IRRV Alert - week ending 13th May 2022

Information Letters

News

Consultations

DWP procurement: security policies and standards (9 May 2022)

Guidance

DWP procurement: security policies and standards

These apply to DWP suppliers and contractors where explicitly stated in the security schedule of the contract.

From:
Department for Work and Pensions
Published
9 April 2018
Last updated
9 May 2022 — See all updates
Get emails about this page

Documents

Acceptable Use policy

PDF, 220 KB, 9 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Information Management policy

https://www.gov.uk/government/publications/dwp-information-management-policies/dwp-information-management-policy

Information Security policy

PDF, 236 KB, 8 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Personnel Security policy

PDF, 171 KB, 5 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Physical Security policy

PDF, 227 KB, 4 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Cryptographic Key Management policy

PDF, 542 KB, 5 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Email policy

PDF, 147 KB, 5 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Forensic Readiness policy

PDF, 422 KB, 4 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Microsoft Teams Recording and Transcription Policy

PDF, 396 KB, 3 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Privileged Users Security policy

PDF, 472 KB, 3 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Remote Working Security policy

PDF, 423 KB, 3 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security Classification policy

PDF, 406 KB, 3 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

SMS Text policy

PDF, 402 KB, 3 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Social Media policy

PDF, 401 KB, 4 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Technical Vulnerability Management policy

PDF, 405 KB, 5 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

User Access Control policy

PDF, 403 KB, 4 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Placeholder: Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers

PDF, 57.4 KB, 1 page

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard: Physical and Electronic Security (part 1)

PDF, 839 KB, 24 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-001 (part 1): Access and Authentication Controls

PDF, 627 KB, 15 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-001 (part 2): Privileged User Access Controls

PDF, 589 KB, 10 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-002: Public Key Infrastructure & Key Management

PDF, 623 KB, 9 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-003: Software Development

PDF, 1.48 MB, 21 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-005: Database Management System

PDF, 634 KB, 11 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-006: Security Boundaries

PDF, 650 KB, 10 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-007: Use of Cryptography

PDF, 857 KB, 12 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-008: Server Operating System

PDF, 605 KB, 11 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-009: Hypervisor

PDF, 548 KB, 9 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-010: Desktop Operating System

PDF, 609 KB, 11 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-011: Containerisation

PDF, 520 KB, 9 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-012: Protective Monitoring Standard

PDF, 567 KB, 10 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-013: Firewall Security

PDF, 788 KB, 15 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-014: Security Incident Management

PDF, 629 KB, 10 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Form: Security incident response team referral (for Security standard SS-014: Security Incident Management)

ODT, 73.2 KB

This file is in an OpenDocument format

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-015: Malware Protection

PDF, 682 KB, 15 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-016: Remote Access

PDF, 625 KB, 7 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-017: Mobile Device

PDF, 639 KB, 8 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-018: Network Security Design

PDF, 1.44 MB, 28 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-019: Wireless Network

PDF, 677 KB, 12 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-022: Voice & Video Communications

PDF, 630 KB, 13 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-023: Cloud Computing

PDF, 1.59 MB, 28 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-025: Virtualisation

PDF, 559 KB, 9 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-027: Application Security Testing

PDF, 793 KB, 15 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-028: Microservices Architecture

PDF, 512 KB, 10 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security standard SS-029: Securely Serving Web Content

PDF, 765 KB, 13 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security Standard SS-030: Oracle Database Security

PDF, 1.61 MB, 26 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security Standard SS-031: Domain Management

PDF, 314 KB, 9 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Security Standard SS-033: Security Patching

PDF, 639 KB, 11 pages

This file may not be suitable for users of assistive technology.

Request an accessible format.

Details

The Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers is under review. You should refer to Good Practice Guides 45 and 44 instead.

Note, the Department for Work and Pensions (DWP) is unable to reply to general enquiries or questions about these security standards and policies.

These security standards and policies apply to DWP suppliers and contractors only. They do not apply to other government departments, their agencies or arm’s length bodies.

They have been published to help inform DWP Invitations to Tender and other contracting processes.

DWP may choose in an Invitation to Tender or the bid process to reference the standards and policies published here. Questions about a specific standard or policy should be sent to the DWP team managing responses to bids. This team is the only DWP authorised responder on any question about a bid and a standard or policy.

A new or changed policy or standard does not mean a new requirement for any existing contract. DWP will notify contract holders or partners of any changes to a contract.

Suppliers and contractors should contact their DWP contract managers with any questions about:

  • varying contracts
  • changing the agreed delivery of contracted services
  • the applicability of a standard or policy for their contracts

Published 9 April 2018
Last updated 9 May 2022 


IRRV Software

Copyright © 2025 · All Rights Reserved · Institute of Revenues Rating and Valuation
Warning: Undefined array key "User_id" in /home/irrvnet/public_html/forumalert/inc_footer.php on line 4