Information Security Assurance

13-316

Attainment: Level 3 (Previous 2)

The objective here is to account for information assets containing patient/service user information to ensure that in the event of damage, destruction or loss, there is awareness of what information is affected and, in the case of loss, whether the information held on the asset is protected from unauthorised access.

Level 1.

Responsibility has been assigned to a staff member for compiling information about the organisation's assets and for maintaining the asset register.

a.

Responsibility has been assigned for compiling and maintaining an information asset register.

Assign responsibility

Level 2.

A list of information assets has been compiled in a register which includes the location and 'owner' for each asset.

a.

All information assets (including online / internet facing systems) have been documented in a register that includes relevant details about each asset (i.e. the location of each asset, what type of information, who uses it etc).

Information Asset Register

Level 3.

a.

The asset register is maintained, updated and regularly reviewed, e.g. to ensure that each asset is still required and is still in use or to add new assets to the register.

Latest Information Governance Review meeting

b. (Not relevant for OHC)