Skip to main content

Part of Objective A - Managing risk

Principle: A1 Governance

A1.a Board direction

“You have effective organisational information assurance management led at board level and articulated clearly in corresponding policies.”

Overview

To meet this contributing outcome, you need to assure that your board is appropriately sighted and involved in your organisation’s cyber security and information governance (IG) activities.

Board direction

Your board, or senior management, should take overall accountability for the data protection and security risks your organisation faces. They should provide direction on cyber security and IG, which is then disseminated through your organisation’s policies, projects and procedures.

In health and care, these board level activities are usually driven by the Senior Information Risk Owner (SIRO) (see A1.b Roles and responsibilities).

Linking governance and security to essential services 

The board should be able to discuss how IG and cyber security contribute to the delivery of essential functions, and understand the potential impact if important information or systems were compromised. They should also recognise IG and cyber security as important enablers for the resilience of those essential functions. To facilitate this, the board must receive briefings that clearly demonstrate how IG and cyber security activities facilitate the organisation’s delivery of services.  

Where seeking the board’s input on topics such as the legal or regulatory landscape, the organisation’s risk profile, or emerging threats, you should make it clear which essential functions are likely to be impacted without adequate mitigations in place. This may be all of them in certain scenarios.  

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • policies relating to the security and governance of information, systems and networks 
  • evidence of IG and security group findings and decisions being discussed at board level 
  • terms of reference and minutes from board meetings 
  • board level strategy and action plans relating to the security and governance of information, systems and networks 

This is not an exhaustive list. You can provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.

Interpreting indicators of good practice 

Indicator of good practice Term Interpretation

A#1

Your organisation’s approach and policy relating to the security and governance of information, systems and networks supporting the operation of your essential function(s) are owned and managed at board level. These are communicated, in a meaningful way, to risk management decision makers across the organisation.

'essential function(s)'

Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions.

For more information, see guidance on scoping essential functions.

A#2

Regular board discussions on the security and governance of information, systems and networks supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.

'regular' On a scheduled basis, with enough frequency to ensure there are no key strategic decisions made which the board does not have visibility of.

A#3

There are board level individuals who have overall accountability for the security and governance of information, systems and networks (these may be the same person), who drive regular discussion at board level.

'regular' On a scheduled basis, with enough frequency to ensure there are no key strategic decisions made which the board does not have visibility of.

A#5 

The board has the information and understanding needed in order to effectively discuss how the security, resilience and governance of information, systems and networks contribute to the delivery of essential function(s) and what the potential impact from compromise of the organisation’s information or systems would be. 

‘understanding needed […] to effectively discuss’  See Linking governance and security to essential services above.

A#6 

Information assurance is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions. 

‘recognised as an important enabler’  See Linking governance and security to essential services above. 

National services

The following national services may help you meet the requirements of A1.a.Board Direction

Additional guidance

For additional guidance, see:

National Cyber Security Centre CAF guidance A1 Governance
National Cyber Security Centre  Risk management Cyber security governance
ICO Leadership and oversight 


A1.b Roles and responsibilities

“Your organisation has established roles and responsibilities for the security and governance of information, systems and networks at all levels, with clear and well-understood channels for communicating and escalating risks.”

Overview

This contributing outcome relates to your organisation’s cyber security and information governance (IG) activities being directed, delivered and followed by a team of appropriately knowledgeable and capable staff.

Roles and responsibilities

How you structure your cyber security and IG teams and allocate responsibilities is a local decision. 

Roles and responsibilities should be well understood to ensure that cyber and IG activities are effectively delivered, and that any gaps in resources are promptly identified and addressed.

You can define roles and responsibilities in a range of ways, including but not limited to: 

  • documented ownership of actions
  • documented role descriptions
  • policies and processes
  • training 
  • contracts

NHS England has created cyber security job profiles and IG role profiles which help provide a practical reference point for defining local role responsibilities and evidencing that key duties are clearly assigned.

Key roles in health and care

The key cyber security and IG roles for health and care organisations are highlighted below, with brief explanations of their purpose, main responsibilities and how they support effective governance, risk management and assurance.  

Data Protection Officer (DPO)

The Data Protection Officer (DPO) is a legally required role under UK GDPR and the Data Protection Act 2018, providing independent data protection advice and reporting to the board or highest management level.

Their duties include:

  • providing independent expert advice on data protection matters
  • advising on compliance, including data protection obligations, Data Protection Impact Assessments (DPIAs) and internal data protection practices
  • monitoring compliance, including data protection policies, staff awareness, training and assignment of responsibilities.
  • supporting breach response, including advising on personal data breaches, reporting requirements and communications with the Information Commissioner’s Office (ICO) or affected individuals
  • acting as a contact point for individuals and the ICO

See ICO guidance on DPOs for more information. 

Senior Information Risk Owner (SIRO)

The Senior Information Risk Owner (SIRO) is a senior board level role responsible for championing data security and protection, owning information risk and ensuring risks are understood, managed and escalated appropriately.

Their duties include:

  • providing board level leadership on data security, protection and information risk
  • overseeing information risk management, including staying informed about key risks, taking ownership of risk assessment processes and ensuring risks are managed appropriately
  • owning and overseeing information risk policies, including ensuring they are developed, communicated and implemented consistently
  • managing major risks and incidents, including high severity cyber alerts, major incidents or breaches, and accepting appropriate residual risk
  • ensuring effective communication and implementation, so the organisation’s approach to information risk is understood by staff and supported with appropriate resources, commitment and execution

The SIRO should be an executive director or another senior member of the board, or equivalent senior management group. A Chief Information Officer (CIO) may take on the role if they sit on the board, although this is not considered best practice.

Temporary cover may be provided by another board member, but the role should not be held by the Caldicott Guardian, as the SIRO is part of the management hierarchy rather than an advisory role.

Caldicott Guardian

The Caldicott Guardian is a senior role responsible for ensuring confidential information about patients, service users and staff is used ethically, legally and appropriately, in line with the Caldicott Principles.

Their duties include:

  • advising on confidential information, particularly where disclosures involve legal or ethical uncertainty
  • promoting ethical and lawful use of information, ensuring the organisation meets high standards when handling confidential information
  • acting as an advocate for patients and service users, helping ensure confidentiality is protected and information is shared appropriately
  • supporting complaints and concerns, including involvement in patient or service user complaints about confidential information
  • reviewing and advising on IG documentation, including relevant data protection and confidentiality materials
  • contributing to audits and assurance, helping the organisation check whether confidential information is being handled appropriately
  • supporting breach investigations, particularly where confidential patient or service user information may have been affected
  • challenging and advising senior decision makers, using independent judgement to question, analyse and advise on complex confidentiality issues

The Caldicott Guardian should be a senior person with the authority, judgement and confidence to advise the organisation’s highest level decision makers. It is preferable, but not mandatory, for them to be an experienced health or social care practitioner. Smaller organisations may share a Caldicott Guardian function with another organisation where appropriate.

In some organisations, the same person may act as both Caldicott Guardian and DPO, provided they have the right knowledge and experience and any conflicts of interest are managed. However, it would not normally be appropriate for the same person to act as both SIRO and Caldicott Guardian, because the SIRO is a management decision making role and this may create a conflict of interest.

See guidance produced by the UK Caldicott Guardian Council and the National Data Guardian for more information.

IG lead

The IG lead is a senior management role responsible for coordinating and managing the organisation’s IG work programme, ensuring effective oversight of data protection, confidentiality, freedom of information and subject access responsibilities.

Their duties include:

  • coordinating the IG work programme, ensuring IG activities are planned, managed and delivered effectively
  • ensuring accountability and assurance, including effective management, compliance and assurance across an organisation’s information handling practices
  • securing senior support for IG, ensuring there is top-level awareness, appropriate resourcing and support for implementing improvements
  • supporting IG training, ensuring appropriate training is available to staff and completed where needed for their roles
  • monitoring information handling, ensuring activities comply with relevant law and guidance
  • providing a focal point for IG issues, including supporting discussion, resolution and escalation where appropriate
  • keeping up to date with IG and data security developments, ensuring the organisation’s approach remains current and effective

In larger organisations, the DPO and IG lead roles should usually be carried out by different people. Where the same person holds both roles, any potential conflict of interest between the operational responsibilities of the IG lead and the independent advisory duties of the DPO should be identified and managed.

Information security or cyber security lead

The information security or cyber security lead is responsible for advising on, implementing and assuring the organisation’s approach to information and cyber security. The role may be highly technical, focused on security controls, or broader, focused on security assurance.

Their duties include:

  • advising on and implementing security strategy, including the effectiveness of technical, organisational and procedural security controls
  • monitoring compliance with legislation and standards, which may include the Network and Information Systems Regulations, UK GDPR and the security requirements of the Data Protection Act 2018
  • responding to high severity alerts and advisories, including coordinating the organisation’s response where action is required
  • coordinating security incident response, ensuring security-related incidents are managed, escalated and addressed appropriately
  • co-operating with key external bodies, including NHS England, the ICO and the National Cyber Security Centre
  • championing good information security practice, promoting secure ways of working across the organisation
  • supporting information security training, ensuring mandatory and role-based training is available to staff and completed where needed

The role may be full time or combined with other roles, such as the IG lead or IT manager. Where responsibilities are shared, the organisation should ensure there is sufficient expertise, capacity and clarity of accountability to manage cyber security effectively.


Staff contracts

Your employment contracts for staff should contain data protection and security requirements.

The NHS terms and conditions of service handbook outlines the following under the ‘Governance, confidentiality, data protection’ section:

“35.46 All employees must comply with the General Data Protection Regulation (GDPR) as it applies in the UK, informed by the Data Protection Act 2018.

Policies should set out clear principles and processes. Specifically, home and/or agile/hybrid workers are under a duty to observe security and confidentiality practices in relation to equipment and data in line with GDPR, data protection legislation, and local policies and procedures. Employers need to ensure provisions are in place for the secure storage, use and disposal of confidential information from the home base.”

Your organisation may use wording reflecting this, or signpost to the NHS terms and conditions of service handbook, to ensure your contracts cover the appropriate bases.

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • documentation of key roles and responsibilities 
  • evidence of the review process for roles and responsibilities 
  • job descriptions 
  • procedures for reporting resourcing issues 
  • name of the individual with overall accountability  
  • staff contract sample 

This is not an exhaustive list. You can provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.

A practical example of a supporting statement for outcome A1.b Roles and responsibilities has been provided. The template is to be used as an example only. The information you provide in your supporting statement must be relevant to your organisation and you are encouraged to choose an approach that best suits you. 

Interpreting indicators of good practice

Indicator(s) of good practice Term Interpretation

A#1

Key roles and responsibilities for the security and governance of information, systems and networks supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.

'regularly'

On a scheduled basis, with enough frequency to ensure there are no critical gaps in cyber security or IG activities.

 

A#1

Key roles and responsibilities for the security and governance of information, systems and networks supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.

'essential function(s)'

Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions.

For more information, see guidance on scoping essential functions.

National services

The following national services may help you meet the requirements of A1.b Roles and responsibilities:

Additional guidance

For additional guidance, see:

National Cyber Security Centre CAF guidance | A1 Governance
National Cyber Security Centre | Risk management – Cyber security governance


A1.c Decision making

“You have senior level accountability for the security and governance of information, systems and networks, and delegate decision making authority appropriately and effectively. Risks to information, systems and networks related to the operation of your essential function(s) are considered in the context of other organisational risks.”

Overview

This contributing outcome relates to your organisational procedures for making decisions relating to cyber security and information governance (IG).

Decision making

Your procedures for risk decision making should ensure that:

  • appropriate staff members are involved
  • staff members operate under direction from senior management
  • risk decisions are reviewed in response to changing circumstances

The teams who are directly involved in conducting your cyber security and IG activities are best placed to determine what decisions should be taken in each individual case and escalating where appropriate. However, they should operate with an informed understanding of your board’s risk appetite.

Risk appetite

Your organisation should have a board approved risk appetite which:

  • determines acceptable and unacceptable risks
  • creates a risk culture and sets risk expectations to be shared across your organisation’s teams
  • allows staff members to make informed, timely and effective risk management decisions

Your organisation’s risk appetite should be continually assessed against current threats and refreshed at suitable intervals.

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • risk appetite statement 
  • responsibilities for decision making in different risk areas 
  • procedures for reporting key risk decisions to the board 
  • procedures for delegating risk decisions 
  • risk registers 
  • procedures for risk register review 
  • procedures for involving other departments in risk decisions 

This is not an exhaustive list. You can provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.

Interpreting indicators of good practice

Indicator of good practice Term Interpretation

A#2

Risk management decision makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.

'essential function(s)'

Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions.

For more information, see guidance on scoping essential functions.

A#4

Risk management decisions are regularly reviewed to ensure their continued relevance and validity.

'regularly'

On a scheduled basis, with enough frequency to ensure that the criteria upon which you have made decisions have not changed due to evolving external factors.

National services

The following national services may help you meet the requirements of A1.c Decision making:

Additional guidance

For additional guidance, see:

National Cyber Security Centre CAF guidance | A1 Governance
National Cyber Security Centre | Risk management – Cyber security governance


Last edited: 26 August 2026 11:39 am