Researching this
I am sure many of us are having similar issues.
Researching this recently I discovered a number of Council's have
adopted policy along the lines
"All information assets, where appropriate, must be assessed and
classified by the owner in accordance with the HMG Security Policy
Framework (SPF)... Disclosing PROTECT or RESTRICTED classified
information to any external organisation is also prohibited, unless via
the GCSx email." [Wokingham BC]
But of course there may be many occasions where we wish to disclose
personal data, to another body who is not and has no reason to be on
GCSx e.g. giving a job reference. One can I suppose adopt the artifice
of unprotecting the reference once it is written and I see increasing
numbers of emails with markings such as "** Protective Marking : NOT
PROTECTIVELY MARKED ** ". However that does not seem right to me. We
can give a reference to a specific person because we have consent to do
so. That does not mean however that the information is no longer
confidential and needs no protection.
Also the policy above, as written, would seem to preclude hand to hand
delivery - possibly the securest method of all in many cases !
Phillip Bradshaw
Information Manager
Clerk to the Council
Room CY4B, County Hall
EMail: [log in to unmask]
Phone: 029 2087 3346
Mobile : 07890 265987
Fax: 029 2087 3349
Mae Cyhoeddi Cynnar yn Codi Canfod Cadarnhaol
Proactive Publishing Promotes Positive Perceptions
-----Original Message-----
From: This list is for those interested in Data Protection issues
[mailto:[log in to unmask]] On Behalf Of Susan Ferguson
Sent: 30 July 2009 10:23
To: [log in to unmask]
Subject: [data-protection] GOV Connect and National Protective marking
scheme
***APOLOGIES FOR CROSS POSTING ******
Dear all
Just wondering if anyone has developed an updated information
classification policy for local authorities to meet GOVConnect
requirements and the National Protective Marking Scheme. The guidance I
have seen is focussed on central government and covers the 2 main
classifications only.
As this is being rolled out nationally, I am sure there will be others
scratching their head for inspiration. I am will willing to share our
draft policy, but would appreciate it anyone has drafted a similar
policy to meet these new requirements, which they would be willing to
share.
I am happy to respond offline if you would prefer and I will circulate
the results.
Many thanks
Susan Ferguson
Corporate Information Governance Officer Newcastle City Council tel 0191
2116644 [log in to unmask]
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask] All user
commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list
owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your
needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
**********************************************************************
Privileged/Confidential Information may be contained in this message. If you are not the addressee indicated in this message (or responsible for delivery of the message to such person), you may not copy or deliver this message to anyone. In such case, you should destroy this message and kindly notify the sender by reply email. Please advise immediately if you or your employer does not consent to Internet email for messages of this kind. Opinions, conclusions and other information in this message that do not relate to the official business of the Council of the City and County of Cardiff shall be understood as neither given nor endorsed by it. All e-mail sent to or from this address will be processed by Cardiff County Councils Corporate E-mail system and may be subject to scrutiny by someone other than the addressee.
**********************************************************************
Mae'n bosibl bod gwybodaeth gyfrinachol yn y neges hon. Os na chyfeirir y neges atoch chi'n benodol (neu os nad ydych chi'n gyfrifol am drosglwyddo'r neges i'r person a enwir), yna ni chewch gopio na throsglwyddo'r neges. Mewn achos o'r fath, dylech ddinistrio'r neges a hysbysu'r anfonwr drwy e-bost ar unwaith. Rhowch wybod i'r anfonydd ar unwaith os nad ydych chi neu eich cyflogydd yn caniatau e-bost y Rhyngrwyd am negeseuon fel hon. Rhaid deall nad yw'r safbwyntiau, y casgliadau a'r wybodaeth arall yn y neges hon nad ydynt yn cyfeirio at fusnes swyddogol Cyngor Dinas a Sir Caerdydd yn cynrychioli barn y Cyngor Sir nad yn cael sel ei fendith. Caiff unrhyw negeseuon a anfonir at, neu o'r cyfeiriad e-bost hwn eu prosesu gan system E-bost Gorfforaethol Cyngor Sir Caerdydd a gallant gael eu harchwilio gan rywun heblaw'r person a enwir.
**********************************************************************
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|