NHS Data Security And Protection Toolkit: How To Achieve “Standards Met”

The NHS Data Security and Protection Toolkit (DSPT) is not simply a compliance exercise. For organisations working with NHS systems, services, or patient information, it shows that the right data security arrangements are in place and maintained.

The NHS Data Security and Protection Toolkit is an online assessment that measures how well an organisation meets the National Data Guardian’s data security standards. Depending on the organisation, this can involve self-assessment, evidence submission and independent assessment.

In this blog, we’ll look at the 10 data security standards, how DSPT categories and assertions work, what evidence you may need, how independent audits fit into the process, and the common issues that can make an assessment harder than expected. We’ll also cover how to prepare for submission and what organisations can do when security weaknesses are found.

What Is the NHS Data Security and Protection Toolkit?

The NHS Data Security and Protection Toolkit (DSPT) is an online assessment used by organisations that access NHS patient data and systems to show that they are managing data security and handling personal information appropriately. NHS England provides it, and it operates within Department of Health and Social Care (DHSC) policy, involving several national bodies in its operation.

The developers built the framework around the National Data Guardian’s 10 data security standards, covering areas such as staff responsibilities, access management, incident response, continuity planning, IT protection and supplier management. For organisations covered by the CAF-aligned DSPT, the toolkit uses the National Cyber Security Centre’s Cyber Assessment Framework (CAF) as the basis for cyber security assurance and maps CAF objectives to the relevant DSPT requirements.

The current framework also includes Objective E, which focuses on using and sharing information appropriately as part of the health and care CAF approach. This is especially relevant in healthcare, where organisations need to protect confidential patient information while ensuring they can use and share it lawfully for patient care and other permitted purposes.

Source: https://qualysec.com/nhs-da ...
返回 下一个