{% extends "withoutnav_template.html" %} {% from "components/table.html" import mapping_table, row, text_field, edit_field, field %} {% from "components/sub-navigation.html" import sub_navigation %} {% block per_page_title %} Information risk management {% endblock %} {% block maincolumn_content %}
GOV.UK Notify is built for the needs of government services. It has processes in place to:
On Notify, data is encrypted:
Any user data you upload is only held for 7 days.
The Cabinet Office acts as data processor for Notify. Your organisation is the data controller.
Notify complies with the Data Protection Act. To make sure it stays compliant, there are regular legal reviews of the service’s:
Other technical security controls on Notify include:
You can set different user permissions in Notify. This lets you control who in your team has access to certain parts of the service.
Our approach to information risk management follows National Cyber Security Centre (NCSC) guidance. It assesses:
This approach also applies to the service providers Notify uses to send messages.
Things we do to manage risks on Notify include:
Notify has been assessed and approved by the Cabinet Office Senior Information Risk Officer (SIRO). The SIRO checks this approval once a year.
Notify also has approval from the Office of the Government’s SIRO to host data within the EEA.
Any information in Notify is classified as ‘OFFICIAL’ under the Government Security Classifications Policy.
All system administration staff working on Notify are cleared to Security Check (SC) level by United Kingdom Security Vetting.
{% endblock %}