Skip to main content

Part of Objective B - Protecting against cyber attacks and data breaches

Principle: B1 Policies, processes and procedures

B1.a Policy, process and procedure development

“You have developed and continue to improve a set of information assurance and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact to your essential function(s).”

Overview

This outcome is about ensuring that you have effective cyber security and information governance (IG) policies, processes and procedures in place.

Policies, processes and procedures

Your organisation should have a suite of policies, processes and procedures in place to guide its cyber security and IG activities. You should appropriately scope the policies to cover your people, processes and technology. The policies should be driven by risks and signed off by the board representative.

These policies, processes and procedures should be documented in a central location accessible to all staff who need to refer to them, along with accompanying registers or logs which show how they have been approved, reviewed and managed over time.  

Examples of areas your policies, processes and procedures should cover, but not be limited to, include:

  • IG oriented topics such as: confidentiality and data protection, data breaches, consent, data protection by design, data protection impact assessments, transparency, data subject rights and information sharing 
  • cyber security-oriented topics such as information technology (IT) acceptable use policy, data security, asset management, access control, change management, business continuity and disaster recovery, encryption, anti-virus/malware, vulnerability management, patch management, network security, problem management, data backups, remote working and portable devices, IT disposal, configuration management, security logs, events management 
  • supply chain oriented topics, such as: procurement, contracts, supplier obligations for data security and protection, incident management support
  • risk management and assurance
  • incident management
  • records management
  • data quality
  • re-use of public sector information (if applicable)
  • freedom of information (FOI) and environmental information regulations (if applicable)

Technical security practice and specific regulatory compliance

The CAF aligned DSPT outcomes and relevant regulatory guidance can help you understand the topics your policies should cover. 

NHS England and DHSC do not require organisations to take a particular approach in most areas. However, where national directive policy requirements exist, you must comply with them to meet the relevant CAF aligned DSPT outcomes. 

You should use your professional judgment to determine whether your policies appropriately guide your technical security practices and meet regulatory compliance.

Good reference points for technical security practice and specific regulatory compliance in cyber security and IG include:

Reviews and updates

You should review your policies, processes and procedures on a regular scheduled basis, with a justifiable rationale for time intervals between reviews and whenever significant changes occur.  

Your approach should ensure they remain effective at delivering the desired outcomes and they are appropriate in the context of existing legislation and regulatory practice. 

National policies and legal frameworks

Ensuring local policies reflect changes at the legal and national level should be part of your policy, process and procedures review process.

You should engage with communities of practice, national communications and NHS England and DHSC resources (such as the NHS England IG portal) to ensure that you are aware of changes in the law and national policy directives, and how they impact your local policies. 

Each organisation is fully accountable for all their own legal obligations. The requirements of the DSPT do not represent the entirety of these obligations, and organisations should seek legal assurances separately where necessary to ensure they are complying with the law.

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • policies, processes and procedures relevant to security governance, risk management, technical security and regulatory compliance
  • evidence of policies, processes and procedures being updated following major cyber security incidents and data breaches  
  • evidence of key information governance and cyber security principles being considered 
  • evidence of mapping policies, processes and procedures to essential functions and technologies 
  • evidence of assessing applicability of policies, processes and procedures to staff groups
  • evidence of key performance indicator (KPI) reporting to senior management
  • evidence of regular review of documentation
  • evidence of review of documentation following any changes to the essential functions, or changes to the threats faced by those functions
  • evidence of design and implementation of failsafe measures

This is not an exhaustive list. You're welcome to provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross-reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate. 

Interpreting indicators of good practice

Indicator(s) of good practice Term Interpretation

PA#1

Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.

'policies, processes and procedures'

A 'policy' is a deliberate system of rules to guide decisions and achieve desired outcomes. A policy can be considered as a simple statement of your organisation’s position on a chosen topic (the 'why'). 

'Processes' or 'procedures' are practical steps to complete a given task, which might contribute towards the implementation of a policy (the ‘how’).

How you define what constitutes a 'policy', a 'process' or a 'procedure' is not important. What is important is that together, they set out clear, documented expectations for how data security and protection-related activities should be conducted within your organisation. 

A#3

Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to your essential function(s) 

'essential function(s)'

Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions.

For more information, see guidance on scoping essential functions.

National services

The following national services may help you to meet the requirements of B1.a Policy process and procedure development: 

Additional guidance

For additional guidance, see:

National Cyber Security Centre CAF guidance | B1 Service protection policies, processes and procedures
Information Commissioner’s Office | Policies and procedures


B1.b Policy, process and procedure implementation

“You have successfully implemented your information assurance policies, processes and procedures and can demonstrate the benefits achieved.”


Overview

This outcome is about ensuring that your organisation’s cyber security and information governance (IG) policies and processes are effectively implemented and followed.

Monitoring policies, processes and procedures

You should have methods of evaluating whether your policies, processes and procedures are being followed by staff members.

Spot checks should form part of your policy, process and procedure monitoring activities. Areas could include, but should not be limited to:

  • joiner/mover/leaver processes, for example checking that departed staff members have promptly had access rights revoked
  • privileged access, for example regularly reviewing staff members with elevated administrator access rights and ensuring they still have a legitimate business need
  • asset management such as checking whether new assets and data flows are being appropriately registered
  • information sharing, such as reviewing disclosure logs for ad hoc disclosures for purposes other than direct care
  • individual rights, for example checking that individual rights requests are responded to within legal deadlines
  • incident reporting, for example comparing numbers of incident reports or time taken to report incidents across departments

Breaches of policies, processes and procedures

You may become aware of breaches of your policies, process and procedures through alerts, reports and investigations. 

You should take a consistent, documented approach to investigating and using these breaches to make improvements. This might mean: 

  • ensuring policies, processes and procedures, as well as accountability for deliberate or avoidable breaches, are communicated to staff members
  • reinforcing policies, processes and procedures through training and awareness activities  
  • conducting follow up spot checks to ensure lessons have been learned
  • implementing amendments to policies, processes or procedures where these are found to be inadequate or difficult to follow

With an understanding of how and why policies are not being followed, you can take corrective action to address the problem. 

See D2.b Using incidents and near misses to drive improvements for additional considerations to be made when the policy, process or procedural breach is associated with an incident or near miss. 

Staff awareness

Your training and awareness activities should be designed to make staff members aware of information assurance policies, processes and procedures that are relevant to their role, and ensure they have the skills to implement them. 

In addition, all staff with access to confidential patient information should be aware of their obligation to handle information responsibly and the accountability they hold for deliberate or avoidable breaches.

See B6.b Training for more information.

Integrating policies, processes and procedures across your organisation

You should demonstrate that you have considered areas of your organisation where business processes should be integrated with cyber security and IG processes to improve overall data protection and security resilience. Some typical examples are:

  • procurement - integrating data protection and security considerations into service design, bid evaluation, contracting, re-contracting and due diligence procedures (See A4.a Supply chain)   
  • HR - linking joiners, movers and leavers events with identity and access management controls
  • HR – reviewing system permissions following disciplinary action 
  • communications and engagement - ensuring adherence to data protection and security principles in outgoing communications  

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • evidence of monitoring of the application of policies, processes and procedures
  • evidence of integration between the policies, processes and procedures of different teams and departments 
  • evidence showing how staff are made aware of policies, processes and procedures
  • investigation process for breaches of policies, processes and procedures, and evidence that the process is followed
  • process for tracking and assessing breaches of policies, processes and procedures, and evidence that the process is followed
  • evidence of monitoring activities being used to improve policies, processes and procedures
  • evidence of successful segmented communication approach to staff members 
  • evidence of analysis and remediation of aggregated breaches

This is not an exhaustive list. You're welcome to provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate. 

Interpreting indicators of good practice

Indicator(s) of good practice

Term Interpretation

PA#1

Most of your policies, processes and procedures are followed and their application is monitored.

'policies, processes and procedures'

A 'policy' is a deliberate system of rules to guide decisions and achieve desired outcomes. A policy can be considered as a simple statement of your organisation’s position on a chosen topic (the 'why'). 

'Processes' or 'procedures' are practical steps to complete a given task, which might contribute towards the implementation of a policy (the ‘how’).

How you define what constitutes a 'policy', a 'process' or a 'procedure' is not important. What is important is that together, they set out clear, documented expectations for how data security and protection-related activities should be conducted within your organisation.

PA#4

All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.

'essential function(s)'

Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions.

For more information, see guidance on scoping essential functions.

National services

The following national services may help you to meet the requirements of B1.b Policy process and procedure implementation. 

Additional guidance

For additional guidance, see:

National Cyber Security Centre CAF guidance | B1 Service protection policies, processes and procedures
National Cyber Security Centre | You shape security
Information Commissioner’s Office | Policies and procedures


Last edited: 26 August 2026 12:09 pm