Skip to main content

Data Security Standard 6 - Responding to incidents

Current Chapter

Data Security Standard 6 - Responding to incidents


This guidance relates to the 2023-24 (version 6) standard. 


Overview

Cyber-attacks against services are identified and resisted and CareCERT security advice is responded to. Action is taken immediately following a data breach or a near miss, with a report made to senior management within 12 hours of detection.
All staff are trained in how to report an incident, and appreciation is expressed when incidents are reported. Sitting on an incident, rather than reporting it promptly, faces harsh sanctions. The Board understands that it's ultimately accountable for the impact of security incidents, and bears the responsibility for making staff aware of their responsibilities to report upwards. Basic safeguards are in place to prevent users from unsafe internet use. Anti-virus, anti-spam filters and basic firewall protections are deployed to protect users from basic internet-borne threats.

Please refer to further note on professional judgement, auditing and UK GDPR.


Last edited: 28 September 2023 11:07 am