HC Deb 07 December 1993 vol 234 c124W
Mr. Cohen

To ask the Secretary of State for the Environment whether he has incorporated the code of practice for information security management, published by the British Standards Institution, into relevant contracts with information technology suppliers.

Mr. Gummer

The security requirements for IT systems and services used by central Government Departments are stated in the Government IT security policy document. This documenht is supported by the use of the CCTA risk analysis and management method (CRAMM) and baseline security for IT systems (BSITS) risk analysis methods, and by supporting advice and guidance published by the Government IT security authorities. These have been developed specifically for use within government and are regularly reviewed to ensure best practice. The code of practice for information security management was developed by and established for use by commercial organisations and does not specifically address the requirements for the protection of official information.

Forward to