IRRV Alert - week ending 28th February 2020

News

Circulars

Consultations

Reports

DWP procurement: security policies and standards (24 February 2020)

 

 

 

 

 

Guidance

DWP procurement: security policies and standards

These apply to DWP suppliers and contractors where explicitly stated in the security schedule of the contract.

Published 9 April 2018
Last updated 24 February 2020 — see all updates

From:

Department for Work and Pensions

Documents

Policy: Acceptable Use

PDF, 449KB, 6 pages

Policy: Information Management

https://www.gov.uk/government/publications/dwp-information-management-policies/dwp-information-management-policy

Policy: Information Security

PDF, 398KB, 8 pages

Policy: Physical Security

PDF, 393KB, 3 pages

Placeholder: Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers

PDF, 57.4KB, 1 page

This file may not be suitable for users of assistive technology. Request an accessible format.

Security standard SS-001 (part 1): Access and Authentication Controls

PDF, 917KB, 24 pages

Security standard SS-001 (part 2): Privileged User Access Controls

PDF, 595KB, 14 pages

This file may not be suitable for users of assistive technology. Request an accessible format.

Security standard SS-002: Public Key Infrastructure & Key Management

PDF, 781KB, 9 pages

Security standard SS-003: Software Development

PDF, 1.16MB, 21 pages

Security standard SS-005: Database Management System

PDF, 654KB, 11 pages

Security standard SS-006: Security Boundaries

PDF, 951KB, 15 pages

Security standard SS-007: Use of Cryptography

PDF, 846KB, 16 pages

Security standard SS-008: Server Operating System

PDF, 853KB, 15 pages

Security standard SS-009: Hypervisor

PDF, 561KB, 9 pages

Security standard SS-010: Desktop Operating System

PDF, 554KB, 11 pages

Security standard SS-011: Containerisation

PDF, 641KB, 11 pages

Security standard SS-012: Protective Monitoring Standard

PDF, 638KB, 10 pages

This file may not be suitable for users of assistive technology. Request an accessible format.

Security standard SS-013: Firewall Security

PDF, 705KB, 20 pages

Security standard SS-014: Security Incident Management

PDF, 275KB, 14 pages

Security standard SS-015: Malware Protection

PDF, 441KB, 16 pages

Security standard SS-016: Remote Access

PDF, 257KB, 7 pages

Security standard SS-017: Mobile Device

PDF, 229KB, 8 pages

Security standard SS-018: Network Security Design

PDF, 816KB, 35 pages

Security standard SS-019: Wireless Network

PDF, 509KB, 17 pages

Security standard SS-022: Voice & Video Communications

PDF, 431KB, 18 pages

Security standard SS-023: Cloud Computing

PDF, 913KB, 35 pages

Security standard SS-025: Virtualisation

PDF, 355KB, 12 pages

Security standard SS-028: Microservices Architecture

PDF, 343KB, 14 pages

Security standard SS-029: Securely Serving Web Content

PDF, 403KB, 14 pages

This file may not be suitable for users of assistive technology. Request an accessible format.

Security Standard SS-030: Oracle Database Security

PDF, 673KB, 24 pages

This file may not be suitable for users of assistive technology. Request an accessible format.

Security Standard SS-031: Domain Management

PDF, 276KB, 8 pages

This file may not be suitable for users of assistive technology. Request an accessible format.

Security Standard SS-033: Security Patching

PDF, 830KB, 9 pages

This file may not be suitable for users of assistive technology. Request an accessible format.

Details

The Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers is under review. You should refer to Good Practice Guides 45 and 44 instead. https://www.gov.uk/government/collections/identity-proofing-and-authentication#how-to-prove-identities

Please note, the Department for Work and Pensions (DWP) is unable to reply to general enquiries or questions about these security standards and policies.

These security standards and policies apply to DWP suppliers and contractors only. They do not apply to other government departments, their agencies or arm’s length bodies.

They have been published to help inform DWP Invitations to Tender and other contracting processes.

DWP may choose in an Invitation to Tender or the bid process to reference the standards and policies published here. Questions about a specific standard or policy should be sent to the DWP team managing responses to bids. This team is the only DWP authorised responder on any question about a bid and a standard or policy.

A new or changed policy or standard does not mean a new requirement for any existing contract. DWP will notify contract holders or partners of any changes to a contract.

Suppliers and contractors should contact their DWP contract managers with any questions about:

  • varying contracts
  • changing the agreed delivery of contracted services
  • the applicability of a standard or policy for their contracts

Published 9 April 2018
Last updated 24 February 2020 + show all updates

 


IRRV Software

Copyright © 2025 · All Rights Reserved · Institute of Revenues Rating and Valuation
Warning: Undefined array key "User_id" in /home/irrvnet/public_html/forumalert/inc_footer.php on line 4