Approach to information risk management
The information risk management approach taken by GOV.UK Notify is aligned to the guidance provided by the
National Cyber Security Centre (NCSC) on GOV.UK.
The scope includes the risk assessment of:
- the GOV.UK Notify technical solution, infrastructure and supporting operations
- the text message, email, and letter service providers used by GOV.UK Notify
The ongoing information risk management activities include:
- formal risk assessments using a methodology based on
ISO 27005:2011
and supplemented by reference to NCSC standards and guidance documentation
- CHECK-based
IT Health Check (ITHC) testing (annual and on major change)
- residual risk statement preparation and active management of the risk treatment plan
- regular updates to the Privacy Impact Assessment
- security impact assessments
- legal reviews of the service’s Privacy Policy, Terms of Use and Data Sharing and Financial
Agreement to ensure Data Protection Act (‘DPA’) compliance
- Office of the Government’s SIRO (OGSIRO) offshoring approvals to host data within the EEA
- annual reviews of the risk acceptance status with the Cabinet Office Senior Information Risk Owner (SIRO)
Controls implemented for the GOV.UK Notify technical solution and operational support team include:
- Data encryption in transit and at rest
- Protective Monitoring
- System administration staff SC cleared
- Service subject to Cabinet Office and GDS security governance
Information within the GOV.UK Notify service is deemed to have a classification of ‘OFFICIAL’ under
the Government Security Classifications Policy.
{% endblock %}