to add a new content
Resource
Open Referral UK Standards

Open Referral UK is an open data standard in use by Local Government. This standard establishes a consistent way of publishing and describing information for councils, to ensure the data is effectively used and shared for the benefit of local communities and services (https://www.localdigital.gov.uk/)

Published 01/01/2019
Authoring body: Open Referral UK
Standards
Resource
Cloud Enablement

Project to identify and provide support to forces as they transition capabilities from legacy on-premises systems to cloud technologies.

For further information, please use the 'Contact Us' tab, to get in touch with the relevant authoring team.

Published 01/01/2022
Authoring body: Police Digital Service (PDS)
Guidance
Resource
ISO 17020:2012 Requirements for the operation of various types of bodies performing inspection (Crime Scene Investigation)

ISO 17020:2012 specifies requirements for the competence of bodies (including police forces) performing inspection and for the impartiality and consistency of their inspection activities, this specifically relates to forensic practitioners conducting examinations at scenes of crime.

Published 01/04/2012
Authoring body: International Standards Organisation (ISO)
Standards
Resource
Data Protection Manual

This manual has been produced by the NPCC Data Protection, Freedom of Information, information Sharing and Disclosure Portfolio Group on behalf of the NPCC. It is updated and adapted to reflect decisions made by the NPCC, views of the Information Commissioner’s Office (ICO) (where appropriate) and the evolution of the legislation as it is interpreted, challenged or reviewed.

Note that this manual has not yet been updated to reflect the legislative changes arising from The Data Protection, Privacy and Electronic Communications (Amendments etc)(EU Exit) Regulations 2019 as amended by The Data Protection, Privacy and Electronic Communications (Amendments etc)(EU Exit) Regulations 2020.

The manual should be regarded as a document that both helps to create an environment across the police service in which compliance can be achieved, and as a means of providing guidance in areas of police business where the Act is regularly applied.

The manual contains a wide variety of information including:

  • Breakdown of governance and responsibilities
  • Definitions
  • General processing (GDPR & DPA Part 2)
  • Comparison between General Processing and Law Enforcement obligations
  • Law Enforcement processing (Part 3 of DPA)
  • Intelligence Service processing (Part 4 of DPA)
  • Assessing data protection compliance
  • The Commisioner, enforcement & offences
  • Case studies
  • Wide variety of appendices including
    • Template DPIA
    • Template National data processing contract
    • Template information sharing agreement
    • Template Data Protection policy 
Published 01/03/2021
Authoring body: National Police Chiefs Council (NPCC)
Guidance
Resource
Digital Investigation & Intelligence APP

The digital policing learning programme was created to for officers and staff to update their knowledge regarding digital intelligence and investigation. The programme helps explains the use and misuse of devices and applications and how they appear in the policing world. 

The programme’s aim is to ensure that all staff are:

  • confident facing situations where there is a digital element

  • competent in identifying and carrying out the actions required by those circumstances

  • able to ensure they are compliant in their actions.

The Digital Intelligence and Investigation project will deliver learning and knowledge resources that will ensure that all new and serving officers acquire the digital skills they need to undertake investigations effectively.  

Published 01/01/2020
Authoring body: College of Policing (CoP)
Guidance
Resource
Mobilisation APP

With the Police responding to critical and complex incidents, sometimes these incidents may require resources that go beyond the capacity and capability of the Police force. Some of these incidents may require the need of other partner agencies, other specialist skillsets and equipment and thus would need to be effectively managed and coordinated. Mobilisation is the process which supports mutual aid, at the local, regional or national level.

The National Police Coordination Centre (NPoCC) is responsible for the mobilisation of police assets, including general policing, operations and crime business areas. A lead force will be responsible for resourcing nationally-led crime enquiries. NPoCC should be the initial point of contact for any mobilisation requirements as it can provide advice and national coordination.

It is important to note that this a challenging area of work, particularly when the length of the investigation is unknown and mobilising crime assets is a new and emerging business field (mutual aid) for the Police service.

Published 01/01/2014
Authoring body: College of Policing (CoP)
Guidance
Resource
ISS4PS Annexes Volume 2

This document was retired in July 2021

The Information Systems Strategy for the Police Service (ISS4PS) is an overarching strategy for Information and Communications Technology (ICT) and Information Systems (IS) for the Police service across the whole of England and Wales. Volume 2 Annexes helps to define and establish a list of standards and should be used a requirements for new developments within the Police Service.

Annex contains guidelines and actions points for: 

1. Establishing ISS4PS standards information base (SIB) 

2. Actions and guidance for IT Directors

3. ISS4PS compliance to the architectural principles 

4. Guidelines for National Programmes focusing on 3 critical ISS4PS policies (Establishing Foundations, Delivering Joined-up Services and Delivering National Initiatives) 

5. Criteria's for corporate and national solutions developed or procured by the Police Force 

6. Summary of Principles and actions defined in 'Implementing ISS4PS Volume 2'  

Published 01/01/2005
Authoring body: Association of Chief Police officers (ACPO)
Principles
Resource
ISO/IEC 27003:2017 Information Technology — Security techniques — Information Security Management Systems — Guidance

ISO (the International Organisation for Standardisation) and IEC (the International Electrotechnical Commission) form the specialised system for worldwide standardisation. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organisation to deal with particular fields of technical activity. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1.

This document was created to provide guidance on the requirements for an information security management system (ISMS) and provides recommendations, possibilities and permissions.

The following areas are very important for ISMS:

  • understanding the organisation’s needs and the necessity for establishing information security policy and information security objectives;

  • assessing the organisation's risks related to information security;

  • monitoring and reviewing the performance and effectiveness of the ISMS

  • practising continual improvement

The ISMS also has key components such as policies, defined responsibilities, documentation and management processes pertaining to policy establishment, planning, implementation, operation, performance assessment, management review and improvement.

Published 01/01/2017
Authoring body: International Organisation for Standardisation (ISO)
Standards
Resource
ISO 90011:2018 Guidelines for Auditing Management Systems

This document informs the creation of auditing systems.

With many organisations now wanting to combine a number of management systems into one, there has been awareness to also combine auditing capabilities into one for these management systems. As a result the international standard BS EN ISO: 19011:2011 has created this standard to provide organisations the knowledge for auditing modern management systems, the principles and guidance to ensuring they deliver a high standard of auditing capabilities and that organisations do not fail which could have damaging effects such as losing out on contracts, certifications, and operational efficiency.

Organisations can save vast amount of time, money and resources, by applying a single approach to multiple management systems by streamlining their auditing processes and removing duplication of effort.

This document shed insights into planning, decision-making and evaluating audits.

The standard includes (but not limited to:

  • Scope

  • Principles of Auditing

  • Managing an audit programme

  • Establishing the Audit programme

  • Implementing the audit programme

  • Monitoring an audit programme

  • Reviewing and improving the audit programme

  • Conducting audit activities

  • Preparing audit report

  • Conducting audit evaluation

  • And much more

Fee applies of £254.00 (members price: £127.00) for accessing the standard.

Published 01/01/2018
Authoring body: British Standards Institution (BSI)
Standards
Resource
ISO/IEC 27003:2017 Preview

ISO (the International Organisation for Standardisation) and IEC (the International Electrotechnical Commission) form the specialised system for worldwide standardisation. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organisation to deal with particular fields of technical activity. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1.

This document provides guidance on the requirements for an information security management system (ISMS) as specified in ISO/IEC 27001 and provides recommendations (‘should’), possibilities (‘can’) and permissions (‘may’) in relation to them. It is not the intention of this document to provide general guidance on all aspects of information security.

Clauses 4 to 10 of this document mirror the structure of ISO/IEC 27001:2013.

This document does not add any new requirements for an ISMS and its related terms and definitions. Organisations should refer to ISO/IEC 27001 and ISO/IEC 27000 for requirements and definitions. Organisations implementing an ISMS are under no obligation to observe the guidance in this document.

An ISMS emphasises the importance of the following phases:

  • understanding the organisation’s needs and the necessity for establishing information security policy and information security objectives;

  • assessing the organisation's risks related to information security;

  • implementing and operating information security processes, controls and other measures to treat risks;

  • monitoring and reviewing the performance and effectiveness of the ISMS; and

  • practising continual improvement.

Published 01/01/2017
Authoring body: International Organisation for Standardisation (ISO)
Standards
Resource
Encoding Characters

 UTF-8, an encoding form for Unicode character sets, for government digital services and technology encodes all Unicode characters without changing the ASCII code.

Unicode is based on the American Standard Code for Information Interchange (ASCII) character set.

UTF-8 is an international standard used by, data scientists, data analysts and developers. It allows you to read, write, store and exchange text that remains stable over time and across different systems. It also have accurately translated languages moving between systems and prevent accidental or unanticipated corruption of text as it transfers between systems.

This makes UTF-8 flexible for a wide range of uses.

The government chooses standards using the open standards approval process and the Open Standards Board has final approval. Read more about the approval process for cross-platform character encoding. 

Published 01/01/2020
Authoring body: Government Digital Service (GDS)
Policy
Resource
All vehicles (VEH01)

All vehicles (VEH01) is a dataset of all licensed and registered vehicles in Great Britain and the UK, produced by Department for Transport.

It contains licensed vehicles, registered vehicles for the first time, vehicles by numbers of keepers, Statutory Off Road Notification (SORN) and the Ultra-low emissions vehicles (ULEVs).

For more information please contact Vehicles statistics

Emailvehicles.stats@dft.gov.uk

Public enquiries: 020 7944 3077

Published 01/01/2020
Authoring body: Department for Transport (DfT)
Reference Data / Templates
Resource
ISO/IEC 27032:2012 Information Technology — Security Techniques — Guidelines for Cybersecurity

ISO (the International Organisation for Standardisation) and IEC (the International Electrotechnical Commission) form the specialised system for worldwide standardisation. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organisation to deal with particular fields of technical activity. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1.

The Cyberspace is a complex environment resulting from the interaction of people, software and services on the Internet, supported by worldwide distributed physical information and communications technology (ICT) devices and connected networks. However there are numerous security gaps not covered by current information security, Internet security, network security and ICT security. The aim of this international standard is to address Cyberspace security issues and bridge the gap between different security domains in the cyberspace.

International Standard provides technical guidance for addressing common cybersecurity risks such as social engineering, hacking, spyware and proliferation of malicious software.

It also provides guidelines for addressing risk such as preparing for attacks, detecting and monitoring attacks and responding to attacks.

The International Standard also provides a framework for information sharing, coordination, and incident handling.

Published 01/01/2012
Authoring body: International Organisation for Standardisation (ISO)
Standards
Resource
Domain-based Message Authentication, Reporting & Conformance (DMARC)

The Domain-based Message Authentication, Reporting and Conformance (DMARC) is an email standard that used in email transactional activity. It helps validates a senders identity using Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM). The receiving email service uses SPF and DKIM to confirm the sender’s identity. If the receiving email service confirms the sender’s identity it will forward the email to the receiver’s inbox. If the receiving email service cannot confirm the sender’s identity it will mark the email as spam. 

Using DMARC has its benefits such as helps to protect the users, employees from cybercrime, reduce customer support costs relating to email fraud and improve trust in the emails organisation sends and receives.

Published 01/01/2016
Authoring body: Government Digital Service (GDS)
Standards
Resource
Using Open Document Formats (ODF) in your organisation

Open Document Formats (ODF) 1.2 standard was selected by the Open Standards Board for use across the UK government. ODF works on most operating systems (including desktops, laptops, mobiles and tablets). This is because it is an open standards that allows suppliers to create interoperable office productivity solutions, can lower IT costs as ODF is low cost or free to use, allows government staff to share and edit documents, allows stricter security checks therefore helping it to prevent common cyber-attack scenarios, can add digital signatures to a document. 

ODF standard works with several software tools as Mac, Windows, Linux, and Android operating systems as well as many others. User needs are very important when selecting an ODF complaint solution, therefore the research and analysis is critical.

The standard also includes the following information:

  • Buying ODF compliant solutions

  • Migrating to ODF compliant solutions

  • Securing ODF compliant solutions

  • Integrating ODF compliant solutions

  • Setting up ODF complaint solutions

Published 01/01/2018
Authoring body: Government Digital Services (GDS)
Guidance
Resource
Cybersecurity Framework NIST (Version 1.1)

National Institute of Standards and Technology (NIST), covers a wide range of topics including Bioscience, Chemistry, Advanced Communications, Cybersecurity, Energy, Materials, Nanotechnology, Neutron research, Physics, Health, Infrastructure, Public Safety, Standards, Transportation and many more.

NIST also cover a wide range of publications, laboratories and programs, Research projects, Services and Resources Software, Data, Computer Security Resource Center, and News and Events.

Under Cybersecurity, there is a framework developed to help organisations to better understand and improve their management of cybersecurity risk.

The Cybersecurity framework consists of standards, guidance, and best practices.

It stages of the framework:

  1. Identify

  2. Protect

  3. Detect

  4. Respond

  5. Recover

The cyber security framework help organisations prioritise, become flexible and cost-effective in promoting and dealing with protection and resilience of critical infrastructure and other parts critical to the national security and economy.

For further information and/or questions about the Cybersecurity Framework please contact:  cyberframework@nist.gov

Published 01/01/2018
Authoring body: National Institute of Standards & Technology (NIST)
Guidance
Resource
Technology Code of Practice

The Technology Code of Practice is a set of criteria to help government design, build and buy technology. Technology Code of Practice should be used for all technology projects and programmes and should be aligned to the mandatory code and as much as possible align the organisation’s technology and business strategies to the Technology Code of Practice.

Following the Technology Code of Practice will help introduce or update technology so that it:

  • meets user needs, based on research with your users

  • is easier to share across government

  • is easy to maintain

  • scales for future use

  • is less dependent on single third-party suppliers

  • provides better value for money

  • makes use of open standards

Organisations must consider all points of the Technology Code of Practice as part of the Cabinet Office spend control process as it’s used as a cross-government agreed standard in the spend controls process. Where legacy technology limits your ability to adhere to the standard, you must explain this to the GDS Standards Assurance team.

 

 

Published 01/01/2019
Authoring body: Government Digital Service (GDS)
Guidance
Resource
Defence Industry Security Notices

Industry Security Notices (ISNs)

 A Industry Security Notice (ISN) is an official document that tells people in industry about important instructions, guidance or other information relating to security.

Information from Ministry of Defence, that provides updates.

  • ‘ISN 2014/04 Farnborough International Air Show 2014: exhibition clearances’ has been removed

  • ‘ISN 2014/01: Government Security Classification Scheme’ updated April 2014

  • ‘ISN 2011/05 Defence & Security Equipment International (DSEi) 2011: exhibition clearances’ has been removed

  • ‘ISN 2011/02: incident report’ has been superseded by ‘2011/07: incident reporting’

  • ‘ISN 2011/03: Nato personnel security clearances’ has been superseded by ‘2014/03: Procedure for UK contractors to obtain Nato personnel security clearances’

Published 01/01/2021
Authoring body: Government Digital Services (GDS)
Guidance
Resource
Recruitment Guidance - Candidate Management

Ensuring that the right candidates are selected for policing roles is essential. Employing the right selection process is essential to make the most efficient use of money, time and resources and can have the following benefits:

  • Reduce the probability of selecting individuals who will not perform at their jobs effectively.

  • Better value at the national Assessment process

  • Minimises disproportionality in outcomes for underrepresented groups

  • Maximise candidates potential by supporting, them and ensuring a positive candidate experience.

It is known that not all forces handle their recruitment process in the same way in the early process and therefore causes discrepancies in the way people are recruited in the police force. A sifting solution is being undertaken that aims to help effectively mange candidates. Whilst this is still on-going, this document aims to help police forces consider some key principles for an effective end-to-end recruitment process.

Each area should be considered:

  • Recruitment strategy

  • Attraction campaign and positive action

  • Registration

  • Force selection

  • National Assessment Process

  • Post-assessment process activity

  • Appointment

Monitoring of each area and collaborating with other learning providers are critical to the improvement, maximisation and best practise of the selection process.

 

Published 01/01/2020
Authoring body: College of Policing
Guidance
Resource
Secure Sanitisation of Storage Media (Version 1.0)

Data sanitisation is a key aspect to any organisations dealing with data storage media and who want to ensure that unauthorised parties do not gain access to their data.

Data sanitisation has to do with the safe removal, treatments and disposal of sensitive information from storage media devices to guarantee that retrieval and reconstruction of data is not possible or may be very difficult to reproduce as some forms of sanitisation will allow you to re-use the media, while others are destructive in nature and render the media unusable.

There could be many reasons why an organisation may want to sanitise its data:

  • Re-use purposes – new user device allocation, re-purpose or resell device.

  • Repair purposes - return or repair faulty device

  • Disposal purposes – dispose of device

  • Destruction purposes – destroy information held on device or the device itself.

There are risks associated with improper sanitisation as key data may still remain on the device, such as:

  • Sensitive data may end up with the wrong people who can expose the sensitive data

  • Loss of control over information assets

  • Private or personal data could be leaked and used to commit fraud or identity theft.

  • Intellectual property could be used leading to reputational loss

Whilst this may not be entirely a sanitisation issue, it is part of it and one way to combat these risks is using encryption.

 

 

Published 13/02/2020
Authoring body: National Cyber Security Centre (NCSC)
Guidance