introduction to information governance (ig) & the ig toolkit · the information governance...

51
Introduction to Information Governance (IG) & the IG Toolkit IG Working Group

Upload: phungduong

Post on 08-Jul-2018

222 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Introduction to Information Governance (IG) & the IG Toolkit IG Working Group

Page 2: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

The same old song?

University of Leicester 2

Presenter
Presentation Notes
It is usual for any presentation regarding information governance or information security to include some scary headlines – demonstrating what can go wrong
Page 3: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

The same old song?

University of Leicester 3

Presenter
Presentation Notes
This was a very recent case of patient data being mistakenly released
Page 4: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

The same old song?

University of Leicester 4

Presenter
Presentation Notes
This reflects the risk of large Information Commissioner fines (up to £500,000)
Page 5: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

The same old song?

University of Leicester 5

Presenter
Presentation Notes
A tale of the loss of computer equipment
Page 6: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

The same old song?

University of Leicester 6

Presenter
Presentation Notes
Universities are not immune
Page 7: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Introduction to IG & IGT - Content

University of Leicester 7

Presenter
Presentation Notes
And more to frighten the public
Page 8: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Introduction to IG & IGT - Content

University of Leicester 8

Presenter
Presentation Notes
But one you may not have seen… as it is fictional.
Page 9: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Conclusion?

There is no glamour in good information governance … … but it means maintaining your reputation and keeping on doing your work.

University of Leicester 9

Presenter
Presentation Notes
A conclusion form this is that there is no glamour and no good headlines from looking after data well. On the very positive side however in avoiding the sort of events and issues described, you and the University can maintain its reputation and you can carry on doing your work.
Page 10: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Introduction to IG & IGT - Content

• What is Information Governance (IG)?

• When and why might IG be an issue for me?

• What we are doing

• What does this mean to me? – What can I do?

• Information Governance - Why?

• How the University can provide IG assurance

• The Information Governance Toolkit & the College

• How you use and provide evidence for the IG Toolkit?

• Responsibilities

University of Leicester 10

Presenter
Presentation Notes
I want to try to keep to this positive side of things and talk about some of the things we and you can do to keep doing things well.
Page 11: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

What is Information Governance?

University of Leicester 11

Presenter
Presentation Notes
Information Governance can be seen broadly to cover a range of issues – it isn’t therefore the concern of just a particular person or function.
Page 12: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

The Breadth of Information Governance

University of Leicester 12

• Information Governance Management (responsibility for IG, University policy, training, responsibilities)

• Confidentiality and Data Protection Assurance (link to Information Assurance Services, implementation of requirements, Information Security Policies)

• Information Security Assurance (Information Security Management, risk management, information asset inventory and ownership, policy, incident management, maintenance of confidentiality, integrity and availability of data, anonymisation and pseudonymisation, secure data processing/secure data processing environment)

• The process of generating IG Toolkit submissions which relies on, and in turn drives development in the areas above.

Page 13: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

What is Information Governance?

University of Leicester 13

Presenter
Presentation Notes
But put simply information governance can be described as being to do with the way organisations process or handle information.
Page 14: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

What is Information Governance?

University of Leicester 14

• Information Governance is the information aspect of Clinical Governance

• It concerns information security and confidentiality

• It is to do with the way organisations ‘process’ or handle information

• It covers personal information, i.e. that relating to patients/service users and employees, and corporate information, e.g. financial and accounting records

• It is relevant when dealing with use of health information (whether defined as, personal, sensitive, “person identifiable”, pseudonymised or anonymised)

Page 15: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

What is Information Governance?

University of Leicester 15

Presenter
Presentation Notes
So there is a logical link: Where an individual wishes to ensure that data are secure. This is examined for example through Research Sponsorship (and or funder proposal documents, IRAS forms, S251 forms, ONS forms, HSCIC Data Sharing Agreements… or whatever is relevant to you). That relies on IT Which reflects/complies with University Information Security Policies Which in turn comply with legislation and reflect standards such as ISO27001.
Page 16: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

When and why might IG be an issue for me?

University of Leicester 16

Presenter
Presentation Notes
In practice when might IG be an issue. There are many examples but one example here reflects situations which have occurred.
Page 17: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

When and why might IG be an issue for me?

University of Leicester 17

Dealing with IG involves:

• researchers facing challenges which relate to the data they are concerned with,

• what exists at the University to deal with this (people, advice, processes, IT), and

• the University providing an IG framework which needs to be applied in a practical context.

Page 18: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

When and why might IG be an issue for me?

University of Leicester 18

Page 19: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

When and why might IG be an issue for me?

University of Leicester 19

Presenter
Presentation Notes
Similarly we have been asked to assist in this sort of case.
Page 20: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

What we are doing

University of Leicester 20

• IG Working Group

• Contact point – [email protected]

• Co-ordination – Information Assurance

• Co-ordination – Research Governance

• IG Framework – Responsibility / IG Leads / SIRO

• IG Framework – Strategy / Policy

• IG Toolkit – College Registration/submission (annual)

• Training

Presenter
Presentation Notes
What we want to communicate is the range of things happening to support appropriate information governance
Page 21: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

What we are doing

University of Leicester 21

• Research proposals / data sharing requests

• NHS-HE IG Working Group – national involvement

• Influence on IT developments (VPN, R:, standards, ISO27001)

• HSCIC communication / Data Sharing Contracts

• Standard advice / support

• College meetings / discussions

• Website – Information Governance, RDM

Page 22: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

What does this mean to me? – What can I do?

University of Leicester 22

•Good things you are already doing •Much is in your control •Knowing what you need to be aware of •Avoiding common pitfalls

Presenter
Presentation Notes
So where does that leave me as an individual? What can I do? The first thing is to emphasise the positives …
Page 23: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Handling Risk

• Reduce • Transfer • Avoid • Accept

Presenter
Presentation Notes
In practice whether or not you are a risk management expert that is something you are used to doing. In handling risk we aim to reduce, transfer, avoid, or accept – the key being to recognise the risk in the first place.
Page 24: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Handling Risk

• Less Identifiable / only anonymised data (reduce/avoid risk)

• Reduce data transfers / secure method / encryption

• Encryption of data when working remote/mobile (reduce risk)

• Minimal staff access data (reduce risk)

• Use central data storage (transfer risk to ITS)

• Quantify, document and accept, but be aware of risk

Presenter
Presentation Notes
Among many examples...
Page 25: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Provide Assurance

• Quote policy

• Follow policy

• Raise awareness

• Do training

• Processes & procedures (SOPs)

• Existing Research Governance

• Documentation (“if it is not documented it hasn’t happened”)

• Audit/Monitoring

Presenter
Presentation Notes
In addition to handling risk you can provide assurance
Page 26: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Information Governance – Why?

University of Leicester 26

A more robust and comprehensive approach to the management of data: •active expectation of compliance with

applicable legislation • range of regulators • those providing data such as HSCIC • research funders

Presenter
Presentation Notes
In addition to handling risk you can provide assurance
Page 27: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Information Governance – Why?

University of Leicester 27

What is demanded:

• the ability to maintain confidentiality, integrity and availability of data, through people (with appropriate skills and training), processes and framework of responsibility, and technical means, alongside

• the means to actively evidence that this is a reality.

Page 28: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Information Governance – The means to address rules

University of Leicester 28

• The Data Protection Act 1998.

• The common law duty of confidentiality.

• The Confidentiality NHS Code of Practice.

• The NHS Care Record Guarantee for England.

• The Social Care Record Guarantee for England.

• The international information security standard: ISO/IEC 27002: 2013.

• The Information Security NHS Code of Practice.

• The Records Management NHS Code of Practice.

• The Freedom of Information Act 2000.

Presenter
Presentation Notes
Examples of the relevant legislation.
Page 29: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Information Governance – The means to assurance

University of Leicester 29

Good IG provides assurance - assurance to the public and organisations working with you, that information governance is taken seriously – there is good practice, appropriate processes, structures, systems, trained staff – and information is handled appropriately.

Presenter
Presentation Notes
So in the face of all that expectation we need to provide assurance.
Page 30: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

How the University can provide IG assurance

University of Leicester 30

• An IG Framework (defining responsibility etc.)

• Policies

• Processes e.g. Research Governance Sponsorship

• Services e.g. IT infrastructure

• Appropriately skilled staff who have undergone training

• Formal submission of evidence

Presenter
Presentation Notes
… and this is provided through …
Page 31: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

How the University can provide IG assurance

University of Leicester 31

• Research proposals and Data Management Plans (www.le.ac.uk/researchdata )

• ISO27001 certification - increasingly it is questioned whether there is University certification under the Information Security Management standard (there is no current University certification)

• Information Governance Toolkit (IGT) submission – particularly in the absence of ISO27001 certification it is important that the University can demonstrate IGT compliance.

Presenter
Presentation Notes
There are three particular areas worth noting here: In all disciplines the production of data management plans are expected and are supported here through the RDM website. The University is often asked if it is ISO27001 certified for Information Security Management. Currently it isn’t, which makes number 3. more important. Completion of the Information Governance Toolkit.
Page 32: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

What is the Information Governance Toolkit?

University of Leicester 32

• The Information Governance Toolkit (IGT) is a performance tool produced by the Department of Health (DoH) and the responsibility of the Health & Social Care Information Centre (HSCIC)

• It draws together the legal rules and central guidance set out and presents them in one place as a set of information governance requirements

• Types of organisations described are required to carry out self-assessments of their compliance against the IG requirements

• The Toolkit consists of a number of standards against which assurance of compliance needs to be given

Presenter
Presentation Notes
For those not familiar with it … The IGT was originally produced for NHS organisations so it hasn’t been overly-well known beyond the NHS.
Page 33: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Does the University have to do the IG Toolkit?

University of Leicester 33

Presenter
Presentation Notes
Since 2011 however the DoH and IOC have taken the stance that it is relevant.
Page 34: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Does the University have to do the IG Toolkit?

University of Leicester 34

• compulsory in Section 251 cases – use of identifiable patient information without patient consent

• other organisations that have access to NHS patients and/or to their information

• a collaborator demands it

• a data request results in it being required

Presenter
Presentation Notes
In reality many are still unfamiliar with IGT and the response from the HE sector has been variable. Where you may come across it …
Page 35: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

The College and the IG Toolkit

University of Leicester 35

• Some existing IGT work/submission

• IG Leads and Working Group

• Responsibility with College IT Advisory Committee

• 2014-15 first successful College-wide ‘umbrella’ IGT submission

• IG/IGT web presence - Approved IG Policy

• University Registrar as SIRO (Senior Information Risk Owner)

• Recommended Training

Presenter
Presentation Notes
So what is happening here?
Page 36: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

The College and the IG Toolkit

University of Leicester 36

IGT (2012-13) Hosted Secondary Use Teams/Project (HSUT/P)

For individuals, teams and their projects that process NHS patient information for the purposes of non-direct care e.g. clinical research activities and other related patient data analysis (public health planning). These individuals / teams are effectively discrete sub-units or divisions of their host organisation whose overall business interests may span a range of clinical and non-clinical activities e.g. universities, Public Health Teams hosted/employed by Local Authorities, commercial organisations. This requirement set enables such individuals / teams to assess the adequacy of IG processes around their projects.

Presenter
Presentation Notes
The “Hosted Secondary Use Team/Project” category is used by this and other universities.
Page 37: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

The College and the IG Toolkit

University of Leicester 37

Presenter
Presentation Notes
The approach being taken currently is to avoid over duplication and focus initially on providing the framework of assurance through a college-wide IGT submission. This (150 or so documents) is then available for any individual lower level submissions, alongside local context specific evidence.
Page 38: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

IGT Submissions – Sources of evidence

Presenter
Presentation Notes
A complete IGT submission therefore will consist of evidence from University, College and Department/Group levels.
Page 39: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

IGT Submissions – Sources of evidence

Presenter
Presentation Notes
What the IG Working Group has done is to provide existing and develop further University and College evidence – this is available for any Department/Group IGT submission.
Page 40: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

How do you provide evidence for the IGT?

• Talk to the IG Working Group

• Register for IGT

• Register under University of Leicester e.g. UoL-ResearchGroupX

• Evidence gathering through the year

• Evidence upload to IGT website

• Annual submission by 31 March

Page 41: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

How do you provide evidence for the IGT?

Presenter
Presentation Notes
The work is done through a website which currently looks like this, and which is open to the public to look at requirements and results of submissions (but not the detail of the submissions themselves).
Page 42: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

How do you provide evidence for the IGT?

• The toolkit consists of a number of standards.

• Each standard is associated with detail of the subject area and what requirements need to be evidenced to satisfy the standard.

• The organisation provides evidence against each of these standards.

• Responsibility for this is given to an organisation “Administrator”, and via “Ownership” of particular standards.

• Each standard - compliance level is ‘Not Applicable’, 0, 1, 2, or 3.

• The aim is to achieve an acceptable status of at least 2, and work to Level 3 for each.

Page 43: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

IGT Requirements (Hosted Secondary Use)

Page 44: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

How to make IGT easier • Liaise with the IG Working Group – their job is to achieve compliance

with you and to reduce duplication of effort: contact [email protected]

• Use College evidence – the College submission provides much of what any other IGT submission will need

• University IG web content - http://www2.le.ac.uk/colleges/medbiopsych/research/information-governance-igt

• University Research Governance web - http://www2.le.ac.uk/colleges/medbiopsych/research/researchgovernance

• University Research Data Management web – www.le.ac.uk/researchdata

Page 45: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Responsibilities

• General - all have responsibilities to comply with relevant legislation, notably the Data Protection Act, and the Caldicott Principles

• All team/project members – undergo recommended training

• All will contribute to evidence gathering: a) Contribute to documents b) Undertake training c) Review processes and practices d) Review technical systems e) Read and comply with advice/policy f) Demonstrate that you have read and are complying with advice/policy g) Undertake technical work to support agreed standards

Page 46: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

What does this mean to me? – What do I have to do?

Individual

• Understand polices and issues, aware of the requirements , compliance day to day, responsible for records or data, and what they do with information they use

• IG Training

IG Leads

• Authoring the IG Policy • Build Policy into standards & processes • Ongoing compliance, IG Toolkit submission, Improvement Plan

College IT Committee

• IG Policy and framework approval, ensure resources to support the policy • Ensure research meets legal responsibilities and adopts governance requirements • IGT submission review and approval

Institution

• Institutional Policy and responsibility • SIRO (Senior Information Risk Owner)

Page 47: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Responsibilities

Page 48: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

Responsibilities

Page 49: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

What is “Personal Data”?

University of Leicester 49

Personal data (according the Information Commissioner’s Office or ICO) means data which relate to a living individual who can be identified:

• from those data, or

• from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller,

and includes any expression of opinion about the individual and any indication of the intentions of the data controller or any other person in respect of the individual.

Page 50: Introduction to Information Governance (IG) & the IG Toolkit · The Information Governance Toolkit & the College ... information asset inventory and ownership, policy ... confidentiality,

What is “Sensitive Personal Data”?

University of Leicester 50

Sensitive personal data (according the ICO) means personal data consisting of information as to:

• the racial or ethnic origin of the data subject,

• their political opinions,

• their religious beliefs or other beliefs of a similar nature,

• whether they are a member of a trade union,

• their physical or mental health or condition,

• their sexual life,

• the commission or alleged commission by him of any offence, or

• any proceedings for any offence committed or alleged to have been committed by him.