FOI release

Annual compliance for ITHC, PCI DSS and general data security

Case reference FOI2024/01249

Received 22 July 2024

Published 12 August 2024

Request

I am requesting the following information:

 

1.1)        When did you conduct your last IT Health Check?

1.2)        When is your next IT Health Check due?

 

1.3)        Do you conduct other cybersecurity penetration testing?

1.4)        Are you in a contract for your IT Health Check / other testing? If so, when will this be up for renewal?

 

1.5) Who is the contact person at the Council for the annual IT Health Check?

2.1) When is the next date to renew compliance validation for PCI DSS?

2.2) Will the Council be requiring consultancy to ensure they adhere to the new PCI DSS 4.0?

2.3) Who is the contact person at the Council looking after PCI DSS compliance?

3.1) Do the Council adhere to other data security standards, such as Cyber Essentials Basic, Cyber Essentials Plus, ISO27001?

 

 

3.2) If no, do the Council plan on achieving any of these accreditations?

 

4.1) Does the Council currently utilise an in-house or outsourced Security Operations Centre for solutions such as EDR, MDR, or XDR?

 

4.2) Do the Council have Windows Defender for EDR. If so, is this managed in-house or externally?

5) What are the contact details for the Data Protection Officer?

Response

I am requesting the following information:

 

1.1)        When did you conduct your last IT Health Check?

 

          A: 20th June 2024 - 10th July 2024

 

1.2)        When is your next IT Health Check due?

 

   A: June 2025 - July 2025

 

 

1.3)        Do you conduct other cybersecurity penetration testing?

 

 

          A: Website Penetration Tests

 

 

1.4)        Are you in a contract for your IT Health Check / other testing? If so, when will this be up for renewal?

 

 

          A: Not in contract

 

 

1.5) Who is the contact person at the Council for the annual IT Health Check?

 

 

          A: Hoople’s Information Security Officer

 

 

2.1) When is the next date to renew compliance validation for PCI DSS?

 

          A: Completion of the SAQ P2PE currently under review

 

 

2.2) Will the Council be requiring consultancy to ensure they adhere to the new PCI DSS 4.0?

 

 

          A: No

 

 

2.3) Who is the contact person at the Council looking after PCI DSS compliance?

 

          A: The Information Security Officer at Hoople Ltd

 

 

3.1) Do the Council adhere to other data security standards, such as Cyber Essentials Basic, Cyber Essentials Plus, ISO27001?

 

 

A: ISO27001: The scope describes which Hoople business areas are examined for managing information security to the ISO 27001:2013 standard for certification purposes. This provides consumers of these certified services with a level of quality assurance. Subscribers to these certified services can state that these aspects of their business, are managed to the requirements of the standard; however, they cannot claim to be ISO27001 certified as this would require the examination of information security practices from their perspective.

 

PSN: Compliance is another way to report Herefordshire Council’s security arrangements. It demonstrates that Herefordshire Council’s security arrangements, policies, and controls are sufficiently rigorous to allow interaction with the Public Sector Network and those connected to it.

 

DSPT: The Data Security and Protection Toolkit (DSPT) helps adult social care providers in England check and improve how they keep people’s information safe.

 

UK GDPR: Herefordshire Council’s data protection compliance falls within the scope of the General Data Protection Regulation (GDPR) and meets the requirements for properly handling personal data as defined in the law.

 

Data Protection Act 2018: The Data Protection Act 2018 is the UK’s implementation of the General Data Protection Regulation (GDPR). Everyone responsible for using personal data must follow strict rules called ‘data protection principles’. They must ensure the information, is used fairly, lawfully, and transparently.

 

 

3.2) If no, do the Council plan on achieving any of these accreditations?

 

 

          A: N/A

 

 

4.1) Does the Council currently utilise an in-house or outsourced Security Operations Centre for solutions such as EDR, MDR, or XDR?

 

 

A: We consider that disclosing information relating to network security would be likely to prejudice the prevention or detection of crime and will not be released.  This information is exempt from disclosure under section 31 of the Freedom of Information Act 2000. Section 31(1)(a), therefore no network security arrangement will be released other than confirmation that Herefordshire Council do not have an in-house or outsourced Security Operations Centre.

 

4.2) Do the Council have Windows Defender for EDR. If so, is this managed in-house or externally?

 

 

          A: We consider that disclosing information relating to network security would be likely to prejudice the prevention or detection of crime and will not be released.  This information is exempt from disclosure under section 31 of the Freedom of Information Act 2000. Section 31(1)(a)

 

 

 

5) What are the contact details for the Data Protection Officer?

 

 

          A: Samantha Smith, email: informationgovernance@herefordshire.gov.uk

 

 

If you are a company intending to use the names and contact details of council officers provided in this response for direct marketing, you must be registered with the Information Commissioner to process personal data for this purpose. You must also check that the individual (whom you wish to contact for direct marketing purposes) is not registered with one of the preference services to prevent direct marketing. If they are you must adhere to this preference. You must also ensure you comply with the Privacy Electronic Communications Regulations (PECR). For more information see www.ico.org.uk

 

For the avoidance of doubt, the provision of individual names and contact details under the Freedom of Information Act 2000 does not give consent to receive direct marketing via any media and expressly does not constitute a 'soft opt-in' under PECR.

Documents

There are no documents for this release.

This is Herefordshire Council's response to a freedom of information (FOI) or environmental information regulations (EIR) request.

You can browse our other responses or make a new FOI request.