There may be some government agencies where Information Security is the
overarching issue (especially after all the recent kerfuffle), but surely
Data Protection is about compliance with all eight Principles, not just
Principle 7? In many organisations Information Security is possibly less
important than offering the right choices to comply with Principle 1 (or
have I misunderstood what InfoSec is?).
I feel there must be a matrix, not a hierarchy. For example,
Confidentiality is a major component of Data Protection and Information
Security, but also stands in its own right, because confidentiality covers
information that is not personal data, and may not even be recorded, and it
is subject to both common and contractual law. So now we've got three
interlocking policies, as a minimum, all giving a different and important
slant.
For the record, I'm with the 'short policy, backed up with explanation and
procedures (which may be long), and staff guidance (which must be short)'
brigade.
Paul Ticher
0116 273 8191
22 Stoughton Drive North, Leicester LE5 5UB
----- Original Message -----
From: <[log in to unmask]>
To: <[log in to unmask]>
Sent: Thursday, November 19, 2009 10:04 AM
Subject: Re: Data Protection and Information Security Policies
>
> UNCLASSIFIED
>
> For the probation service nationally Information Security is the
> overarching policy, under which there are 14 further policies including
> Data Protection, Protective Marking, Physical Security, Password Control,
> Vetting, Email Communication. They are not short policies - the DP one is
> 47 pages long!
>
> Hilary
>
> Hilary Lawrenson, Information Security Officer
> South Yorkshire Probation Area
> Head Office, 45 Division Street, Sheffield, S1 4GE
>
> Tel 0114 276 6911 Fax 0114 276 1967
>
>
>
> "Barlow, Jackie" <[log in to unmask]>
> Sent by: This list is for those interested in Data Protection issues
> <[log in to unmask]>
> 18/11/2009 15:42 Please respond to
> "Barlow, Jackie" <[log in to unmask]>
>
>
> To [log in to unmask]
> cc
> Subject [data-protection] Data Protection and Information
> Security Policies
>
>
>
>
>
>
>
> Dear colleagues,
>
> I am fairly new to the role of Records Manager here at Anglia Ruskin and I
> have recently revised our Data Protection Policy. Our Information
> Security
> Policy is also currently being revised and I am unsure which of these
> policies should be the overarching one.
>
> I would be grateful for your opinions on this and any information on your
> current practices.
>
> Kind regards
> Jackie
>
>
>
> Jacqueline Barlow ACIB MBA
> University Records Manager
>
> Anglia Ruskin University
> Office of the Secretary and Clerk
> 3rd Floor
> Tindal Building
> Chelmsford
> CM1 1SQ
>
> Direct dial 0845 196 4215
>
>
>
> --
> EMERGING EXCELLENCE: In the Research Assessment Exercise (RAE) 2008, more
> than 30% of our submissions were rated as 'Internationally Excellent' or
> 'World-leading'. Among the academic disciplines now rated 'World-leading'
> are Allied Health Professions & Studies; Art & Design; English Language &
> Literature; Geography & Environmental Studies; History; Music; Psychology;
> and Social Work & Social Policy & Administration. Visit
> www.anglia.ac.uk/rae for more information.
>
>
>
> This e-mail and any attachments are intended for the above named
> recipient(s)only and may be privileged. If they have come to you in
> error you must take no action based on them, nor must you copy or show
> them to anyone please reply to this e-mail to highlight the error and
> then immediately delete the e-mail from your system.
>
> Any opinions expressed are solely those of the author and do not
> necessarily represent the views or opinions of Anglia Ruskin University.
>
> Although measures have been taken to ensure that this e-mail and
> attachments are free from any virus we advise that, in keeping with good
> computing practice, the recipient should ensure they are actually virus
> free.
>
> Please note that this message has been sent over public networks which may
> not be a 100% secure communications
>
> Email has been scanned for viruses by Altman Technologies' email
> management service -
> www.altman.co.uk/emailsystems
> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
> All archives of messages are stored permanently and are
> available to the world wide web community at large at
> http://www.jiscmail.ac.uk/lists/data-protection.html
> If you wish to leave this list please send the command
> leave data-protection to [log in to unmask]
> All user commands can be found at
> http://www.jiscmail.ac.uk/help/commandref.htm
> Any queries about sending or receiving messages please send to the list
> owner
> [log in to unmask]
> Full help Desk - please email [log in to unmask] describing your
> needs
> To receive these emails in HTML format send the command:
> SET data-protection HTML to [log in to unmask]
> (all commands go to [log in to unmask] not the list please)
> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>
>
> **********************************************************************
>
> This email & any files transmitted with it are private & intended solely
> for the use of the individual or entity to whom they are addressed. If you
> are not the intended recipient, the e-mail & any attachments have been
> transmitted to you in error & any copying, distribution or use of the
> information contained in them is strictly prohibited.
>
> The National Probation Service may monitor the content of the e-mails sent
> & received via its network for the purposes of ensuring compliance with
> its policies & procedures.
>
> Any views or opinions presented are only those of the author & not those
> of the National Probation Service.
>
> **********************************************************************
>
>
>
>
> --------------------------------------------------------------------------------
>
> All archives of messages are stored permanently and are available to the
> world wide web community at large at
> http://www.jiscmail.ac.uk/lists/data-protection.html
>
> Selected commands (the command has been filled in below in the body of the
> email if you are receiving emails in HTML format):
>
> a.. Leaving this list: send leave data-protection to
> [log in to unmask]
> b.. Suspending emails from all JISCMail lists: send SET * NOMAIL to
> [log in to unmask]
> c.. To receive emails from this list in text format: send SET
> data-protection NOHTML to [log in to unmask]
> d.. To receive emails from this list in HTML format: send SET
> data-protection HTML to [log in to unmask]
> All user commands can be found at
> http://www.jiscmail.ac.uk/help/commandref.htm and are sent in the body of
> an otherwise blank email to [log in to unmask]
>
> Any queries about sending or receiving messages please send to the list
> owner [log in to unmask]
>
> (Please send all commands to [log in to unmask] not the list or the
> moderators, and all requests for technical help to
> [log in to unmask], the general office helpline)
>
> --------------------------------------------------------------------------------
>
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|