to add a new content
Resource
Joint Crown Prosecution Service (CPS) & Police Principles for Redaction

This document contains the agreed principles for redaction of information from digital (and physical) material by police for legal or security reasons. Material includes statements, documentary exhibits, audio and video recordings, digital material, and other sources of information such as crime reports. 

Effective redaction allows police and CPS to share and serve relevant information whilst complying with the Data Protection Act 2018 (DPA) and the Criminal Procedure and Investigation Act 1996 (CPIA 1996) / CPIA Code of Practice (CPIA Code) whilst protecting and safeguarding personal and sensitive data.

Published 01/08/2021
Authoring body: National Police Chiefs Council (NPCC) / Crown Prosecution Service (CPS)
Principles
Resource
Police Assured Landing Zone (PALZ) Amazon Web Services (AWS) Blueprint

The AWS Police Assured Landing Zone (PALZ), is a set of configuration, code, security model and design decision rationale artefacts created specifically for policing workloads.  The goal is to enable policing organisations to get started using cloud services more quickly, with confidence that they are implementing an assured set of baseline controls, reviewed by National Police Technology Council (NPTC), Police Digital Service (PDS) and National Police Information Risk Management Team (NPIRMT). These control documents are available in the PALZ documentation set. This will allow them to focus their efforts on activities and assurances unique to their workloads.

PALZ provides a landing zone with a multi-account structure aligned with AWS best practice including standardised AWS account and organisational unit (OU) structure, best-practice centralised networking and additional preventative and detective guardrails. It also provides a series of AWS Service Catalogue portfolios and products, which provide a self-service capability that greatly simplifies tasks such as the provisioning of new AWS accounts and the creation of private networks within an AWS account. Finally, PALZ integrates with a number of AWS security services to provide dashboards and alerts which support ongoing compliance monitoring, plus alignment to NEP designs for IAM and NMC.

PALZ has been through the NPTC “Security by Design” process. This process identifies key design decisions which are related to form a series of risks identified with common policing data. NPTC have used an independent third-party assessor to review the design decisions and generate the assurance documentation. This has been reviewed by the Police assuror, National Police Information Risk Management Team (NPIRMT), to approve the security controls and the solution design.

Note: This blueprint is marked OFFICIAL-SENSITIVE, for enquiries on access please contact the National Standards team who can put you in touch with the relevant team

Published 01/06/2021
Authoring body: Amazon / Police Digital Service (PDS)
Reference Data / Templates
Resource
Management of Police Information (MoPI) APP

This Authorised Professional Practice (APP) provides guidance to forces on meeting the requirements of the Management of Police Information (MoPI) Code of Practice in relation to the review, retention and disposal of policing information and records. This APP is supplemented by the Manual of Guidance, which provides a further level of operational data.

Police information refers to all information obtained, recorded or processed for a policing purpose. The Management of Police Information (MoPI) authorised professional practice (APP) provides a framework and guidelines for managing police information, complying with the law and managing risk associated with police information including data retention.

  • Policing information is information held for a policing purpose. The MoPI Code of Practice definition of ‘policing purpose’ is:
    • protecting life and property
    • preserving order
    • preventing the commission of offences
    • bringing offenders to justice
    • any duty or responsibility of the police arising from common or statute law
  • Corporate information includes other organisational information, such as HR or finance records, minutes of meetings, policies and procedures.

There is further information on compliance with the Freedom of Information Act.

It should also be noted that the retention periods for biometric data are governed by the Protection of Freedoms Act 2012 and sit outside this APP.

Published 06/05/2020
Authoring body: College of Policing (CoP)
Guidance
Resource
ACPO Good Practice Guide for Digital Evidence (Version 5)

This ACPO guide contains a set of golden principles for management of digital evidence and guidance on each stage in the evidence lifecycle: Plan, Capture, Analyse and Present. This guide represents good practice across a broad digital forensic landscape for policing.

Although dated, this guide has been reviewed in March 2021 by the National Standards Assurance Board and deemed current and relevant.

Published 01/03/2012
Authoring body: Association of Chief Police Officers (ACPO)
Guidance
Resource
National Policing Digital Strategy 2020-2030

The National Policing Digital Strategy sets out a new digital ambition for UK policing. It presents a set of tangible digital priorities and outlines the key data and technology building blocks required to deliver them. 

The strategy contains 5 priorities:

  1. Seamless citizen experience
  2. Addressing harm
  3. Enabling officers & staff through digital
  4. Embedding a whole public system approach
  5. Empower the private sector
Published 01/01/2020
Authoring body: Police Digital Service (PDS)
Principles