Information Security and Data Classification Policy 2024
This document is available to preview on this page. Public downloads are not enabled.
Document Details
Scroll through the document above to read all pages. Downloads are not enabled for public users.
The Information Security and Data Classification Policy 2024 defines the strict protocols required to safeguard the council’s digital assets and protect personal information handled during administrative operations.
This comprehensive policy categorizes all internal data into distinct sensitivity tiers, mandating specific encryption levels and access restrictions for each classification. It establishes clear rules regarding password complexity, multi-factor authentication requirements, and the secure handling of files within cloud storage environments.
The document explicitly prohibits the transfer of sensitive public records to unsecured personal devices or unauthorized external communication platforms. All staff members, elected councillors, and external contractors are legally required to complete an annual information governance training module to ensure ongoing compliance.
Adhering to this framework minimizes the risk of data breaches and reinforces the council’s alignment with data protection standards.The Information Security and Data Classification Policy 2024 defines the strict protocols required to safeguard the council’s digital assets and protect personal information handled during administrative operations.
This comprehensive policy categorizes all internal data into distinct sensitivity tiers, mandating specific encryption levels and access restrictions for each classification. It establishes clear rules regarding password complexity, multi-factor authentication requirements, and the secure handling of files within cloud storage environments.
The document explicitly prohibits the transfer of sensitive public records to unsecured personal devices or unauthorized external communication platforms. All staff members, elected councillors, and external contractors are legally required to complete an annual information governance training module to ensure ongoing compliance.
Adhering to this framework minimizes the risk of data breaches and reinforces the council’s alignment with data protection standards.