to add a new content
Resource
Cyber Security Architectural Principles

This document provides all National Policing and its partners with a clear set of security architectural principles, which are the foundation to build, design and implement secure solutions.

Published 01/05/2023
Authoring body: Police Digital Service (PDS)
Principles
Resource
Data Protection

On the 25th May 2018 the Data Protection Act 2018 was implemented by the UK as the General Data Protection Regulation also known as GDPR. It controls how personal information is captured and used by organisations and the government.

Everyone responsible for using personal data has to follow strict rules called ‘data protection principles’ and must ensure that the information they obtain is for a lawful purpose, used fairly and must be transparent about its intended purpose of usage and used explicitly for that purpose only.

Data should also not be kept for more than is necessary, and whilst it is kept, should be kept up to date and handled and secured in a way that does not compromise its protection from unauthorised processing, loss of theft of data.  

It is important to note that there is stronger legal protection for more sensitive information such as race, health, sex life, orientation, ethnic background. There are separate safeguards for personal data relating to criminal convictions and offences.

Under the Data Protection Act 2018, an individual has the right to find out what information the government and other organisations holds about them and this ideally should be provided to the individual within 1 month.  

To make a complaint about the misuse of personal information or lack of security it should be made to the organisation, following their response the complaint can also be made to the Information Commissioner’s Office.

ICO
casework@ico.org.uk
Telephone: 0303 123 1113

Published 01/01/2018
Authoring body: Information Commissioner's Office (ICO)
Principles
Resource
NCSP Management of High Risk Applications standard v1.1

This standard outlines the minimum requirements and controls that must be met to ensure the secure management of applications identified as high risk.

Published 01/10/2024
Authoring body: Police Digital Service (PDS)
Standards
Resource
NCSP Robotic process automation guideline

This guideline describes best practice risk management controls for using Robotic Process Automation (RPA) for the purpose of automating manual administrative overheads for National Policing Forces and applications

Published 01/10/2024
Authoring body: Police Digital Service
Guidance
Resource
NCSP MS Power platform guideline v1.0

This guidance is to assist members of the UK policing community of trust in the design, setup and use of Microsoft’s Power Platform service, incorporating Power Apps, Power Automate, and Power Pages.

Published 01/10/2024
Authoring body: Police Digital Service (PDS)
Guidance
Resource
NCSP Vetting requirements for policing guideline v1.3

This guidance describes the requirements for access to policing assets including premises, information, and information systems. This document should be read in conjunction with the Statutory Vetting Code of Practice and Authorised Professional Practice on Vetting

Published 02/09/2024
Authoring body: Police Digital Service (PDS)
Guidance
Resource
NCSP Security Management standard v1.1

This standard describes the requirements to implement and maintain an effective cyber security management system as required by the National Policing Community Security Policy Framework.
Implementation of this standard will help members to ensure that adequate management controls and oversight is in place to mature their cyber resilience

Published 02/09/2024
Authoring body: Police Digital Service
Standards
Resource
Security Management Standard v1.0

This standard describes the requirements to implement and maintain an effective cyber security management system as required by the National Policing Community Security Policy Framework.
Implementation of this standard will help members to ensure that adequate management controls and oversight is in place to mature their cyber resilience.

Published 01/10/2023
Authoring body: Police Digital Service (PDS)
Principles
Resource
NCSP Security Governance standard v1.1

This Standard defines the requirements to implement Security Governance as mandated in the National Community Security Policy

Published 02/09/2024
Authoring body: Police Digital Service (PDS)
Standards
Resource
NCSP Safe Deployment of High Risk Applications Guideline v1.1

This guideline outlines approaches to follow for any use of high risk applications to reduce risk.

Published 01/08/2024
Authoring body: Police Digital Service (PDS)
Guidance