Information Security Assurance

13-314

Attainment: Level 3 (Previous 1)

Level 1.

a.

There are documented procedures for mobile working or teleworking that provide guidelines for staff on expected behaviours.

Remote working procedures

b.

There is a documented policy for approvals and authorisation for mobile working and teleworking arrangements.

Policy for approving remote working

c.

The documented approvals policy and procedures have been agreed by an appropriate senior manager or group.

Approval of remote working procedures

Level 2.

a.

All mobile or teleworkers are appropriately approved and authorised, and records are maintained of all authorisations

Remote working procedures

b.

Mobile or teleworkers are provided with procedures / guidelines.

Training records

c.

Robust remote access solutions have been provided

OHC does not provide remote access solutions to any services containing patient data, only services on the public internet.

Level 3.

a.

Providing staff with guidelines, procedures and briefings does not provide sufficient assurance that they have been understood and are being followed, therefore compliance spot checks and routine monitoring are conducted.

Latest Information Governance Review meeting

b.

Documented reviews are carried out to obtain assurance that the mobile and/or teleworking arrangements are only available to authorised users, all mobile devices and removable media are accounted for; secure remote access is in place and that sensitive or confidential information (including service user information) is encrypted, securely transported or stored in secure locations.

Latest Information Governance Review meeting

c. (Not relevant for OHC)