/
Information Governance Standard uplift following SME review

Information Governance Standard uplift following SME review

ID

RM251

Version

1.0.0

Type

Roadmap Item

Contracting Vehicle(s)

Title

Information Governance Standard uplift following SME review

Description

Improvements arising from SME review of the Information Governance Standard

Date Added

Feb 11, 2025

Standards and Capabilities

Information Governance

Change Route

Managed Capability - Minor/Patch uplifts

Change Type

Uplift

Status

Draft

Publication Date

Feb 25, 2025

Effective Date

Mar 11, 2025

Incentives / Funding

No

Incentive / Funding Dates

N/A

Background

As part of a review of the Information Governance Standard some improvements to the Standard have been identified to ensure requirements are as clear as possible and remain current.

  • A context description will be added to the Data Labelling section of the Standard.

  • Removal of GP-IG-5-7 to remove duplication across requirements within the Standard. New requirement GP-IG-18-9 will be added to cover the remaining part of this requirement that is not a duplicate to ensure this continues to be assured.

  • Requirement GP-IG-14.1-4 will be removed as the requirement is no longer necessary.

This Roadmap Item does not impact the compliance status for currently compliant Solutions.

Outline Plan

N/A

Summary of Change

Information Governance: MUST Requirements removed

All

GP-IG-5-7

Provision of online services - information protection

The technical architecture of the interface mechanism and any supporting infrastructure to satisfy the requirements in this document will:

  • Satisfy the requirements of Data Security and Protection Toolkit or itā€™s equivalent successor

  • Be subject to annual penetration testing as a minimum, or to coincide with significant Solution changes

  • Continually incorporate best practice monitoring and intrusion-detection mechanisms

Must

All

GP-IG-14.1-4

Synchronise Internal Clocks -Ā with HSCN Network DNS Servers

The Supplier to ensure that Solutions align to HSCN Network Time Protocol Guidance NHS Network Time Protocol guidance - NHS England Digital

Must

Information Governance: MUST Requirement added to Information Security

All

GP-IG-18-9

Penetration Testing

Penetration testing will be completed by a 3rd party CHECK / CREST accredited organisation before go-live and annually thereafter.

An action plan must be in place to mitigate any vulnerabilities identified in an appropriate timeframe.

MUST

Information Governance: GP-IG-9-1 updated

All

GP-IG-9-1

Data Labelling - hard-copy output

All Personal Data which are output to hard-copy by the Solution will be labelled "Official ā€“ Sensitive".

The requirements in this section are not intended to affect the printing specifications for prescriptions or dispensing tokens as specified by the Electronic Prescription Service (EPS) requirements, or for any other outputs that are subject to separate requirements.

SHOULD

Information Governance: Data Labelling context description added

The Requirements in this section are not intended to affect the printing specifications for Prescriptions or dispensing tokens as specified by the EPS Requirements, or for any other outputs that are subject to separate requirements.

Full Specification

The updated Information Governance Standard will be added at a later date. Proposed changes can be viewed in the Summary of Change above.

Assurance Approach

N/A