§ Mr. CohenTo ask the Secretary of State for Employment whether he has incorporated the code of practice for information security management, published by the British Standards Institution, into relevant contracts with information technology suppliers.
§ Miss WiddecombeThe security requirements for information technology—IT—systems and services used by central Government Departments are stated in Her Majesty's Government IT security policy document. This document is supported by use of the Central Communications Telecommunications Agency risk analysis and management method—CRAMM—and the baseline security for IT systems—BSITS—risk analysis methods, by the Communications Electronic Security Group—CESG—memorandum No. 10 where appropriate, and by supporting advice and guidance published by the HMG IT security authorities.
These are reviewed regularly to ensure best practice, have been developed specifically for use within government and have been in operation for some time.
The code of practice for information security management was developed by, and established for use by, commercial organisations and does not specifically address the requirements for the protection of official information.
§ Mr. CohenTo ask the Secretary of State for Employment if he will make a statement about the operation of his Department's sensitive documents unit; how many staff are employed in its operation; and approximately how many documents per annum come within its purview.
§ Miss WiddecombeWe do not have a sensitive file unit.