Last updated: 
4 months 2 weeks ago
Group Manager
New: Presentations from NHS-HE Forum on 11th June 2020; NHS-HE IG WG meeting 7th July 2020 NHS-Higher Education Connectivity Project: about NHS-HE Forum: about+archive, last meeting, next - November 2020 tba Scotland NHS-HE Forum:archive, next - currently on hold NHS & eduroam, List of hospitals providing eduroam Govroam  - roaming federation for the public services NHS-HE Information Governance Working Group - particularly for those involved in applying for health data for research, especially where this involves an NHS Digital Data Security and Protection Toolkit submission Please join this group and comment, also the parallel NHS-HE Forum JISCMAIL group for email updates.

Group administrators:

Oct 2012: NHS Scotland approach to Information Governance - Colin Howarth

24 October 2013 at 3:16pm

Colin is the lead for the Information Governance for connecting to N3 in Scotland. He notes that the rules are essentially the same in Scotland as in England but they use a Manual of Information Security/NHS Scotland Information Security Policy with direct review rather than the policies covered by the online Information Statement of Compliance including the Information Governance Toolkit process as in England.

Colin stressed that a risk management approach is essential and is the basis of ISO27001, very much the basis of the policy. There is a body of knowlege and good practice e.g. Her Majesty's Government Information Assurance Standards. It is recommended that a well made case for the connectivity should be the first step and if well made then takes you a long way. Further recommended:

–ISO27001 – for organisation/ISMS
–ISO27002 + ISO27005 – for solution
–Focus on solution/application level IA proposal