Skip to main content

Part of Infrastructure hosting standards for the NHS

Leadership and governing standards

Current Chapter

Current chapter – Leadership and governing standards


Standards you should meet on senior leadership and ownership of networks and connectivity.


1. NHS organisations should have senior leadership team (SLT) responsibility for Infrastructure Hosting

Importance of meeting the standard

Having clearly defined roles and responsibilities and an owner will help focus the organisations infrastructure hosting strategy. Without this focus, there’s a risk that: 

  • the use of hosting technology will only meet short-term needs and could lead to additional unplanned costs 
  • digital strategies do not account for hosting requirements for new digital services and there is insufficient hosting capacity available, delaying implementation

When to meet the standard

You should meet this standard when
  • the use of hosting technology will only meet short-term needs and could lead to additional unplanned costs 
  • digital strategies do not account for hosting requirements for new digital services and there is insufficient hosting capacity available, delaying implementation

How to meet the standard

NHS organisations should assign a member of their SLT to
  • have strategic oversight of infrastructure hosting and how it fits with wider digital strategies
  • ensure the organisations position against the NHS England Infrastructure Hosting standards is reviewed annually
  • create and manage a hosting strategy led by the needs of staff and patients
  • ensure infrastructure hosting requirements are included in disaster recovery and business continuity plans
  • regularly review and update all relevant strategies and plans

IBM to NHS infrastructure hosting standards mapping

This mapping shows derivation, not strict equivalence. Multiple IBM controls are often collapsed into a single NHS outcome‑based standard.

2. Power and cooling

1.1  Resilient and protected power arrangements

IBM source references

PC‑1 Power Circuit

PC‑2 UPS

PC‑3 Dual Path

PC‑5 Generator

PC‑9 Power Outages & Spikes

1.2 Stable and monitored environmental conditions

IBM source references

PC‑4 Cooling Capacity

PC‑6 Environmental Monitoring

PC‑7 Power & Cooling Systems PC‑8 Failure Alerts

3. Environmental and physical protection

2.1 Physical security proportionate to risk

IBM source references

PS‑1 Secure Areas

PS‑2 Physical Access Controls

2.2 Fire detection and suppression controls

IBM source references

PE‑3 Fire Alarm

4. Rack, cabinet and space management

3.1 Racks and cabinets installed and secured

IBM source references

CS‑1 Infrastructure Housing

3.2 Structured cabling and cable management

IBM source references

PE‑4 Network cabling

PE‑6 Power and telecommunications cabling

3.3 Capacity, layout and scalable hosting design

IBM source references

CS‑5 Monitoring of Resources (capacity aspects)

AS2 Scalability & Resilience

PE‑1 Dedicated Data Centre

5. Hosting architecture and resilience

4.1 Resilient hosting, avoiding single points of failure

IBM source references

AS‑2 Scalability and Resilience

SA‑5 System Redundancy

4.2 High availability with documented dependencies and failover

IBM source references

SA‑5 System Redundancy

SA‑9 Application Performance & Availability

AS4 Architecture Diagrams

CS4 CMDB

6. Back up

5.1 Backups aligned to BCDR and requirements

IBM source references

Ops‑3 Server Backup

SA‑12 Application Backup

Ops‑4 DRP

5.2 Restore capability, testing and recovery times

IBM source references

Ops‑3 Server Backup

Ops‑4 DR Testing

7. Disaster recovery and business continuity

6.1 DR arrangements defined, documented and maintained

IBM source references

Ops‑4 DRP

AS‑4 Architecture Diagrams

6.2 Recovery objectives understood, tested and inform decisions

IBM source references

Ops‑4 DRP

SA‑5 System Redundancy

8. Maintenance, monitoring and operational management

(Post‑merge structure: Monitoring, maintenance, incident  and change)

7.1 Proactive monitoring of hosted infrastructure

IBM source references

Ops‑6 Infrastructure Monitoring

Ops‑7 Device Monitoring

Ops‑8 Event Logs

7.2 Planned, controlled maintenance

IBM source references

Ops‑1 Preventative Maintenance

7.3 Incident and change management

IBM source references

Ops‑11 Incident Management

Ops‑12 Change Management

9. Asset lifecycle and configuration management

8.1 Visibility of assets and lifecycle status

IBM source references

CS‑2 Hardware Lifecycle Management

CS‑3 Asset Inventory

Ops‑5 Asset Management

8.2 Configuration documentation and dependencies

IBM source references

CS‑4 Configuration Management Database

AS‑4 Architecture Diagrams

8.3 Asset and configuration information supports planning and resilience

IBM source references

CS‑2 Hardware Lifecycle

CS‑5 Monitoring of Resources

Ops‑5 Asset Management


Last edited: 18 June 2026 2:27 pm