version Control: September 2015 Version Date Author Sent to Reason 1.1 June 2015 Steve Dean ( Health and

More information

NHS BARNSLEY CCG DATA QUALITY POLICY SEPTEMBER 2016

NHS BARNSLEY CCG DATA QUALITY POLICY SEPTEMBER 2016 Putting Barnsley People First NHS BARNSLEY CCG DATA QUALITY POLICY SEPTEMBER 2016 Version: 1.0 Approved By: Governing Body Date Approved: 8 September 2016 Name of originator / author: Name of responsible

More information

RISK MANAGEMENT STRATEGY

RISK MANAGEMENT STRATEGY RISK MANAGEMENT STRATEGY 2015-2020 2016 Amendments This is a five-year strategy that is subject to annual review by the Board of Directors. The first review took place on 29 November 2016. At this time

More information

Information governance strategy

Information governance strategy Information governance strategy January 2018 Version 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment V 1.0 Trevor Duplessis 22/01/18 Due for review Dec

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Applicable to All employees Version1.0 Last Updated March 2014 CONFIDENTIAL Page 2 of 6 Contents 1. Objectives 3 2. Scope 3 3. Principles 3 4. Information Governance Policy

More information

Risk Management Strategy inc Policy Statement

Risk Management Strategy inc Policy Statement Title Risk Management Strategy inc Policy Statement 2015-17 Summary This strategy will establish a consistent and integrated approach to the management of risk throughout the BSO. Purpose The control and

More information

Leicestershire Police CCTV on Police Premises Policy

Leicestershire Police CCTV on Police Premises Policy Leicestershire Police CCTV on Police Premises Policy Policy Owner: Department Responsible: Chief Officer Approval: Deputy Chief Constable Corporate Services Directorate Deputy Chief Constable Date of Next

More information

DATA QUALITY POLICY. Version: 1.2. Management and Caldicott Committee. Date approved: 02 February Governance Lead

DATA QUALITY POLICY. Version: 1.2. Management and Caldicott Committee. Date approved: 02 February Governance Lead DATA QUALITY POLICY Version: 1.2 Approved by: Date approved: 02 February 2016 Name of Originator/Author: Name of Responsible Committee/Individual: Information Governance, Records Management and Caldicott

More information

This Policy supersedes the following Policy, which must now be destroyed:

This Policy supersedes the following Policy, which must now be destroyed: Document Title Reference Number Lead Officer Author(s) (name and designation) Ratified by Forensic Readiness Policy NTW(O)56 Lisa Quinn Executive Director of Performance and Assurance Sue Proud Information

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY 1. CONSULTATION AND RATIFICATION SCHEDULE 1.2. Document Name: Governance Policy 1.4. Policy Number/Version: V4.0 1.6. Name of originator/author: Midlands & Lancashire CSU

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Including the Information Governance Strategy Framework and associated Information Governance Procedures Last Review Date June 2017 Approving Body Audit Committee Date of

More information

RISK MANAGEMENT STRATEGY AND POLICY

RISK MANAGEMENT STRATEGY AND POLICY NEWPORT COMMUNITY SCHOOL PRIMARY ACADEMY Date Adopted: 12 th July 2012 Author/owner: Resources Committee Anticipated Review: Ongoing RISK MANAGEMENT STRATEGY AND POLICY Risk Management Strategy The Governing

More information

This Policy supersedes the following Policy, which must now be destroyed:

This Policy supersedes the following Policy, which must now be destroyed: Document Title Reference Number Lead Officer Author(s) (name and designation) Ratified by Forensic Readiness Policy NTW(O)56 Lisa Quinn, Executive Director of Commissioning and Quality Assurance Angela

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Page 1 of 13 INFORMATION GOVERNANCE POLICY EXECUTIVE SUMMARY Key Messages Principles of Information Governance Openness Confidentiality and Legal Compliance Information Security

More information

Information Governance Training Plan

Information Governance Training Plan Information Governance Training Plan Page 1 of 10 Paper O2 - CCG_IG_Training_Plan_2017-18_V3.0 Final Paper O2 - CCG_IG_Training_Plan_2017-18_V3.0 Final Information Governance Training Plan Derbyshire Clinical

More information

ENVIRONMENTAL MANUAL. Page 1 of 26 Uncontrolled when printed NCH Env Manual Vers 11.0 date 01/02/18

ENVIRONMENTAL MANUAL. Page 1 of 26 Uncontrolled when printed NCH Env Manual Vers 11.0 date 01/02/18 ENVIRONMENTAL MANUAL Page 1 of 26 Uncontrolled when printed NCH Env Manual Vers 11.0 date 01/02/18 Document Control Identification and Approval Status Document Title: Environmental Manual Version Number:

More information

Data Protection Impact Assessment Policy

Data Protection Impact Assessment Policy Data Protection Impact Assessment Policy Version 0.1 1 VERSION CONTROL Version Date Author Reason for Change 0.1 16.07.18 Debby Jones New policy 2 EQUALITY IMPACT ASSESSMENT Section 4 of the Equality Act

More information

PROBATIONARY PERIODS POLICY

PROBATIONARY PERIODS POLICY PROBATIONARY PERIODS POLICY Last Review Date n/a Approving Body Governing Body Date of Approval 6-12-18 Date of Implementation 6-12-18 Next Review Date December 2021 Review Responsibility Head of HR Version

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Unique Reference / Version Primary Intranet Location Information Management & Governance Secondary Intranet Location Policy Name Information Governance Policy Version Number

More information

East Riding of Yorkshire Council Data protection audit report. Executive summary March 2014

East Riding of Yorkshire Council Data protection audit report. Executive summary March 2014 East Riding of Yorkshire Council Data protection audit report Executive summary March 2014 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with the Data

More information

AUDIT GUIDELINES: ELECTRICITY, GAS AND WATER LICENSING: AUDIT TEMPLATE FOR SMALLER ORGANISATIONS

AUDIT GUIDELINES: ELECTRICITY, GAS AND WATER LICENSING: AUDIT TEMPLATE FOR SMALLER ORGANISATIONS AUDIT GUIDELINES: ELECTRICITY, GAS AND WATER LICENSING: AUDIT TEMPLATE FOR SMALLER ORGANISATIONS This document is available from the Economic Regulation Authority website www.era.wa.gov.au. For further

More information

Bowmer. & Kirkland. Kirkland. & Accommodation. Health & Safety Policy.

Bowmer. & Kirkland. Kirkland. & Accommodation. Health & Safety Policy. Bowmer Kirkland & Kirkland & Accommodation Health & Safety Policy December 2013 www.bandk.co.uk Index Policy Statement Page 3 Interaction of Health and Safety Responsibilities Page 5 Organisation Page

More information

GOVERNANCE STRATEGY October 2013

GOVERNANCE STRATEGY October 2013 GOVERNANCE STRATEGY October 2013 1. Introduction 1.1. The Central Manchester University Hospitals NHS Foundation Trust believes that the role of the governing body is pivotal to the success of the Trust.

More information

Staff Training and Development Procedure

Staff Training and Development Procedure Staff Training and Development Procedure Version: 8.0 Bodies consulted: Approved by: Recognised Trade Unions and Executive Management Team Executive Management Team Date Approved: September 2018 Lead Manager:

More information

IGPr002 - Information Governance Management Framework

IGPr002 - Information Governance Management Framework IGPr002 - Information Governance Management Framework Page 1 of 10 Table of Contents Information Governance Management Framework... 1 Why we need this Framework... 3 What the Framework is trying to do...

More information

Date: INFORMATION GOVERNANCE POLICY

Date: INFORMATION GOVERNANCE POLICY Date: INFORMATION GOVERNANCE POLICY Information Governance Policy IGPOL/01 Information Systems Corporate Services Division March 2017 1 Revision History Version Date Author(s) Comments 0.1 12/12/2012 Helen

More information

CORPORATE GOVERNANCE STATEMENT

CORPORATE GOVERNANCE STATEMENT CORPORATE GOVERNANCE STATEMENT The Company is committed to the pursuit of creating value for shareholders, while at the same meeting shareholders expectations of sound corporate governance practices. As

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK NHS South West Lincolnshire Clinical Commissioning Group (CCG) INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History: Document Reference: Document Purpose: IG01 Date Ratified: January 2015 Ratified

More information

Colleague HR Policies: Statutory & Mandatory Training Policy

Colleague HR Policies: Statutory & Mandatory Training Policy Colleague HR Policies: Statutory & Mandatory Training Policy Date Approved: 5 December 2017 In a nutshell We recognise our responsibilities that all of our colleagues are adequately and properly trained

More information

HEALTH AND SAFETY STRATEGY

HEALTH AND SAFETY STRATEGY HEALTH AND SAFETY STRATEGY 2016-2019 Version: 1.0 Ratified by: Integrated Governance Committee Date ratified: 30 September 2015 Title of originator/author: Title of responsible committee/group: Head of

More information

RISK MANAGEMENT STRATEGY

RISK MANAGEMENT STRATEGY Agenda Item No: 15 RISK MANAGEMENT STRATEGY PURPOSE: The Risk Management Strategy has been updated to reflect the revised approach to the Corporate Risk Register and Board Assurance Framework and to reflect

More information

Data Protection in schools and colleges: Questions from the Governing Board/Trustees/Directors

Data Protection in schools and colleges: Questions from the Governing Board/Trustees/Directors Data Protection in schools and colleges: Questions from the Governing Board/Trustees/Directors This document, produced by SWGfL is designed to support governors/trustees/directors of schools / colleges

More information

Information Governance Management Framework 2016/17

Information Governance Management Framework 2016/17 Information Governance Management Framework 2016/17 Reference: IG12 Compliance with all CCG policies, procedures, protocols, guidelines, guidance and standards is a condition of employment. Breach of policy

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Date completed: February 2016 Responsible Director: Approved by/ date: Director of Compliance Review date: October 2017 Amended: Author: Ben Westmancott Information Governance

More information

OPHTHALMIC LISTING (Northern Ireland)

OPHTHALMIC LISTING (Northern Ireland) GOS Practice and GOS Regulations Health and Social Care Board Northern Ireland OPHTHALMIC LISTING (Northern Ireland) GUIDANCE ON THE STATUTORY REQUIREMENTS FOR GENERAL OPHTHALMIC SERVICES CONTRACTORS Context

More information

CCG CO12 Policy and Framework for Partnership Governance

CCG CO12 Policy and Framework for Partnership Governance Corporate CCG CO12 Policy and Framework for Partnership Governance Version Number Date Issued Review Date V2: 21/02/2015 29/04/2015 21/02/2018 Prepared By: Consultation Process: Formally Approved: 25/02/2015

More information

INFORMATION GOVERNANCE COMMUNICATION STRATEGY

INFORMATION GOVERNANCE COMMUNICATION STRATEGY INFORMATION GOVERNANCE COMMUNICATION STRATEGY 20-2017 Summary This document sets out the steps to be taken during the next two years to maintain and improve communication of the strategic Information Governance

More information

Belfast Health and Social Care Trust (BHSCT) Personal and Public Involvement (PPI) Monitoring Report September 2017

Belfast Health and Social Care Trust (BHSCT) Personal and Public Involvement (PPI) Monitoring Report September 2017 Belfast Health and Social Care Trust (BHSCT) Personal and Public Involvement (PPI) Monitoring Report September 2017 Prepared by Martin Quinn and Claire Fordyce, PHA 1 Contents Introduction...... 3 Rationale

More information

WILTSHIRE POLICE FORCE POLICY

WILTSHIRE POLICE FORCE POLICY Template v4 WILTSHIRE POLICE FORCE POLICY BUSINESS CONTINUITY MANAGEMENT SYSTEMS (BCMS) Date of Publication: January 2017 Version: 3.0 Next Review Date: January 2019 POLICY STATEMENT Wiltshire Police has

More information

Agile Working Policy for EMIS Community Health Services

Agile Working Policy for EMIS Community Health Services Agile Working Policy for EMIS Community Health Services DOCUMENT NUMBER POL/001/077 DATE RATIFIED May 2017 DATE IMPLEMENTED May 2017 NEXT REVIEW DATE May 2019 ACCOUNTABLE DIRECTOR POLICY AUTHOR Director

More information

Phoenix Energy Holdings Gas Ltd Health & Safety Policy

Phoenix Energy Holdings Gas Ltd Health & Safety Policy Phoenix Energy Holdings Gas Ltd Health & Safety Policy July 2017 Phoenix Energy Holdings Ltd Health & Safety Policy July 2017 Contents 1.0 Introduction 2.0 Purpose 3.0 Scope 4.0 References 5.0 Definitions

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History Document Reference: IG33 Document Purpose: The document complements all other Information Governance policies and sets out the management arrangements

More information

Trust Board Meeting in Public: Wednesday 17 January 2018 TB

Trust Board Meeting in Public: Wednesday 17 January 2018 TB Trust Board Meeting in Public: Wednesday 17 January 2018 Title Progress report regarding organisational preparedness for the General Data Protection Regulation (Data Protection Act 2018) Status History

More information

GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector

GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector TABLE OF CONTENTS INTRODUCTION... 2 Accountable privacy management 2 Getting started 3 A.

More information

PROCEDURE (Essex) / Linked SOP (Kent) Information Sharing Agreements. Number: W 1014 Date Published: 23 June 2017

PROCEDURE (Essex) / Linked SOP (Kent) Information Sharing Agreements. Number: W 1014 Date Published: 23 June 2017 1.0 Summary of Changes 1.1 The following minor changes have been made to this procedure/sop on 23 June 2017: Paragraph 3.3.7 link created to Privacy Impact Assessment; Paragraph 3.4 Legal Services replaced

More information

The Corporate Governance Statement is accurate and up to date as at 30 June 2018 and has been approved by the board.

The Corporate Governance Statement is accurate and up to date as at 30 June 2018 and has been approved by the board. Rules 4.7.3 and 4.10.3 1 Appendix 4G Key to Disclosures Corporate Governance Council Principles and Recommendations Name of entity: Catalyst Metals Limited ABN / ARBN: Financial year ended: 54 118 912

More information

Records Management Policy

Records Management Policy Records Management Policy November 2013 Page 1 of 12 Policy Title: Records Management Policy Reference Number: CORP 08/003 Original Implementation Date: June 2011 Reviewed: November 2013 Next Review Date:

More information

HSE Integrated Risk Management Policy. Part 3. Managing and Monitoring Risk Registers Guidance for Managers

HSE Integrated Risk Management Policy. Part 3. Managing and Monitoring Risk Registers Guidance for Managers HSE Integrated Management Policy Part 3 Managing and Monitoring Registers Guidance for Managers HSE Integrated Management Policy Part 3 Managing and Monitoring Registers Guidance for Managers Identify

More information

WHISTLE BLOWING POLICY

WHISTLE BLOWING POLICY WHISTLE BLOWING POLICY Introduction The Tandridge Learning Trust is committed to the highest possible standards of honesty, openness, probity and accountability. It seeks to conduct its affairs in a responsible

More information

Business Continuity Management Policy

Business Continuity Management Policy Business Continuity Management Policy Version FINAL 1.0 Ratified by Dudley CCG Audit Committee Date ratified 17/03/16 Name of originator(s) / author(s) David Morris, Midlands and Lancashire CSU/ Sue Johnson,

More information

NORTHERN IRELAND AMBULANCE SERVICE ENVIRONMENTAL MANAGEMENT POLICY

NORTHERN IRELAND AMBULANCE SERVICE ENVIRONMENTAL MANAGEMENT POLICY NORTHERN IRELAND AMBULANCE SERVICE ENVIRONMENTAL MANAGEMENT POLICY April 2014 Version 2.0 Title: Purpose of Policy: Environmental Management Policy To set out NIAS policy on Environmental Management across

More information

General Data Protection Regulation (GDPR) Strategy

General Data Protection Regulation (GDPR) Strategy General Data Protection Regulation (GDPR) Strategy NHS Digital s Approach to Compliance Published October 2017 Copyright 2017 Health and Social Care Information Centre. The Health and Social Care Information

More information

RISK MANAGEMENT POLICY

RISK MANAGEMENT POLICY RISK MANAGEMENT POLICY Clinical Governance & Risk Management Department Warning Document uncontrolled when printed Policy Reference: RM 2.0 Date of Issue: TBC Prepared by: Risk Management Short Life Date

More information

Information Governance and Assurance Framework

Information Governance and Assurance Framework Information Governance and Assurance Framework Title: Information Governance and Assurance Framework Original author(s): Head of Business Technology Owner: SIRO Reviewed by: SIRO Group Approval body: SIRO

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY Version: 1.4 Approved by: Date approved: 19 January 2017 Name of Originator/Author: Name of Responsible Committee/Individual: Date issued: Information

More information

2018 CORPORATE GOVERNANCE STATEMENT

2018 CORPORATE GOVERNANCE STATEMENT 2018 CORPORATE GOVERNANCE STATEMENT This corporate governance statement sets out Prospect Resources Limited s (Company) current compliance with the ASX Corporate Governance Council s Corporate Governance

More information

Chelsea & Westminster Hospital NHS Foundation Trust. Data protection audit report

Chelsea & Westminster Hospital NHS Foundation Trust. Data protection audit report Chelsea & Westminster Hospital NHS Foundation Trust Data protection audit report Executive summary October 2017 1. Background The Information Commissioner is responsible for enforcing and promoting compliance

More information

HSCIC Audit of Data Sharing Activities:

HSCIC Audit of Data Sharing Activities: Directorate / Programme Data Dissemination Services Project Data Sharing Audits Status Approved Director Terry Hill Version 1.0 Owner Rob Shaw Version issue date 20/04/2016 HSCIC Audit of Data Sharing

More information

Corporate Governance Statement

Corporate Governance Statement The Board of Gowing Bros. Limited (the Company) is committed to ensuring that its systems, procedures and practices reflect a high standard of corporate governance. The Board supports the core governance

More information

Ixion Group Policy & Procedure. Quality & Assurance Framework

Ixion Group Policy & Procedure. Quality & Assurance Framework Ixion Group Policy & Procedure Quality & Assurance Framework Policy Statement The Ixion Group (Ixion) is committed to raising the standard of provision by putting our clients at the heart of everything

More information

RISK MANAGEMENT STRATEGY

RISK MANAGEMENT STRATEGY RISK MANAGEMENT STRATEGY Version 2.0 Page 1 of 9 OCTOBER 2013 POLICY DOCUMENT VERSION CONTROL CERTIFICATE TITLE Title: Risk Management Strategy Version: 2.0 SUPERSEDES Supersedes: Risk Management Strategy

More information

A Framework of Quality Assurance for Responsible Officers and Revalidation

A Framework of Quality Assurance for Responsible Officers and Revalidation A Framework of Quality Assurance for Responsible Officers and Revalidation Supporting responsible officers and designated bodies in providing assurance that they are discharging their statutory responsibilities.

More information