1-1 of 1 results for subject:Self-assessment
Librarians' tools
- Search time
- 0.134 seconds
- Solr query time
- 0.003 seconds
- Search query
- subject:Self-assessment
- We searched for
- subject_t:Self-assessment OR subject_ses:92954
Answering member
X
Liam Byrne
Type
House
Session
Year
Department
Member
Primary member
Answering member
More
Byrne, Liam (1)
Legislative stage
Legislation
Subject
Publisher
(2) what plans she has to change local self-assessment for British Standard 7799 NHS compliance; and if she will make a statement;
(2) what plans she has to change local self-assessment for British Standard 7799 NHS compliance; and if she will make a statement;
Asked by
Andrew Murrison
(Conservative)
Answered by
Liam Byrne
(Labour)
Answering body
Department of Health
Type
Written questions
Status
Answered
Tabled on
25 October 2005
For answer on
27 October 2005
Answered on
15 November 2005
The BS7799 part 1, recently updated and now known as ISO/IEC 17799, provides the foundation for the best practice security management of the national health service's information assets. Central arrangements have already been established that enable all NHS organisations to obtain a full reference copy of the standard for their own use. In addition, key requirements of the ISO/IEC17799 are included within the existing NHS Information Governance Framework, along with relevant topic guidance and illustrations. These are available to NHS organisations through the centrally provided and maintained NHS Information Governance Toolkit service.The NHS Information Governance Toolkit supports NHS organisations to meet information security requirements but also numerous other closely associated requirements including best practice in terms of records management, information quality, data protection and the confidential management of records. Bringing these requirements together in this way has eliminated considerable duplication of effort as each of these aspects of information governance are based on similar principles and working practices but in the past they were addressed separately. The Information Governance Toolkit is provided free of charge to NHS organisations and replaced a range of existing data collections and has generated significant savings in staff time and resources across a wide range of NHS organisations.Compliance assessment of NHS information security management, is based upon the ISO/IEC 17799 framework and is currently achieved on an annual basis through self-assessed organisational attainment reporting within the NHS Information Governance Toolkit. A review of these arrangements is currently under way and that will further refine and extend assurance criterion. These new arrangements should also in future form a significant part of formal NHS audit programmes at both local and national level.In addition to contractual obligations, it is also intended that equivalent information governance assurance reporting arrangements will shortly be developed and implemented for a range of non-NHS information partner organisations, including those private sector organisations treating NHS patients. These requirements already exist for commercial service provider organisations involved in the delivery of the NHS National Programme for Information Technology and whose security management performance is routinely monitored against the ISO/IEC 17799.Although there is no current requirement for NHS organisations to seek or maintain a formal BS7799 part 2:2002 registration, NHS organisations are able to do so as a local decision. This part 2 of the original BS7799 standard has recently been replaced and is now known internationally as ISO/IEC 27001:2005. The Information Governance toolkit was developed, in part, to provide a cost effective alternative to individual NHS organisations requiring assistance from independent qualified lead accreditation consultants at commercial rates. As formal registration is not an NHS requirement, there are no central records of NHS organisations that may already have chosen to formally register or that may be considering doing so.On 18 October 2005, a departmental official met with two representatives of the British Standards Institute to outline and discuss the NHS approach to BS7799. The British Standards Institute are therefore now fully aware of the significant steps taken by the Department to both adopt and promote the values of this standard to NHS organisations and relevant others.
Subjects
Data protection; ICT; NHS; Standards; Security; Self-assessment
Date
15 November 2005
Reference
22588; 439 c1163-5W;439 c1163-5W
House
House of Commons