Information security policy

Published 1 April 2023

Introduction

This policy sets out how we protect information at the highest level within the Information Security Management System (ISMS). It covers information, systems, networks, the physical environment, and the people who support council services.

The policy:

  • sets out how we protect the confidentiality, integrity and availability of our information assets. This includes hardware, software and information used across systems, networks and applications
  • defines roles and responsibilities for information security
  • points to the key documents that make up the ISMS

It is therefore supported by additional policies and procedures that cover specific areas, such as working off site and encryption.

Policy objective

This policy aims to protect the council’s information assets by putting appropriate controls in place. These controls may include policies, procedures, working practices, organisational structures and technical measures.

The controls must meet business needs and help us achieve a clear and measurable level of compliance.

Information security focuses on protecting:

  • confidentiality, making sure only authorised people can access information
  • integrity, keeping information accurate and complete
  • availability, making sure authorised users can access information and systems when they need them

Policy scope

This policy applies to all council information systems, networks, applications, locations and users.

Policy statement

Council systems, applications and networks must be available when needed. Only authorised users must be able to access them, and the information they hold must be as accurate and complete as possible.

We must protect these systems and recover them from any threats to their availability, integrity or confidentiality. We must also protect them from accidental data loss.

To do this, we will:

  • protect all hardware, software and information assets under our control using a balanced mix of technical and organisational measures
  • provide protection that is proportionate to the level of risk
  • implement the ISMS in a consistent, timely and cost‑effective way

Legislation

We're governed by the law of England and Wales. Some legislation which is relevant to information security includes:

  • Data Protection Act 2018
  • UK General Data Protection Regulation
  • The Human Rights Act 1998
  • The Freedom of Information Act 2000
  • Regulation of Investigatory Powers Act 2000
  • Telecommunications (Lawful Business Practice), (Interception of Communications) Regulations 2000
  • Privacy and Electronic Communications Regulations 2003
  • Obscene Publications Act 1964
  • Protection of Children Act 1999
  • Criminal Justice Act 2003
  • Copyright, Designs and Patents Act (1988)
  • Computer Misuse Act (1990)
  • Protection from Harassment Act 1997
  • Sex Discrimination Act 1975
  • Race Relations Act 1976;

This is not an exhaustive list. We'll endeavour to comply with this and other relevant laws and legislation.

Security and risk management

Under common law, all users must keep information confidential and only use it for its intended purpose.

We carry out security risk assessments for all business processes covered by this policy. These assessments:

  • cover all systems, applications and networks that support those processes
  • identify and apply appropriate controls to protect against risks to confidentiality, integrity and availability
  • use a recognised method for assessing security risks

Policies, procedures and training

We will:

  • produce system security policies for major systems, based on risk and a standard template
  • develop system operating procedures and make sure users understand them
  • provide security awareness training so users understand their responsibilities
  • give users clear security guidance and explain that misuse may lead to disciplinary action

Business continuity and system management

We will:

  • create and regularly test business continuity and disaster recovery plans for critical systems
  • use effective configuration management for all systems, applications and networks
  • protect systems from viruses and other malicious software

Monitoring and incident management

We will:

  • monitor systems, where possible, to detect security risks or breaches
  • carry out penetration testing where appropriate
  • make sure any suspected security incidents or weaknesses are reported and investigated

Managing access and third‑party connections

We will:

  • make sure all connections to external systems have approved security policies
  • make sure third‑party access to our systems is documented and approved

Governance and assurance

We will:

  • review all systems before they go live to ensure they meet security requirements
  • review and approve any changes that could affect system security
  • put in place encryption policies for mobile devices and data, in line with current standards

Definitions

Personal data

UKGDPR Article 4(1) and Chapter 2 of the Data Protection Act 2018 defines personal data as: 'any information relating to an identified or identifiable natural person (the data subject). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as:

  • a name
  • an identification number, such as an employee number
  • location data, such as your home address
  • an online identifier 

Special category data

UKGDPR Article 9(1) defines special category data as 'data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.'

Special category data includes information about criminal convictions and offences.

When data is lost or disclosed, we consider the type of information involved. This is usually categorised as:

  • public data
  • internal data 
  • confidential or sensitive data 
  • highly confidential data 

Public data

Public data is information we can share openly without causing harm to the Council.

Internal data

Internal data is information about the day‑to‑day business of the council. We may share this information with third parties where there is a contract or an appropriate information sharing agreement in place. It could have some impact on the council, but this is usually minor.

Confidential or sensitive data

Confidential or sensitive data is information that is personal, restricted or commercially sensitive, including intellectual property. 

We only share this information with authorised people within the Council, or with partners where there is a contract or an appropriate information sharing agreement in place.

If this data is lost or disclosed, it could have a serious impact on individuals and on council services. It is likely to be considered a data breach under UKGDPR.

Highly confidential data

Highly confidential data is information that would cause significant harm to the council’s activities or reputation if it were shared. This may include personal or sensitive data, or information about the security of the area or the people within it.

If this data is lost, disclosed or accessed without permission, it is likely to be a data breach under UKGDPR.

We restrict access to this information. Only people who need it for their work can use it.

Types of information

Information is created when we collect and combine data. 

We may hold and use information in different formats, including:

  • electronic records
  • paper documents
  • phone calls
  • audio or video recordings
  • conversations

In this policy, we use ‘information’ and ‘data’ to mean the same thing. 

Personal and sensitive information can include:

  • personal data that identifies a person, such as a name, postcode or driving licence number
  • commercially sensitive information, including details of business proposals or ongoing negotiations
  • politically sensitive information
  • information about security, investigations or legal proceedings
  • information shared in confidence
  • personal or sensitive information provided by other organisations, such as the NHS, central government or the police

This is not a complete list.

How to identify personal or sensitive information

Information can be identified as personal or sensitive if:

  • it is covered by the Data Protection Act 2018
  • sharing it could harm individuals, the public, the Council or a partner organisation
  • sharing it could affect the outcome of negotiations or investigations

Roles and responsibilities 

There are a number of officers and teams across the Council that have professional expertise relating to data protection and information security.

Read the full responsibilities of all users with legitimate access to council data

Policy validity 

We review this policy every year. The Information Security Manager leads the review, and the Senior Information Risk Owner (or an authorised deputy) approves it.

We review and update related information security standards on an ongoing basis.

Audit

We regularly audit compliance with this policy against information governance standards. These standards are subject to routine and statutory assessments, as well as internal and external audits.

Contact us

If you have any questions or concerns, please contact us.

Data Protection
Email: dataprotection@westmorlandandfurness.gov.uk  

Information Security
Email: security@westmorlandandfurness.gov.uk