<p>Start by writing the message you want to send. Don’t worry about the information security aspect just yet – write the message you want to convey as clearly and directly as possible.</p>
<p>We have <ahref="">design patterns</a> and <ahref="">content guidance</a> to help you write clearly and convey the right information at the right time.</p>
<p>Once you have a message which meets user needs, look at it in relation to the risks we outline. Use this to decide if you need to change the message in order to keep the users safe.</p>
<p>For some messages, the recipient would be unhappy if someone else accidentally saw the contents, for example, the results of a recent medical test.</p>
<p>To address this risk, don’t reveal the important information in the subject line or opening sentence, or ask the user to sign in to see the information in full.</p>
<h3class="heading-small"id="risk-fraud">An attacker intercepts a message, or gains access to someone’s email inbox, phone messages or paper files</h3>
<p>It’s possible for hackers to intercept messages. Text messages, emails and letters can all be intercepted.</p>
<p>It’s also possible for a criminal to gain access to someone’s entire email inbox, phone messages or paper files. Email accounts can be hacked, phones and paper files can be stolen, left lying around or picked out of the rubbish.</p>
<p>In both cases, criminals are looking for information they can use to commit fraud. To address this risk, don’t send payment details, ID numbers or any other information that can be used for fraud.</p>
<h3class="heading-small"id="risk-phishing">An attacker tricks the user by sending a fake notification (phishing)</h3>
<p>In this scenario, a hacker sends lots of messages pretending to be from an official government service, hoping to trick someone into revealing information of value.</p>
<li>passport, driving licence, or National Insurance numbers, or any other personal ID numbers</li>
<li>the person’s date of birth, mother’s maiden name or other information commonly used for identification</li>
<li>the person’s full address or previous addresses</li>
<li>passwords (c’mon team)</li>
<li>payment amounts – if you use them as a form of identification</li>
</ul>
<p>Payment details can be used for fraud straight away. Other information requires a bit more work. For example, an attacker might use one piece of information to get hold of another, eventually gaining enough information to commit fraud. Or a criminal might use information from several old messages to steal someone’s identity.</p>
<h3class="heading-small"id="guideline-phishing">Don’t send requests for personal information of any kind, unless the request is directly connected with a transaction</h3>
<p>To reduce the risk from phishing attacks, don’t send <strong>requests</strong> for personal information <strong>of any kind</strong>, unless the request is <strong>directly connected with a transaction</strong>.</p>
<li>Don’t send links that reveal information that can be used for fraud</li>
<li>Don’t send unsolicited messages that include a link requesting personal information of any kind (it’s OK to send a message with a link requesting information if the user has just requested it)</li>
<li>Links must point to a .gov.uk domain – for example, <ahref="https://www.gov.uk">https://www.gov.uk</a> or <ahref="https://www.armslengthbody.gov.uk">https://www.armslengthbody.gov.uk</a>.</li>
<li>Links must show the URL in full – for example <ahref="https://www.gov.uk/vehicle-tax">https://www.gov.uk/vehicle-tax</a>, not <ahref="https://www.gov.uk/vehicle-tax">Vehicle tax</a>.</li>
<li>Don’t use redirects or tracking links – disguising the URL makes phishing easier. Just show the URL in full.</li>
<li>Don’t link directly to a sign-in page – this is a request for personal data. If the user needs to sign in to your service, link to your start page on GOV.UK.</li>
<li>It’s OK to deep-link into your service, as long as the user doesn’t have to sign in to view the information or take action.</li>
<p>If you want to communicate something, write it in the body of the email. This is more user-friendly. If the information is too sensitive to include in the email body, it’s too sensitive to include in an attachment.</p>
<h3class="heading-small"id="guideline-name">Include the user’s name – it makes phishing more difficult</h3>
<p>Start your message by addressing the user. For example, Hi Alice Smith or Dear Bob Jones. Including this extra piece of information makes phishing more difficult.</p>
<h3class="heading-small"id="guideline-technical">Use technical approaches to improve privacy and prevent phishing</h3>
<p>There are several technical approaches to preventing phishing. You must use <ahref="https://www.gov.uk/guidance/common-technology-services-cts-secure-email-blueprint">SPF/DKIM, DMARC</a> and <ahref="https://en.m.wikipedia.org/wiki/Transport_Layer_Security">TLS</a>.</p>
<h3class="heading-medium">Example of an appointment reminder</h3>
<p>“Dear Anne Smith, you’ve got a licence appointment tomorrow at 2:15pm at the Licence Office, 1 Chapel Hill, Heswall, Bournemouth BH1 1AA. To cancel your appointment, visit licensing.service.gov.uk/appointment/12345678/cancel. To change your appointment time, sign in to your account.”</p>
<p>This is a good example because:</p>
<ulclass="list list-bullet">
<li>The message and link doesn't reveal any sensitive personal data.</li>
<li>The message and link doesn't ask for personal data, passwords or payment details.</li>
<li>The reminder addresses the user by their name, helping to make phishing attacks more difficult.</li>
<li>The link just cancels the appointment. The worst that could happen is that an attacker cancels someone else’s appointment.</li>
<li>Users have to sign in to change the appointment time, making it harder for an attacker to know what their appointment time is .</li>
<li>The topic is something the user is familiar with.</li>
</ul>
<h3class="heading-medium">Example of an application</h3>
<p>“Dear Anne Smith, you’ve got a licence appointment tomorrow at 2:15pm at the Licence Office, 1 Chapel Hill, Heswall, Bournemouth BH1 1AA. To cancel your appointment, visit licensing.service.gov.uk/appointment/12345678/cancel. To change your appointment time, sign in to your account.”</p>
<p>This is a good example because:</p>
<ulclass="list list-bullet">
<li>The message and link doesn't reveal any sensitive personal data.</li>
<li>The message and link doesn't ask for personal data, passwords or payment details.</li>
<li>The reminder addresses the user by their name, helping to make phishing attacks more difficult.</li>
<li>The link just cancels the appointment. The worst that could happen is that an attacker cancels someone else’s appointment.</li>
<li>Users have to sign in to change the appointment time, making it harder for an attacker to know what their appointment time is .</li>
<li>The topic is something the user is familiar with.</li>