> For the complete documentation index, see [llms.txt](https://guidance.ctag.org.uk/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://guidance.ctag.org.uk/data-handling-guidelines-version-6.md).

# Data Handling Guidelines Version 7

{% file src="/files/UrnbS63Mm3ubQ32tDIwB" %}

Local Public Services

Data Handling Guidelines

**Seventh Edition**

**October 2025**

<br>

## Data Handling and Information Governance Guidance for Local Public Services

&#x20;

Copyright © Dr. Mark Brett 2025

&#x20;

No part of this book may be reproduced or distributed in any form without prior written permission from the author, with the exception of non-commercial uses permitted by copyright law. No part of this book may be reproduced or transmitted by any means, except as permitted by UK copyright law or the author.<br>

&#x20;

Table of Contents

[Data Handling and Information Governance Guidance for Local Public Services](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759076)

[Chapter 1:  Information Governance: A Holistic Approach](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759077)

[Chapter 2. Artificial Intelligence (AI) and Information Governance](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759078)

[Chapter 3: Information Risk, Risk Management, Risk Appetite, and Assurance within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759079)

[3.1 Information Risk and Risk Management in the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759080)

[3.2 Risk Appetite within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759081)

[3.3 Assurance within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759082)

[Chapter 4: Risk Assessments and Risk Appetite within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759083)

[4.1 Risk Assessments within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759084)

[4.2 Risk Appetite within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759085)

[Chapter 5: Incident Management, Reporting, and Incident Response within the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759086)

[5.1 Defining and Preparing for Incidents](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759087)

[5.2 The Incident Response Process](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759088)

[5.3 Incident Reporting](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759089)

[5.4 Tools and Techniques for Incident Management](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759090)

[Chapter 6: The Cyber Assessment Framework (CAF), Stocktake, Key Lines of Enquiry (KLOEs), and Objectives & Key Results (OKRs) for Cyber Maturity](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759091)

[6.1 Understanding the Cyber Assessment Framework (CAF) for Local Government](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759092)

[6.2 Integrating a Stocktake Approach with the CAF](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759093)

[6.3 The Role of Key Lines of Enquiry (KLOEs)](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759094)

[6.4 Developing Objectives and Key Results (OKRs) to Support Cyber Maturity](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759095)

[Chapter 7: A Strategic Approach to Cyber Resilience using the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759096)

[7.1 The LACES Framework as a Strategic Integrator](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759097)

[7.2 A Ten-Step Implementation Guide using the LACES Framework](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759098)

[Chapter 8: Statecraft and Resilience in the Context of Civil Society](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759099)

[8.1 Understanding Civic Cyber Resilience](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759100)

[8.2 The Role of Statecraft in Fostering Civic Cyber Resilience](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759101)

[8.3 Impact of Cyber Incidents on Civil Society](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759102)

[8.4 Leveraging the LACES Framework for Civic Cyber Resilience](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759103)

[8.5 Conclusion](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759104)

[Chapter 9: Local Authority Devolution: Guidance for Enhanced Information Governance, Resilience, and Integration](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759105)

[9.1 Understanding Local Authority Devolution in England](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759106)

[9.2 Implications of Devolution for Information Governance](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759107)

[9.3 Enhancing Resilience in the Context of Devolution](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759108)

[9.4 Fostering Integration within Devolved Structures](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759109)

[9.5 Call to Action](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759110)

[9.6 Strategic Plan and Action Points](applewebdata://36BC9244-A1D2-41B3-BCD9-6E3B47248EF6#_Toc196759111)

&#x20;

&#x20;

&#x20;

Introduction

Welcome to this fully revised seventh edition. The Data Handling Guidelines were originally written in 2008, as a response to the HMRC CD’s going missing with huge amounts of personal information. The disappearance of the disks was never proven. At the time central government responded with a full data handling review. The Local government guidelines were written to support Local Government. We have since revised and updated the guidelines since. The latest edition has been fully revised to incorporate the information governance needs and the LACES (Local Authority Cyber Ecosystem Framework). LACES was developed during 2024 by the author and culminated in the publication of a PhD thesis. The LACES approach provides a holistic framework to understand and work with Cyber Information Governance. There are new sections covering Cyber Incident Response, the Cyber Assessment Framework (CAF), implications for Artificial Intelligence and the devolution process. These guidelines provide an approach and toolset for senior leaders in Local Public Services to help understand Cyber Security, Information Risk and governance.&#x20;

Information remains a critical asset for Local Public Services, fundamental to the efficient and effective delivery of public services. This guidance builds upon previous iterations, incorporating the latest developments in data protection legislation, notably the Data Protection Act 2018, and the evolving cyber threat landscape. It aims to provide a holistic framework for Information Management, Assurance, and Governance (IMAG™), enabling Local Public Services to build public confidence and ensure the professional and secure handling of personal data. This document recognises that Local Public Services are best placed to assess their own risk and implement necessary safeguards, serving as a guide highlighting best practices and referencing useful resources.&#x20;

<br>

&#x20;

## 1. Information Governance: A Holistic Approach

Information Governance is the framework for managing information assets effectively and securely to support an organisation's strategic goals. It encompasses policies, processes, people, and technology to ensure the confidentiality, integrity, and availability of information. A robust Information Governance regime is crucial for legal compliance, risk management, service delivery, and maintaining public trust. This guidance promotes Corporate Information Governance, integrating Corporate Risk Management and the protection of the supply chain, which is vital in today's cloud-first, internet-driven environment.

2\. The Corporate Information Governance Group (CIGG)

To ensure effective Information Governance, it is strongly recommended that a Corporate Information Governance Group (CIGG) is established, chaired by the Senior Information Risk Owner (SIRO). The CIGG should report back to senior management on a regular basis, at least quarterly.

Terms of Reference for the CIGG:

The CIGG will be responsible for:

* Overseeing the development, implementation, and maintenance of the organisation's Information Governance framework, policies, and procedures.
* Reviewing and monitoring compliance with data protection legislation, including the Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR).
* Identifying, assessing, and managing information risks across the organisation.
* Reviewing and approving Corporate Information Risk Plans (both review and forward-looking) at least annually.
* Monitoring the implementation of the Corporate Information Governance work plan.
* Ensuring the organisation has a published, tracked, and monitored implementation plan for data protection.
* Overseeing the development and maintenance of a Register of Processing Activities (ROPA).
* Reviewing and monitoring data sharing agreements and practices.
* Promoting a culture that properly values, protects, and uses information for the public good amongst all staff, including suppliers.
* Developing mechanisms through which individuals may bring concerns about information risk to the attention of senior management and ensuring these concerns are taken seriously.
* Ensuring the organisation is a member of the Regional Local Authority WARP (Warning, Advice and Reporting Point) or the Cymru WARP in Wales.
* Reviewing and monitoring cyber resilience measures and incident response plans.
* Receiving reports from Information Asset Owners (IAOs) on the security and use of their information assets.

3\. Roles and Responsibilities in Information Governance

Effective Information Governance relies on clearly defined roles and responsibilities at all levels of the organisation.

3.1 The Senior Information Risk Owner (SIRO)

A Senior Manager must fulfil the function of Senior Information Risk Owner (SIRO) to ensure accountability for information risk. Even with the changes to the Public Services Network (PSN), the retention of the SIRO role is strongly recommended.

Responsibilities of the SIRO:

* Accountable for Risk Management within the organisation.
* Should be a senior manager who is appropriately trained and familiar with information risk and the organisation’s response.
* Provide written judgement of the security and use of business assets at least annually to support the audit process.
* Provide advice to the accounting officer on the content of their statement of internal control.
* Must be briefed and aware of Cyber Threats and Cyber Incident Coordination requirements.
* Must ensure their organisation has a regular Cyber Exercising regime in place.
* Should champion the establishment and chair the Corporate Information Governance Group (CIGG).
* Responsible for ensuring that Information Asset Owners (IAOs) are clearly identified and their responsibilities are set in line with SIRO requirements.
* Needs to understand where information is created, processed, stored, and finally destroyed.
* Will need to agree if a new system containing personal data is applicable to the organisation and within its risk appetite.
* Should complete a Corporate Information Risk Plan at least once a year, or nominate an individual to do so on their behalf.
* Needs to ensure the organisation has Business Continuity Plans in place and that an annual exercise is carried out.

3.2 Information Asset Owners (IAOs)

Information Asset Owners (IAOs) are responsible for specific information assets within the organisation.

Responsibilities of the IAO:

* Understanding fully where their information asset(s) is created, processed, stored, and finally destroyed. This includes cloud services.
* Ensuring that processes relating to the operation and interfacing of systems containing their information asset(s) are properly documented and kept up to date.
* Contributing to risk assessments related to their information asset(s).
* Checking that the use of their information asset(s) is being conducted properly, especially in respect of protected personal data.
* Working with the SIRO to ensure the security and appropriate use of their information asset(s).

3.3 Data Protection Officer (DPO)

Under the Data Protection Act, all public bodies such as Local Authorities will require a Data Protection Officer (DPO)to be appointed; however, for smaller public bodies, there can be shared Data Protection Officers. The DPO must be independent and can be shared by a number of organisations. The ICO expects all Local Authorities to have a DPO.

Responsibilities of the DPO (as per ICO Guidance):

* To inform and advise the organisation and its employees about their obligations under data protection law.
* To monitor compliance with data protection law and the organisation’s data protection policies.
* To provide advice regarding Data Protection Impact Assessments (DPIAs).
* To cooperate with the ICO.
* To be the first point of contact for the ICO and for individuals whose data is processed.

4\. The Cabinet Office Cyber Assessment Framework (CAF) and Data Handling

The UK Government has an "Internet First" approach, which will see a move towards processes supporting the Cabinet Office Cyber Assessment Framework (CAF) and the Local Government version of that, the LG-CAF. The formulation of the LG-CAF aims to provide a framework for cross-organisational assurance and act as a common currency for Information Sharing across the UK Public Sector.

Effective data handling, as outlined in this guidance, directly supports the objectives of the CAF and LG-CAF by ensuring:

* Secure data storage and processing: Adhering to principles of integrity and confidentiality.
* Robust access controls: Limiting access to personal data to authorised personnel.
* Proper data disposal: Securely destroying information when it is no longer needed.
* Effective incident management: Having plans in place to respond to and recover from data breaches and cyber incidents.
* Supply chain security: Ensuring third-party processors have adequate security measures.
* Awareness and training: Educating staff on their responsibilities for data protection and security.
* Risk assessment and management: Identifying and mitigating threats to information assets.

By implementing the data handling practices recommended in this guidance, Local Public Services will be better positioned to meet the requirements of the CAF and LG-CAF, demonstrating their commitment to cyber resilience and information assurance.

5\. Secure by Design

The principle of secure by design should be embedded in all processes relating to systems operation and interfacing. This means that security and data protection considerations are integrated into the design and development of systems and services from the outset.

Key aspects of secure by design include:

* Understanding information flows: Documenting where information is created, processed, stored, and destroyed.
* Risk assessment from the beginning: Identifying potential security and privacy risks early in the development lifecycle.
* Implementing appropriate security controls: Choosing and implementing technical and organisational measures to mitigate identified risks. This includes considering encryption, strong authentication, and access controls.
* Data minimisation: Ensuring that only necessary personal data is collected and processed.
* Privacy by default: Configuring systems and services so that the most privacy-protective settings are the default.
* Regular testing and review: Conducting penetration testing and vulnerability scanning to identify and address weaknesses.
* Considering the insider threat: Implementing measures to prevent data breaches caused by human error or malicious actions, including training and awareness raising.
* Following secure development practices: Adhering to secure coding standards and principles, especially when using agile development methodologies. When using agile, information risks must be fully understood and addressed at each release.
* Utilising Privacy Enhancing Technologies (PETs) where appropriate.

6\. Call to Action

Local Public Services are urged to adopt the principles and practices outlined in this enhanced guidance to strengthen their Information Governance regimes and ensure the secure and responsible handling of data. By prioritising these measures, organisations can enhance public trust, comply with legal obligations, and build resilience against the ever-evolving cyber threats.

7\. Ten Actionable Points

1. Establish or review your Corporate Information Governance Group (CIGG) with clear terms of reference and ensure it meets regularly.
2. Ensure a Senior Manager is appointed and actively fulfilling the role of Senior Information Risk Owner (SIRO) with clearly defined responsibilities.
3. Identify and clearly define the roles and responsibilities of Information Asset Owners (IAOs) for all key information assets.
4. Maintain a comprehensive and up-to-date Register of Processing Activities (ROPA) as required by the Data Protection Act 2018 and the UK GDPR.
5. Develop and implement a Corporate Information Risk Policy and corresponding Corporate Information Risk Plans, reviewed at least annually.
6. Embed the principles of "secure by design" into all new and existing systems and processes that handle personal data.
7. Develop, implement, and regularly exercise Cyber Incident Response Plans to prepare for and manage potential cyber attacks and data breaches.
8. Implement a comprehensive training and awareness program for all staff (including suppliers) on data protection, information security, and secure data handling practices. Keep records of all training.
9. Conduct regular risk assessments, including Data Protection Impact Assessments (DPIAs) for processing likely to result in high risk to individuals.
10. Review and update all Data Sharing Agreements to ensure they comply with the Information Commissioner’s Data sharing code of practice and include agreed terms for data sharing, security, and disposal.

By taking these actionable steps, Local Public Services can significantly enhance their data handling practices and strengthen their overall Information Governance framework.

&#x20;

&#x20;

<br>

&#x20;

### Chapter 1:  Information Governance: A Holistic Approach

Information Governance is the framework for managing information assets effectively and securely to support an organisation's strategic goals. It encompasses policies, processes, people, and technology to ensure the confidentiality, integrity, and availability of information. A robust Information Governance regime is crucial for legal compliance, risk management, service delivery, and maintaining public trust. This guidance promotes Corporate Information Governance, integrating Corporate Risk Management and the protection of the supply chain, which is vital in today's cloud-first, internet-driven environment.

Information remains a critical asset for organisations and is fundamental to effective service delivery. Protecting this information, especially personal data, is a legal requirement. Information Governance provides the necessary structure to meet these legal obligations and to safeguard this key business asset.

A holistic approach to Information Governance considers several key components:

* Policies: A comprehensive set of policies forms the heart of any Information Governance regime. These policies need to be monitored and audited to ensure they are effectively enacted. Local Public Services should implement a range of security policies to ensure compliance. Examples of policy areas include secure disposal and destruction of information assets, log management, disclosure of information, risk management, protective marking, and the use of personal devices. The Senior Information Risk Owner (SIRO) also oversees the development, implementation, and regular review of clear and comprehensive information security policies and procedures.
* Processes: All processes relating to systems operation and interfacing should be properly documented with up-to-date information and included in risk assessments. It is essential that the SIRO and Information Asset Owners (IAOs) fully understand where information is created, processed, stored, and finally destroyed, a challenge further highlighted by the use of cloud services. Implementing clear Data Handling Procedures encompassing people, places, policies, processes, and procedures is crucial. A standards-based approach to service management, such as the Information Technology Infrastructure Library (ITIL), is recommended to align IT services with business needs.
* People: All staff (including suppliers) should develop a culture that properly values, protects, and uses information for the public good. Local Public Services should reinforce that information is a key business asset, and its proper use is not simply an IT issue. Training and awareness programmes are essential to ensure employees understand data governance policies, AI ethics, and legal requirements. Governance roles and responsibilities must be clearly defined. A Senior Manager should fulfil the function of the SIRO to ensure accountability. Information Asset Owners (IAOs) are responsible for specific information assets. The establishment of a Corporate Information Governance Group (CIGG), chaired by the SIRO, is strongly recommended to oversee Information Governance.
* Technology: Technology plays a crucial role in enabling effective and secure information management. The principle of secure by design should be embedded in all processes relating to systems operation and interfacing, integrating security and data protection considerations from the outset. This includes understanding information flows, conducting risk assessments early, implementing appropriate security controls (including encryption and access controls), data minimisation, and regular testing. The increasing reliance on cloud services necessitates careful consideration of offshoring data and ensuring data is kept within appropriate jurisdictions, often requiring the use of model contract clauses.

Corporate Information Governance promotes the integration of Corporate Risk Management and the protection of the supply chain. In today's cloud-first, internet-driven world, managing information risk within the supply chain, ensuring suppliers adhere to appropriate security standards, is critical.

A robust Information Governance regime is crucial for several reasons:

* Legal Compliance: It ensures adherence to data protection legislation, such as the Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR). Compliance with these laws, overseen by the Information Commissioner's Office (ICO), is essential to avoid penalties and maintain legal standing. This includes principles like lawfulness, fairness, transparency, integrity, and confidentiality (security), as well as the accountability principle.
* Risk Management: It facilitates the identification, assessment, and mitigation of information risks across the organisation. This includes cyber security risks, data breaches, and risks associated with the use of new technologies like AI. The SIRO is accountable for risk management within the organisation. Conducting regular risk assessments, including Data Protection Impact Assessments (DPIAs) for high-risk processing, is a key aspect of this.
* Service Delivery: By ensuring the availability and integrity of information assets, effective Information Governance supports the efficient and effective delivery of public services. Accurate and accessible information is vital for informed decision-making and operational efficiency.
* Maintaining Public Trust: In the delivery of public services, building and maintaining public confidence is paramount. Ensuring that personal data is handled professionally, and that privacy is protected through robust Information Governance practices is essential for fostering this trust. Transparency regarding data handling practices and AI usage is also important for building public trust.

By embracing a holistic approach to Information Governance, organisations can effectively manage their information assets, mitigate risks, comply with legal obligations, and maintain the trust of the individuals they serve.

### Chapter 2. Artificial Intelligence (AI) and Information Governance

Building upon the foundational principles of Information Governance outlined in the previous chapter, the increasing adoption of Artificial Intelligence (AI) necessitates a significant expansion and adaptation of existing frameworks. AI, while offering tremendous potential for improving services and driving innovation, also introduces novel complexities and risks that must be addressed through a holistic and integrated Information Governance approach. This chapter will explore how the core components of Information Governance – policies, processes, people, and technology – are impacted and need to evolve in the age of AI.

Policies for AI Governance

The establishment of clear and comprehensive AI governance policies is paramount. These policies should align with existing information security and data handling policies but also address the unique challenges posed by AI systems.

* Ethical Considerations and Fairness: AI policies must explicitly address ethical considerations, ensuring that AI systems are fair, unbiased, and do not discriminate against any group. This includes guidelines on bias detection and mitigation, algorithmic fairness, and the responsible design and development of AI systems by applying the principles of privacy by default and privacy by design. Organisations should consider definitions of fairness appropriate to a system’s use and may need to establish independent ethics committees.
* Transparency and Explainability: Policies should mandate transparency regarding AI systems, including clear documentation of how they work, what data they use, and their limitations. Guidelines for achieving explainable AI (XAI), ensuring AI decisions are understandable to stakeholders, are essential. This includes algorithmic transparency and the auditability of systems.
* Accountability and Responsibility: Clear lines of accountability for AI-driven outcomes must be defined. Policies should designate individuals or teams responsible for each AI system, including the SIRO's role in championing the development of an AI governance framework. Mechanisms for audit, continuous monitoring, and impact assessment of AI systems should be established.
* Data Governance for AI: Specific policies are needed for the data used in AI, ensuring data is collected with proper consent, is relevant, and of sufficient quality, accuracy, and representativeness. Policies should cover data access controls, especially for sensitive information used in AI.
* Security and Privacy in AI: Given the risks AI introduces related to privacy and security, especially when handling sensitive data, policies must address these concerns. This includes guidelines on preventing unauthorised access, data breaches, and exposure of personally identifiable information (PII), aligning with regulations like GDPR and CCPA. Policies should also cover data masking, encryption, access controls, and regular audits.
* Compliance and Legal Framework: AI policies must ensure compliance with relevant legal frameworks, including the Data Protection Act 2018, UK GDPR, and potentially sector-specific regulations and the Equality Act 2010. The policies should reflect the ICO's guidance on AI and data protection.

Processes for AI Governance

Integrating AI considerations into existing organisational processes and establishing new AI-specific processes is crucial for effective governance.

* Data Audit with an AI Focus: Organisations should conduct data audits specifically focusing on the quality, accuracy, and representativeness of data used in AI training, identifying potential biases and assessing the security of sensitive data.
* Development and Deployment Lifecycle: Governance processes should be embedded throughout the AI system lifecycle, from design and data collection to deployment, operation, and decommissioning. This includes assessing and documenting the expected impacts on individuals and society at the beginning of an AI project and throughout its lifecycle.
* Procurement of AI Systems: All procurement processes must take AI into account from a risk and assurance viewpoint. Security and ethical considerations should be embedded in the procurement of AI systems, focusing on the often-opaque nature of AI supply chains. Due diligence processes should include evaluating trade-offs made by third-party AI providers.
* Risk Assessment and DPIAs for AI: Undertaking Data Protection Impact Assessments (DPIAs) is a key process for identifying and mitigating the data protection risks associated with AI. DPIAs for AI should be conducted at the earliest stages of project development and should consider the specific ways AI processing might pose high risks to individuals. This includes assessing risks of bias, inaccuracy, and automated decision-making.
* Bias Detection and Mitigation Processes: Implementing processes to regularly check AI models for bias and take corrective actions is essential. This may involve technical approaches to mitigate algorithmic bias and processing personal data for bias mitigation.
* Incident Response for AI: Organisations need to ensure they have plans to deal with any AI-related data breaches or security incidents. Existing incident response plans may need to be adapted to address the specific challenges posed by AI.
* Monitoring and Audit of AI Systems: Continuous monitoring and periodic review of oversight mechanisms for AI systems are necessary to ensure their proper functioning and adherence to policies. Audit trails of AI decisions and influencing factors should be maintained.
* Managing Automated Decision-Making: Clear processes must be in place for managing AI systems involved in solely automated decision-making that have legal or similarly significant effects on individuals, including providing safeguards and the right to contest such decisions. Meaningful human oversight should be ensured for such systems.

People and AI Governance

A strong culture of responsible AI adoption requires ensuring that all personnel, including leaders, technical teams, and general staff, understand their roles and responsibilities in governing AI.

* Leadership Engagement and Accountability: Senior management, including the SIRO and DPOs, are accountable for the governance and data protection risk management of AI systems. They should set a meaningful risk appetite for AI adoption and ensure AI initiatives align with organisational values and ethical principles.
* Specialised Expertise: Effective AI-driven data governance demands a coordinated approach involving business leaders, IT teams, and data teams. Organisations need to invest in both internal talent development and strategic external partnerships to gain the specialized knowledge and skills required for AI governance, including understanding concepts like explainability, bias mitigation, and model robustness. Upskilling data teams through training and mentorship programs is crucial.
* Awareness and Training: Investing in awareness raising, education, research, and training is vital to ensure a good level of information on and understanding of AI and its potential effects in society. Training programs should cover data governance policies, AI ethics, legal requirements, and the data protection implications of AI processing. Human reviewers of AI-assisted decisions require specific training to understand AI systems, identify potential errors, and exercise appropriate oversight.
* Clear Roles and Responsibilities: Governance roles and responsibilities related to AI must be clearly defined. This includes identifying Information Asset Owners (IAOs) for data used in AI systems and defining responsibilities for the development, testing, validation, deployment, and monitoring of AI.
* Stakeholder Engagement: Engaging with stakeholders, including individuals whose data is processed by AI systems and those potentially affected by AI outcomes, is crucial for ensuring responsible AI development and deployment. Seeking and documenting the views of individuals during the AI lifecycle, unless there is a good reason not to, is a good practice.
* Fostering a Culture of Responsibility: Organisations should foster a culture that values the ethical and responsible use of AI. This includes promoting collective and joint responsibility involving the whole chain of actors and stakeholders.

&#x20;

&#x20;

&#x20;

Technology for AI Governance

Technology plays an enabling role in implementing and enforcing AI governance policies and processes.

* AI Governance Tools: Adopting AI governance tools that automate tasks like data documentation and insight generation can ease the technical burden. AI-driven governance tools can continuously monitor data access, identify vulnerabilities, and protect sensitive information through methods like data masking.
* Data Catalogues: Investing in tools like Collibra or Alation helps organisations create and maintain an inventory of data assets, making it easier to track data lineage, manage metadata, and ensure consistent data usage across AI projects.
* Data Quality Management Tools: Tools for ensuring and monitoring the quality and accuracy of data used in AI systems are essential for mitigating bias and ensuring reliable outcomes.
* AI Fairness Toolkits: Implementing AI fairness toolkits can aid in bias detection, mitigation, and the evaluation of fairness in AI models.
* Explainable AI (XAI) Technologies: Investing in public and private scientific research on explainable artificial intelligence and deploying XAI techniques are crucial for improving the transparency and intelligibility of AI systems.
* Security Technologies for AI: Deploying specific security measures for AI systems is necessary to address the unique security challenges they present. This includes assessing the security of both in-house and externally maintained AI code and frameworks.
* Privacy-Enhancing Technologies (PETs): Exploring and implementing privacy-preserving techniques can help minimise the amount of personal data processed by AI systems and mitigate privacy risks.

Maintaining Legal Compliance, Managing Risk, and Building Public Trust in the Age of AI

The effective integration of AI into the Information Governance framework is fundamental for:

* Legal Compliance: A robust AI governance regime ensures adherence to data protection laws and other relevant legislation. By focusing on lawfulness, fairness, transparency, and accountability in AI systems, organisations can mitigate the risk of non-compliance and potential penalties from regulatory bodies like the ICO. Understanding the lawful basis for processing personal data in AI development and deployment is crucial.
* Risk Management: Addressing the emerging risks associated with AI, such as bias, lack of explainability, security vulnerabilities, and privacy breaches, is a core function of AI governance. A risk-based approach, including regular DPIAs, helps organisations identify, assess, and mitigate these risks effectively. Understanding and managing trade-offs between different objectives, such as accuracy and fairness, is also essential.
* Service Delivery: Well-governed AI systems can enhance the efficiency, effectiveness, and innovation of service delivery. By ensuring AI systems are robust, secure, accurate, and fair, organisations can leverage their benefits while minimising potential negative impacts on service users.
* Maintaining Public Trust: Transparency, fairness, and accountability in the use of AI are crucial for building and maintaining public trust. Clearly communicating how AI systems are used, ensuring decisions are explainable and fair, and providing mechanisms for redress when things go wrong are essential for fostering public confidence in AI-powered services.

In conclusion, as AI becomes increasingly integrated into organisational operations, a proactive and comprehensive approach to Information Governance is essential. By adapting policies, evolving processes, empowering people with the necessary skills and awareness, and leveraging appropriate technologies, organisations can harness the transformative power of AI responsibly and ethically, while safeguarding information, ensuring legal compliance, managing risks effectively, and ultimately maintaining the trust of the public they serve. The SIRO plays a vital role in championing this "AI readiness".

&#x20;

<br>

&#x20;

### Chapter 3: Information Risk, Risk Management, Risk Appetite, and Assurance within the LACES Framework

This chapter will explore the critical concepts of information risk, risk management, risk appetite, and assurance, and how these align with and are integral to the Local Authority Cyber Eco-System (LACES) framework. The LACES framework, with its six interconnected variables – Governance, Assurance, Processes, Data, Resilience, and Knowledge Sharing – provides a holistic model for understanding and managing cybersecurity within local authorities.

3.1 Information Risk and Risk Management in the LACES Framework

Information risk refers to the potential for loss or harm resulting from the compromise of confidentiality, integrity, or availability of information. This compromise can impact an organisation's ability to deliver vital services, lead to the loss of personal or sensitive data, and increase risks to compliance and legal standing. In the context of the LACES framework, information risk permeates all six variables.

Risk management is the systematic process of identifying, assessing, treating, and monitoring risks. It is a fundamental aspect of ensuring the security and responsible handling of data. Within the LACES framework:

* Governance sets the direction for risk management by establishing policies, responsibilities (e.g., SIRO, IAOs), and structures like the Corporate Information Governance Group (CIGG) to oversee information risks. Defining and communicating a clear information risk appetite is a fundamental governance activity.
* Assurance focuses on the mechanisms and activities that provide confidence that information risks are being effectively managed. This includes conducting regular risk assessments to identify vulnerabilities and threats in both physical and virtual domains, as well as implementing security audits and penetration testing for independent validation of security controls.
* Processes related to systems operation and interfacing should be properly documented and included in risk assessments. Understanding where information is created, processed, stored, and destroyed is essential for effective risk management. Secure by design principles should be embedded into all new and existing systems and processes that handle personal data.
* Data, being a key asset, is central to information risk management. The LACES framework aims to protect data, and risk management activities must consider the confidentiality, integrity, and availability of this data. Data protection impact assessments (DPIAs) are crucial for identifying and mitigating risks associated with processing personal data, particularly in AI systems.
* Resilience focuses on maintaining operational continuity in the face of cyber incidents or disruptions. This inherently involves managing the risks that could lead to such incidents through business continuity planning, disaster recovery, and incident response plans. Risk analysis is a key component of building resilience.
* Knowledge Sharing facilitates better risk management by enabling the exchange of information about threats, vulnerabilities, and best practices. Mechanisms for individuals to raise concerns about information risk and for these concerns to be taken seriously are vital.

A key aspect of risk management within LACES is understanding the threats and vulnerabilities that could exploit weaknesses. This process, involving risk, threat, and vulnerability assessments, helps focus resources effectively. The LACES framework itself can be used to assess and mitigate cyber risks associated with new technologies and the supply chain.

3.2 Risk Appetite within the LACES Framework

Risk appetite is the level of risk an organisation is willing to accept in pursuit of its objectives. Articulating and agreeing upon a shared understanding of information risks among senior managers and stakeholders is a crucial aspect of governance within the LACES framework.

* A clearly defined Information risk appetite is a fundamental governance activity, guiding decision-making related to information risk. Without a written, accepted, and understood risk appetite, an organisation cannot effectively understand its information risks, priorities, and where to invest time and budget.
* The risk appetite should reflect the need for a local authority to protect and manage the information it handles, as compromising its confidentiality, integrity, and availability can severely impact service delivery and compliance.
* The Senior Information Risk Owner (SIRO) is responsible for owning and annually reviewing the risk appetite. They must be informed of any residual risks affecting authority information systems and act as the final arbiter on these risks.
* When procuring new systems, it is important to consider whether they fall within the organisation's defined risk appetite. Furthermore, when deploying AI systems, the approach should align with the overall risk appetite from the outset.
* Documenting how final decisions fit within the overall risk appetite is an important aspect of accountability.

Articulating risk appetites for emerging technologies like AI is an evolving area. A potential approach involves modelling harm and consequences, similar to resilience and emergency planning.

3.3 Assurance within the LACES Framework

Assurance within the LACES framework focuses on providing confidence that information risks are being effectively managed. It encompasses a range of activities designed to verify the implementation and effectiveness of security controls and processes.

Key elements of Assurance within LACES include:

* Risk Assessment: Regularly identifying, assessing, and understanding security risks to personal data and the systems that process it. This is a core assurance activity.
* Auditing and Penetration Testing: Implementing security audits and penetration testing provides independent validation of security controls.
* Monitoring: Establishing robust monitoring systems (e.g., SIEM) and baselines for normal system loads to detect anomalies. Cyber hygiene monitoring is also crucial.
* Managing the Supply Chain: Ensuring that third-party suppliers and contractors are subject to the organisation’s policies and procedures, formalised in contracts.
* Ensuring Systems and Services are Secure and Robust: Implementing secure by design principles.
* Implementing a Defence in Depth Approach: Employing multiple layers of security controls.
* Exercising and Response Planning: Regularly rehearsing cyber incident response procedures to ensure preparedness.

The Assurance variable of the LACES framework is critical to ensuring that the Governance policies are being implemented effectively and that the Processes are operating securely to protect Data and maintain Resilience. Assurance findings and recommendations should be shared to improve security practices, contributing to Knowledge Sharing within the framework. Furthermore, in a principles-led approach, assurance is essential to provide cross-checks and balances within different professional disciplines.

In conclusion, information risk, risk management, risk appetite, and assurance are fundamental and interconnected concepts that are fully integrated within the LACES framework. By addressing these elements through the lens of Governance, Assurance, Processes, Data, Resilience, and Knowledge Sharing, local authorities can build a more robust and effective cybersecurity posture.<br>

### Chapter 4: Risk Assessments and Risk Appetite within the LACES Framework

Building upon the foundational concepts introduced in the previous chapters, this chapter will delve into two critical components of cybersecurity management within the context of the Local Authority Cyber Eco-System (LACES) framework: Risk Assessments and Risk Appetite. These elements are fundamental for understanding and mitigating cyber risks effectively and are deeply intertwined with the Assurance and Governance variables of the LACES framework.

4.1 Risk Assessments within the LACES Framework

Risk assessment is a systematic process employed to identify, evaluate, and mitigate risks to an organisation's information assets and operations. It is a core assurance activity within the LACES framework. Regular risk assessments are essential to identify vulnerabilities and threats in both the physical and virtual domains. These assessments should be a continuous process, especially in the dynamic landscape of cyber threats.

Within the LACES framework, risk assessments are integral to several variables:

* Assurance: Risk assessments are a primary mechanism for providing confidence that information risks are being effectively managed. They help to identify areas of vulnerability and inform the implementation of security controls.
* Processes: Risk assessments should consider the security of operational processes and how information is handled throughout its lifecycle. This includes understanding system interdependencies and data flows.
* Data: Protecting data is a central goal, and risk assessments are crucial for identifying risks to the confidentiality, integrity, and availability of data. Data Protection Impact Assessments (DPIAs) are a specific type of risk assessment focusing on the risks to individuals' rights and freedoms arising from the processing of personal data, particularly in the context of AI systems. DPIAs should objectively assess the likelihood and severity of risks and identify mitigation measures.
* Resilience: Understanding potential risks through risk assessments informs the development of effective business continuity and incident response plans. By testing risk assessments through assurance activities, deficiencies in plans can be understood, supporting a proactive approach to dealing with cyber incidents.
* Governance: Governance structures, such as the Corporate Information Governance Group (CIGG), oversee the risk assessment process and ensure its alignment with organisational objectives and risk appetite.

Various methodologies can be employed for risk assessments. The Silverthorn Method emphasises emergent threats and horizon scanning, explicitly incorporating the dynamic nature of the threat landscape. This distinguishes it from more traditional methods like NIST SP 800-30 and OCTAVE, which may not place the same emphasis on anticipating future risks. Horizon scanning is "the systematic examination of potential threats, opportunities and likely future developments which could be strategically important to an organisation".

A comprehensive risk assessment process should include:

* Risk Identification: Identifying potential hazards or threats that could compromise information assets. This can involve horizon scanning to anticipate emerging threats.
* Threat Assessment: Understanding the capabilities and intent of potential adversaries. Threat profiling helps to understand an organisation's susceptibility to attack.
* Vulnerability Assessment: Identifying weaknesses in systems, processes, or physical security that could be exploited by threats. Regular vulnerability scanning is a key practice.
* Risk Analysis: Evaluating the potential impact and likelihood of identified risks. Frameworks like MITRE ATT\&CK can be used for risk analysis and network defence. Qualitative risk analysis can be used to evaluate risks.
* Risk Prioritization: Focusing efforts on the most significant risks based on their potential impact and likelihood.
* Risk Treatment (Mitigation): Developing and implementing strategies to reduce the likelihood or impact of identified risks. This can include data minimisation techniques.
* Risk Monitoring and Review: Continuously monitoring the risk landscape and the effectiveness of implemented controls, and regularly reviewing and updating risk assessments. In an agile environment, a more iterative and cyclic approach to risk and threat management is necessary.

Risk assessments should consider the interconnectedness of physical and virtual domains and the potential impact of new technologies like AI. For AI systems, DPIAs are crucial for assessing risks to individuals' rights. Furthermore, risk assessments should inform the development and review of cyber resilience plans and incident response capabilities.

4.2 Risk Appetite within the LACES Framework

Risk appetite defines the level of risk an organisation is willing to accept in pursuit of its objectives. Defining and communicating a clear information risk appetite is a fundamental governance activity within the LACES framework.

Within the LACES framework, risk appetite is primarily linked to the Governance variable:

* Governance: Establishing and communicating the organisation's risk appetite is a core responsibility of senior management and is essential for guiding decision-making related to information risk. The Senior Information Risk Owner (SIRO) plays a key role in defining, owning, and annually reviewing the information risk appetite.
* The risk appetite acts as a guide for all other variables, influencing the level of investment in assurance activities, the stringency of processes, the security measures applied to data, the resources allocated to resilience, and the focus of knowledge sharing.

A well-defined risk appetite statement is crucial for several reasons:

* Guiding Decision-Making: It provides a framework for evaluating potential risks and determining whether they are acceptable.
* Resource Allocation: It helps in prioritising investments in security controls and risk mitigation efforts. An organisation should not typically spend significantly more to mitigate a risk than the potential loss associated with it.
* Accountability: It provides a benchmark against which risk management performance can be assessed. Documenting how final decisions align with the overall risk appetite is important for demonstrating accountability.
* Understanding Priorities: Without a written, accepted, and understood risk appetite, an organisation cannot effectively understand its information risks and priorities.

Articulating a risk appetite, especially for complex and evolving areas like AI, can be challenging. A suggested approach involves modelling potential harm and consequences, similar to methodologies used in resilience and emergency planning. The NIST AI risk framework offers a four-step approach to risk management: govern, map, measure, and manage, which can support the articulation of risk appetite for AI.

The risk appetite should reflect the specific needs and context of the local authority, considering its vital services, the personal and sensitive information it handles, and its legal and compliance obligations. Compromising the confidentiality, integrity, or availability of this information can have significant consequences, and the risk appetite should reflect the organisation's tolerance for such impacts. Ultimately, the risk appetite is central to the entire information security and assurance landscape, providing a crucial foundation for effective cybersecurity management within the LACES framework.

&#x20;

<br>

&#x20;

### Chapter 5: Incident Management, Reporting, and Incident Response within the LACES Framework

Building upon the previous chapters, this chapter will explore the critical aspects of Incident Management, Reporting, and Incident Response within the context of the Local Authority Cyber Eco-System (LACES) framework. Effective handling of security incidents is paramount for minimising disruption, mitigating potential damage, and maintaining public trust. This chapter will outline the key elements of a robust incident management framework, drawing upon the principles of LACES and the guidance provided in the sources.

5.1 Defining and Preparing for Incidents

An incident can be defined as an emergency or event that threatens to disrupt normal business activities. In the context of cybersecurity, this can range from data breaches and cyberattacks to system failures. Being prepared for such incidents is crucial, and this involves several key steps:

* Developing an Incident Management Plan: A comprehensive Cyber Incident Response Plan is essential. This plan should serve as a reference tool for the actions required during or immediately following an incident. It should outline steps for detecting, containing, and recovering from cyber incidents. The plan should be regularly reviewed and updated.
* Establishing an Incident Management Team (IMT): The Business Continuity Plan guidance highlights the need for an Incident Management Team (IMT) composed of applicable members of staff. This team will coordinate actions and manage communications during an incident. The responsibility for the initial response often lies with a designated role who will work with selected members to form the IMT.
* Defining Roles and Responsibilities: Clear roles and responsibilities within the incident response process are vital. A dedicated Cyber Response Coordinator plays a crucial role in coordinating the cyber incident response team once activated, acting as a liaison officer and ensuring effective communication. The Leggiest (Rapporteur) role, responsible for maintaining a decision log, is a novel addition to the internal cyber response team that has been adopted across Wales.
* Implementing Business Continuity and Disaster Recovery Plans: Alongside the incident response plan, organisations need Business Continuity Plans to maintain critical functions if primary systems become unavailable and Disaster Recovery Plans for restoring IT systems and data after a major incident. These plans should be regularly tested.
* Conducting Risk Assessments: As discussed in the previous chapter, regular risk assessments are essential for identifying potential threats and vulnerabilities that could lead to incidents. Understanding these risks informs the development of more effective incident response plans.
* Promoting a Security Culture and Training: Establishing and maintaining a robust Training & Awareness Programme is a key governance responsibility. All staff should understand their roles and responsibilities in protecting information and reporting incidents. Encouraging a culture where reporting incidents and "Near misses" is encouraged and not punished is crucial for early detection and effective response. Regular cyber exercising is also vital for testing policies and procedures and raising awareness at all levels. The PET (Analyse the Risks, Plan, Educate and Test) cycle should be continuously applied to enhance incident preparedness.

5.2 The Incident Response Process

The incident response process typically involves several stages:

* Detection and Initial Assessment: Recognising that an incident has occurred is the first step. This might involve monitoring systems for unusual activity. Once detected, the initial response checklist includes actions like following evacuation procedures, calling emergency services if necessary, ensuring the safety and welfare of all affected persons, and calling a meeting of the IMT. Establishing the situation by answering key questions (what happened, when, where, severity, impact, etc.) is crucial.
* Declaration and Communication: Once an incident is confirmed, it should be formally declared. Immediate communication to staff about the implications and requirements is necessary. If necessary, key partners and suppliers should also be informed. Internal communication channels for information sharing should be established. During an incident, the shift to "fast-time" communication using secure channels is essential for effective collaboration and coordination within the incident response team and with external partners.
* Containment: The goal of this phase is to limit the scope and impact of the incident. This might involve isolating affected systems or networks.
* Eradication: This involves removing the threat and restoring affected systems to a secure state.
* Recovery: The focus here is on restoring normal business operations. This includes recovering data from backups.
* Post-Incident Activities: After the immediate response, it is necessary to produce a summary report and transition to recovery. A post-incident debrief should be conducted to identify what worked well, what didn't, and what changes need to be made for the future. After-action reporting is necessary to summarise the initial response and transition to recovery. The review, lessons learned and improvement process afterwards is critical for enhancing future incident response capabilities. Lessons learned should be documented and shared internally and with external stakeholders where appropriate.

5.3 Incident Reporting

Effective incident reporting is crucial for situational awareness, collaboration, and compliance:

* Internal Reporting: Clear incident reporting mechanisms with defined escalation paths are essential. All staff should know how to report suspected incidents. A log of all emergency actions taken should be commenced. A Master Activity Log should be maintained, recording all actions, decisions, meetings, and briefing sessions.
* Reporting to Warning, Advice and Reporting Points (WARPs): Serious Security incidents should initially be reported to the Regional Local Authority WARP. WARPs play a key role in a collaborative approach to cyber incident response in the UK. Organisations should be members of their regional WARP.
* Reporting to the National Cyber Security Centre (NCSC): Serious network security incidents affecting specific government networks MUST be reported to NCSC(IM). The NCSC generally will only intervene at category 3 or above in their cyber incident categorisation system. Organisations need their own support arrangements for lower-level attacks.
* Reporting Personal Data Breaches to the Information Commissioner's Office (ICO): Significant, actual or potential losses of personal data should be notified to the Information Commissioner's Office (ICO) as soon as reasonably practicable. Failure to report a serious breach could risk immediate enforcement action. The notification should include details of the nature of the breach, the likely consequences, and the measures taken to address it. Information can be provided in phases if not all details are immediately available. Processors must communicate data breaches to the controller without undue delay. A record of all personal data breaches, regardless of whether they need to be reported, must be kept. The ICO also has a free helpline for advice on data protection compliance, including responses to data loss incidents.
* Reporting to Data Subjects: Incidents that pose a “high risk” to data subjects will need to also be reported to them directly.
* AI-related Incident Reporting: There is a growing recognition of the need for specific incident reporting categories for AI (LLMs) as part of cyber incident response and resilience. It is important to consider how AI systems themselves will identify and report incidents.

5.4 Tools and Techniques for Incident Management

Several tools and techniques can enhance incident management and response:

* Playbooks: Pre-agreed plans or playbooks should be enacted during incident response. These can document specific actions related to different incident scenarios, removing ambiguity and allowing for delegated actions.
* Golden Hour Guide: This provides a novel approach to inform initial actions when responding to cyber incidents. It emphasises the critical nature of the first hour in mitigating damage.
* Crash Gate Framework: This framework facilitates the definition of trigger points for escalation in cyber incident response planning and response. It uses variables like Consequence Scaling, Resilience Scoring, Applicability Scoring, Severity Scoring, and Harm Levels to enumerate an incident and build fast-time situational awareness.
* Information Asset Registers: Maintaining detailed documentation about systems, services, and networks, particularly through Information Asset Registers, is critical for effective incident response and recovery.
* Warning, Advice and Reporting Points (WARPs): These facilitate a collaborative approach to cyber incident response through information sharing.
* Security Information and Event Management (SIEM) Systems: These can be used for robust monitoring to detect unusual traffic patterns and resource usage.

Effective Incident Management, Reporting, and Response are integral to the Resilience variable of the LACES framework. By proactively preparing, having well-defined processes, understanding reporting obligations, and utilising appropriate tools, Local Public Services can significantly enhance their ability to handle cyber incidents effectively and maintain the security and integrity of their information assets.

&#x20;

<br>

&#x20;

### Chapter 6: The Cyber Assessment Framework (CAF), Stock take, Key Lines of Enquiry (KLOEs), and Objectives & Key Results (OKRs) for Cyber Maturity

This chapter will detail the Cyber Assessment Framework (CAF) for local government, explaining how it can be used in conjunction with a stocktake approach and Key Lines of Enquiry (KLOEs) to enhance cyber maturity. Furthermore, it will provide a detailed example of developing Objectives and Key Results (OKRs) to support the achievement of cyber maturity goals.

6.1 Understanding the Cyber Assessment Framework (CAF) for Local Government

The Cyber Assessment Framework (CAF) is a recognised National Cyber Security Centre (NCSC) framework specifically adapted for councils. It is designed to help local government organisations assess their current cyber resilience and identify and mitigate vulnerabilities that could disrupt their important services. The CAF is not intended as a tick-box exercise but rather requires cross-organisational collaboration.

Key benefits of using the CAF for local government include:

* Assessing the current cyber resilience of your organisation.
* Identifying cyber risks that could disrupt your most important services.
* Improving resilience to potential cyber-attacks.
* Knowing what areas to prioritise through actionable recommendations, leading to efficient spending of time and money.
* Understanding your cyber posture against a national benchmark.
* Embedding a culture of cyber security across the whole organisation, not just IT teams.
* Building a strong foundation of resilience to understand and manage risk appropriately.
* Serving as a method for good risk management at a local authority level when used routinely.
* Complementing existing cyber plans or acting as a tool to start conversations around cyber security.
* Aligning with UK government cyber security policy.

&#x20;

&#x20;

The CAF is based on four objectives that build good cyber resilience:

* Managing security risks (Objective A). This objective focuses on ensuring the security of essential network and information systems through governance, risk management, asset management, and supply chain management strategies.
* Protecting against cyber-attack (Objective B). This objective requires organisations to meet principles such as service protection policies and processes, identity and access control, data security, system security, resilient networks and systems, and staff awareness and training.
* Detecting cyber security events (Objective C). This involves having security monitoring processes in place.
* Minimising the impact of cyber security incidents (Objective D). This objective involves response and recovery planning and a 'lessons learned' function.

To achieve these objectives, the CAF uses a structure of principles, contributing outcomes, and Indicators of Good Practice (IGPs). The framework focuses on what needs to be achieved (outcomes) rather than a checklist of what needs to be done.

6.2 Integrating a Stocktake Approach with the CAF

A stocktake approach, such as the one used to benchmark and track cyber posture maturity in Welsh Local Authorities, can be effectively integrated with the CAF. The stocktake often involves asking a series of questions related to cybersecurity practices. These questions can be mapped directly to the CAF objectives and principles, allowing an organisation to understand its current state of cyber resilience against the framework.

By using a stocktake questionnaire aligned with the CAF, councils can:

* Systematically assess their alignment with the CAF objectives and principles.
* Identify areas where they meet the contributing outcomes and indicators of good practice, and areas where improvements are needed.
* Gain a baseline understanding of their cyber security maturity against a framework recognised by the NCSC.
* Track progress over time by repeating the stocktake and comparing results, as demonstrated by the Welsh experience.

The "Comprehensive Mapping of CAF Objectives and Principles to Stocktake Questions" provides a clear example of how this alignment can be achieved. It links specific stocktake questions to the relevant CAF objective and principle, offering insights into the rationale and importance of each question based on the sources. This mapping helps ensure that the self-assessment process is structured and directly relevant to the CAF requirements.

&#x20;

6.3 The Role of Key Lines of Enquiry (KLOEs)

Key Lines of Enquiry (KLOEs) can be a valuable tool within the CAF and stocktake process. Originating from audit practices, KLOEs represent key questions that help assess performance and identify areas for further investigation. In the context of the CAF, KLOEs can be developed to:

* Drill down into the contributing outcomes and IGPs associated with each CAF principle.
* Provide a more granular level of assessment than broad stocktake questions.
* Guide internal audits and reviews of specific cybersecurity controls and processes.
* Help in gathering evidence to support the self-assessment and any independent assurance reviews.
* Focus attention on specific aspects of cyber risk management that are deemed critical for the local authority.

For example, under CAF Objective A (Managing Security Risk) and Principle A1 (Governance), a stocktake question might be "How often are cybersecurity matters reported to the board?". A related KLOE could be: "What specific information is included in the cybersecurity reports presented to the board, and how is this information used to inform strategic decision-making?" \[implied].

The LACES framework also suggests the use of Key Lines of Enquiries (KLOEs) to be integrated with the CAF as part of an ongoing stocktake approach.

6.4 Developing Objectives and Key Results (OKRs) to Support Cyber Maturity

Objectives and Key Results (OKRs) are a goal-setting framework that helps organisations define ambitious goals (Objectives) and track their progress through measurable results (Key Results). When applied to cyber security, OKRs can provide a clear roadmap for improving cyber maturity in alignment with the CAF.

Here is a detailed example of developing OKRs to support cyber maturity, linked to CAF Objective A: Managing Security Risk:

Objective: Enhance the management of cyber security risks across the council to improve overall cyber resilience. (Aligned with CAF Objective A)

&#x20;

&#x20;

&#x20;

&#x20;

Objectives & Key Results:

* OKR1: Develop and approve a documented cybersecurity risk appetite statement by \[Date]. (Supports CAF Principle A1: Governance).
* *Rationale:* A documented risk appetite is fundamental for informed decision-making and resource allocation.
* *Measurement:* Completion and formal approval of the risk appetite document by the specified date.
* OKR2: Update the council's risk register to include cybersecurity risks, ensuring all critical systems are identified and risk-assessed by \[Date]. (Supports CAF Principle A2: Risk Management and CAF requirement to identify critical systems).
* *Rationale:* Maintaining a risk register incorporating cybersecurity is crucial for identifying, assessing, and managing potential threats. Identifying critical systems allows for targeted protection.
* *Measurement:* Completion of the updated risk register with identified critical systems and associated risk assessments.
* OKR3: Implement minimum cybersecurity standards for \[X]% of high-risk third-party vendors by \[Date], including evidence of enforcement for \[Y]% of these vendors. (Supports CAF Principle A4: Supply Chain).
* *Rationale:* Establishing and enforcing cybersecurity standards for third parties is crucial for managing supply chain risks.
* *Measurement:* Percentage of high-risk vendors with implemented minimum standards and percentage of those vendors with evidence of enforcement (e.g., audit logs, contractual clauses).
* OKR4: Achieve a "\[Target Percentage]" completion rate for the self-assessment of critical systems against CAF Objective A contributing outcomes by \[Date]. (Supports the CAF self-assessment process).
* *Rationale:* Conducting the self-assessment helps identify areas of strength and weakness against the CAF's requirements for managing security risks.
* *Measurement:* Percentage of critical systems that have completed the self-assessment for CAF Objective A.

Further Considerations for Developing Cyber Maturity OKRs:

* Alignment with CAF Objectives: Ensure your Objectives directly support one or more of the four CAF objectives.
* Specificity and Measurability: Key Results should be specific, measurable, achievable, relevant, and time-bound (SMART). Use quantifiable metrics where possible.
* Ambitious but Achievable: OKRs should stretch the organisation but remain within the realm of possibility given available resources. The draft CAF profile was noted as challenging but not disproportionate.
* Cross-Organisational Collaboration: Recognise that achieving cyber maturity requires effort across different teams. Involve relevant stakeholders in the OKR setting process.
* Regular Review and Adjustment: OKRs should be reviewed regularly (e.g., quarterly) to track progress and make adjustments as needed. Lessons learned from incidents and exercises should inform these adjustments.
* Link to Improvement Plans: OKRs should drive the creation and implementation of improvement plans to address identified vulnerabilities.

By strategically using the CAF, incorporating a stocktake approach, leveraging KLOE’s & OKR’s for deeper insights, and driving progress with well-defined OKRs, local government organisations can systematically enhance their cyber maturity and build greater resilience against the ever-evolving cyber threat landscape.

<br>

&#x20;

### Chapter 7: A Strategic Approach to Cyber Resilience using the LACES Framework

This chapter will explain how the **Local Authority Cyber Eco-System (LACES) framework** can be used as a **strategic approach to enhance cyber resilience**, effectively joining together the concepts discussed in the previous chapters, including the Cyber Assessment Framework (CAF), stocktake methodologies, Key Lines of Enquiry (KLOEs), and Objectives and Key Results (OKRs). It will conclude with a ten-step implementation guide for leveraging the LACES framework.

#### 7.1 The LACES Framework as a Strategic Integrator

The **LACES framework** is a **holistic model for cyber resilience** designed to enhance the understanding and implementation of cybersecurity measures within local government. It moves beyond traditional policy-driven approaches to a more adaptable, **principles-based approach**. The framework integrates **six interconnected variables**: **Governance**, **Assurance**, **Processes**, **Data management**, **Resilience**, and **Knowledge sharing**. Any one of these can be the central focus, with the others acting as satellites to ensure a comprehensive perspective.

The LACES framework provides a **structured approach** that can be used to understand complex situations, aid in learning and teaching, and provide a common language for both technical and non-technical practitioners. It is not intended to be a compliance or assurance framework itself, but rather an **educational tool** that supports the development of policies, processes, and procedures.

**Brining it all together:**

·       **Cyber Assessment Framework (CAF):** The LACES framework can be used as a **complementary tool** to the CAF. While the CAF details what good cyber resilience looks like through objectives and principles, LACES provides a **holistic lens** through which to understand and address these requirements. The variables of LACES (Governance, Assurance, etc.) align with many of the principles and contributing outcomes within the CAF objectives. For example, CAF Objective A (Managing Security Risk) aligns strongly with LACES Governance and Assurance variables.

·       **Stocktake Approach:** A stocktake, which assesses current cybersecurity practices, can be **structured around the LACES framework**. Questions within the stocktake can be mapped not only to the CAF but also to the specific variables of LACES, providing a broader understanding of strengths and weaknesses across governance, assurance, processes, data management, resilience, and knowledge sharing. This allows for a more nuanced analysis of cyber maturity.

·       **Key Lines of Enquiry (KLOEs):** KLOEs, used to drill down into specific areas, can be developed to explore each of the LACES variables in greater detail. For instance, under the LACES Governance variable, KLOEs could focus on the roles and responsibilities of the SIRO and CIGG. Similarly, under the Resilience variable, KLOEs could investigate the effectiveness of cyber incident response plans. LACES provides a **contextual structure** for formulating relevant KLOEs.

·       **Objectives and Key Results (OKRs):** When developing OKRs to enhance cyber maturity, the **LACES framework can inform the strategic Objectives**. For example, an Objective to "Strengthen our cyber governance" directly aligns with the LACES Governance variable. The Key Results to achieve this objective can then be linked to specific actions that address CAF principles or identified gaps from a LACES-aligned stocktake. The variable-centric approach of LACES allows for the prioritisation of specific areas when setting OKRs.

#### 7.2 A Ten-Step Implementation Guide using the LACES Framework

The following ten steps provide a strategic approach for local government organisations to implement and leverage the LACES framework to enhance their cyber resilience:

1\.        **Establish a Corporate Information Governance Group (CIGG) and Appoint a Senior Information Risk Owner (SIRO):** Ensure clear **governance** structures are in place with defined roles and responsibilities for information security oversight. The SIRO plays a central role in championing information resilience.

2\.        **Conduct a Baseline Assessment (Stocktake) Aligned with LACES and CAF:** Undertake a comprehensive assessment of the organisation's current cyber security posture. **Map stocktake questions to both the CAF objectives and the six variables of the LACES framework** to identify strengths and weaknesses across governance, assurance, processes, data management, resilience, and knowledge sharing.

3\.        **Define Key Lines of Enquiry (KLOEs) for Each LACES Variable:** Develop **granular KLOEs** to further investigate areas identified in the baseline assessment. These KLOEs should probe deeper into the contributing outcomes and indicators of good practice within the CAF, viewed through the lens of each LACES variable.

4\.        **Develop Objectives and Key Results (OKRs) Informed by LACES and Addressing CAF Requirements:**  Based on the findings of the stocktake and KLOE analysis, set **strategic Objectives** aligned with the LACES variables that need strengthening. Define **measurable Key Results** that will contribute to achieving these Objectives and address specific CAF principles and identified vulnerabilities.

5\.        **Embed "Secure by Design" Principles Across Processes:** Integrate **security and data protection consideration** into the design and development of all systems and services from the outset. This aligns with the LACES Processes and Assurance variables.

6\.        **Develop and Regularly Exercise Cyber Incident Response Plans:** Strengthen the **Resilience** variable by creating comprehensive cyber incident response plans and conducting regular exercises to test their effectiveness. This should include consideration of fast-time communication strategies.

7\.        **Implement a Comprehensive Training and Awareness Programme:** Enhance the **Knowledge Sharing** variable by providing regular training to all staff (including suppliers) on data protection, information security, and secure data handling practices. Foster a **culture of reporting** incidents and near misses.

8\.        **Conduct Regular Risk Assessments and Data Protection Impact Assessments (DPIAs):** Strengthen the **Assurance** variable through regular risk assessments, including DPIAs for processing likely to result in high risk to individuals.

9\.        **Review and Update Data Sharing Agreements:** Ensure all data sharing agreements comply with relevant guidance and include agreed terms for data sharing, security, and disposal. This aligns with the **Data management**and **Governance** variables.

10\.  **Foster Knowledge Sharing and Continuous Improvement:** Actively participate in **knowledge sharing networks** such as WARPs and CTAG. Use lessons learned from incidents, exercises, and peer engagement to continuously improve the organisation's cyber resilience posture across all six LACES variables. The SIRO should champion this culture of continuous improvement and learning.

By adopting this strategic approach using the LACES framework, local government organisations can move towards a more **holistic and resilient cybersecurity posture**, effectively integrating various tools and frameworks to protect their essential services and data.<br>

### Chapter 8: Statecraft and Resilience in the Context of Civil Society

This chapter will explore the intricate relationship between **statecraft** and **cyber resilience** within the broader context of **civil society**, particularly as it pertains to local government. Building upon the strategic application of the **LACES framework** outlined in the previous chapter, we will examine how the actions of the state, particularly at the local level, can foster a more cyber-resilient civil society and how cyber incidents can impact this crucial sphere.

#### 8.1 Understanding Civic Cyber Resilience

**Civic cyber resilience** refers to **the ability of individuals, communities, and organisations within a society to withstand and recover from cyberattacks**. It necessitates a **whole-of-society approach**, involving collaboration between governments, businesses, and citizens. This concept recognises that cyber resilience is not solely the responsibility of technical teams within organisations but requires a broader understanding and engagement across all sectors of society.

The **Local Authority Cyber Eco-System (LACES) framework**, while primarily focused on local government organisations, has a significant role to play in understanding and enhancing civic cyber resilience. The framework's emphasis on **Knowledge sharing** highlights the importance of disseminating information about cyber threats and best practices to the wider community. Furthermore, the **Resilience** variable extends beyond organisational recovery to consider the impact on the services delivered to citizens.

#### 8.2 The Role of Statecraft in Fostering Civic Cyber Resilience

**Statecraft in the digital age** involves nations utilising cyber capabilities to achieve their political objectives and ensuring the security and well-being of their citizens in the digital realm. For local government, as a key component of the state, this translates into a responsibility to foster cyber resilience within their communities.

·       **Protecting Essential Services:** Local authorities deliver critical services to citizens. Ensuring the **cyber resilience**of these services is paramount to maintaining societal order and welfare. Disruptions caused by cyberattacks can have a huge financial cost and threaten the delivery of these vital services to citizens. The **Cyber Assessment Framework (CAF) for local government** can help councils identify cyber risks that could disrupt their most important services and improve their resilience to potential cyber attacks.

·       **Building Public Trust and Confidence:** If Local Public Services are to deliver efficient and often shared services, they need to **build public confidence** and ensure that the public trust that their privacy is protected and their personal data is handled professionally. Cyber incidents can erode this trust. By adopting strong information governance practices and demonstrating a commitment to cyber security, local authorities contribute to a more resilient and trusting relationship with their citizens. Publishing an **information charter** setting out how information is handled can further enhance transparency and public confidence.

·       **Promoting Public Awareness and Education:** A key element of civic cyber resilience is **educating citizens about cyber threats and best practices for online safety**. Local authorities can play a role in raising public awareness through campaigns and by providing accessible information on cyber security. The "Think Cyber Think Resilience" work implemented by MHCLG aimed to help organisations prepare for cyber attacks, and a good starting point is the strategy report produced as part of the programme.

·       **Facilitating Information Sharing and Collaboration:** **Encouraging collaboration between government agencies, businesses, and individuals to share information about cyber threats and vulnerabilities** is crucial for a whole-of-society approach. Local Resilience Forums (LRFs) are increasingly focusing on planning for cyber incidents, and local authority security officers are strengthening their ties with LRFs. Initiatives like WARPs (Warning, Advice and Reporting Points) facilitate the dissemination of knowledge and co-learning, improving resilience from a cybersecurity viewpoint.

·       **Developing Incident Response Capabilities:** **Developing and testing plans for responding to cyber incidents, including coordinating efforts between different stakeholders**, is essential. Local authorities need to have **Cyber Incident Response Plans** and regularly exercise them. The **LACES framework's** emphasis on **Processes** supports the development of effective incident response mechanisms.

#### 8.3 Impact of Cyber Incidents on Civil Society

Cyberattacks are no longer just isolated incidents; they are now tools of geopolitical influence with the potential to disrupt economies, undermine national security, and sow discord among nations. At the local level, cyber incidents can directly impact civil society in several ways:

·       **Disruption of Essential Services:** As highlighted earlier, attacks on local government systems can disrupt vital services relied upon by citizens, such as social care, waste management, and council tax processing. The inability to access these services can have significant consequences for individuals and communities.

·       **Erosion of Trust:** Data breaches and cyberattacks can lead to the compromise of citizens' personal information, eroding trust in public institutions and their ability to protect sensitive data. Maintaining trust with citizens is paramount.

·       **Impact on Democratic Engagement:** Cyberattacks can target activities that support or promote democratic engagement. Securing local democracy through the protection of local and national elections is a priority area.

·       **Financial Costs:** Cyber attacks can have a huge financial cost for local authorities, which ultimately impacts the resources available for public services. Local Public Services will still face the full financial penalties for any breaches.

#### 8.4 Leveraging the LACES Framework for Civic Cyber Resilience

The **LACES framework** can be a valuable tool for local authorities in their efforts to enhance civic cyber resilience:

·       **Governance:** Establishing clear governance structures that include consideration of the wider community impact of cyber security decisions. This involves the SIRO championing cyber resilience not just within the council but also in its interactions with citizens.

·       **Assurance:** Conducting risk assessments that consider the potential impact of cyber threats on the community and ensuring that security measures are proportionate to the information risk.

·       **Processes:** Developing and implementing incident response plans that include communication strategies for informing and supporting affected citizens during a cyber incident.

·       **Data Management:** Implementing robust data protection measures to safeguard citizens' personal information and maintain their trust.

·       **Resilience:** Focusing on the ability to maintain operation of essential services in the face of cyber attacks, ensuring that business continuity plans consider the needs of the community.

·       **Knowledge Sharing:** Actively engaging with the public to raise awareness about cyber threats and providing guidance on how individuals can protect themselves online.

#### 8.5 Conclusion

Fostering **cyber resilience** within **civil society** is a crucial aspect of modern **statecraft**, particularly for local government. By prioritising the security of essential services, building public trust, promoting awareness, facilitating collaboration, and developing robust incident response capabilities, local authorities can contribute to a more resilient society. The **LACES framework** provides a holistic lens through which to understand and address these multifaceted challenges, ensuring that cyber security efforts extend beyond the boundaries of the council to protect the communities they serve. The increasing convergence of the physical and digital realms necessitates a proactive and adaptive approach to cyber resilience that embraces a whole-of-society perspective.

<br>

&#x20;

### Chapter 9: Local Authority Devolution: Guidance for Enhanced Information Governance, Resilience, and Integration

This chapter provides detailed guidance on **Local Authority devolution** in England, building upon the principles of **Information Governance**, **resilience**, and **integration** discussed in previous chapters, particularly Chapter 8 on statecraft and resilience in civil society. It aims to equip Local Authorities with a strategic understanding and actionable steps to navigate the evolving devolved landscape while ensuring the secure and effective management of information and the resilience of essential services.

#### 9.1 Understanding Local Authority Devolution in England

The UK Government is actively pursuing a policy of **widening and deepening devolution** across England. This involves granting local leaders and communities greater powers and funding to drive growth and raise living standards. The **English Devolution White Paper**, "Power and Partnership: Foundations for Growth," outlines the government’s plans to empower local leaders, particularly through **mayoral-led strategic authorities**, and to reform local government structures.

Key aspects of this devolution agenda include:

* **Creation of Strategic Authorities:** The government is legislating to create a concept of "**Strategic Authorities**" with increasing levels of duties and powers. These include "**Foundation Strategic Authorities**" (non-mayoral combined authorities and combined county authorities) and "**Mayoral Strategic Authorities**," with "**Established Mayoral Strategic Authorities**" at the highest tier based on specific criteria.
* **Increased Powers for Mayors:** The devolution proposals significantly enhance the powers and functions of **metro mayors**, granting them greater control over areas such as strategic planning, housing, transport, skills, and potentially health and net zero. Mayors may also be able to appoint remunerated "**Commissioners**" to support the delivery of key functions.
* **Devolution Framework:** The government intends to enshrine a new "**Devolution Framework**" in statute, making it easier to grant new powers and simplifying devolution processes. There is a preference for all strategic authorities to be led by mayors.
* **Funding Reforms:** The funding of combined authorities is being reformed, with "**Integrated Settlements**" granted to the most established Mayoral Strategic Authorities, providing greater flexibility in allocating resources. The government also aims to reduce competitive bidding and rationalise funding pots.
* **Local Government Reorganisation:** A programme of local government reorganisation is underway to replace two-tier county and district councils with single-tier "**unitary**" authorities. This aims to simplify the local government landscape and improve public service performance.
* **Focus on Growth and Public Service Reform:** The devolution agenda is presented as a means to unlock regional growth, deliver on the government’s Plan for Change, and improve public services through better integration at a local level.

This significant shift towards devolution presents both opportunities and challenges for Local Authorities, particularly in relation to **Information Governance**, **resilience**, and the **integration** of services and systems across potentially larger and more complex strategic authorities.

#### 9.2 Implications of Devolution for Information Governance

The evolving devolution landscape has significant implications for how Local Authorities manage and protect information:

* **Expanded Data Sharing:** The drive for integrated services and strategic planning across larger areas governed by Strategic Authorities will necessitate **increased data sharing** between constituent councils and potentially with new mayoral bodies. This must be undertaken in accordance with **data protection legislation**, including the Data Protection Act 2018 and the UK GDPR. Authorities should **review and update all Data Sharing Agreements** to ensure compliance with the Information Commissioner’s data sharing code of practice, including agreed terms for data sharing, security, and disposal. As a data sharing practitioner, clarity about legal powers, consistency in information about these powers, and a focus on using existing legal gateways are crucial.
* **Accountability and Governance:** The creation of new Strategic Authorities, especially those led by mayors, requires clear **accountability frameworks** and robust **governance structures** for information. The ICO’s DPA/THE DATA PROTECTION ACT guidance on accountability should be followed, stressing the controller’s responsibility to implement appropriate technical and organisational measures to ensure and demonstrate compliance. Establishing or reviewing the **Corporate Information Governance Group (CIGG)** with clear terms of reference and ensuring the active role of the **Senior Information Risk Owner (SIRO)** are essential.
* **Data Protection by Design and Default:** As new devolved structures and integrated services are designed, the principle of "**secure by design**" should be embedded from the outset. Security and data protection considerations must be integrated into the design and development of all systems and services that handle personal data.
* **Transparency and Public Trust:** In a devolved system with potentially new layers of governance, maintaining **transparency** with the public about how their data is handled is paramount for building and sustaining **public trust**. Publishing an **information charter** outlining data handling practices and how concerns can be addressed remains a key recommendation.
* **Record of Processing Activities (ROPA):** Local Authorities within devolved structures must maintain a **comprehensive and up-to-date Register of Processing Activities (ROPA)**, detailing all processing activities of personal data, including those related to shared services and strategic authority functions.

#### 9.3 Enhancing Resilience in the Context of Devolution

Devolution necessitates a coordinated approach to **cyber resilience** across potentially larger and interconnected strategic authority areas:

* **Cyber Assessment Framework (CAF) and LG-CAF:** Local Public Services should utilise frameworks like the **Cyber Assessment Framework (CAF)** and the developing **Local Government CAF (LG-CAF)** to identify and address cyber risks in a proportionate way. Implementing data handling practices recommended in guidance will better position authorities to meet the requirements of these frameworks.
* **Cyber Incident Response Planning:** Each Local Authority within a devolved structure must have a robust and regularly exercised **Cyber Incident Response Plan**. These plans should consider the interconnected nature of services within a strategic authority and outline clear protocols for communication and coordination during a cyber incident. The ability to respond to cyber incidents remotely and testing this capability are increasingly crucial.
* **Risk Management:** Councils need to maintain a **risk register that includes cybersecurity** and articulate a documented **cybersecurity risk appetite** at the board level. This is crucial for informed decision-making and resource allocation in the context of devolved responsibilities. The SIRO plays a key role in owning and reviewing the information risk appetite.
* **Security Standards for Third Parties:** As Strategic Authorities and constituent councils may increasingly rely on shared services and third-party vendors, establishing and enforcing **minimum cybersecurity standards for third parties** is vital for managing supply chain risks. This includes conducting risk assessments of vendors, ensuring stringent security requirements in contracts, and auditing suppliers for compliance.
* **Network Security and Segmentation:** Implementing practices like **network segmentation** and segregating internet services from internal systems remain essential for limiting the impact of potential cyberattacks across the devolved landscape.
* **Staff Training and Awareness:** Comprehensive **cybersecurity training and awareness programs** for all staff and councillors are crucial for building a security-conscious culture across all levels of the devolved structure. This includes training on data protection and secure data handling practices, with records of all training maintained. Conducting phishing tests for staff and councillors can help assess and improve awareness.
* **Information Sharing through WARPs:** Active participation in regional **Warning, Advice and Reporting Points (WARPs)** facilitates the sharing of threat intelligence and best practices across Local Authorities, enhancing collective resilience within devolved areas.

#### 9.4 Fostering Integration within Devolved Structures

Effective **integration** of information governance and resilience practices is crucial for the success of devolution:

* **Collaborative Governance:** Strategic Authorities should establish clear mechanisms for **collaborative governance** of information, involving representatives from all constituent councils. This ensures a consistent and coordinated approach to data protection and cybersecurity across the devolved area.
* **Shared Policies and Procedures:** Where appropriate and feasible, Strategic Authorities should aim to develop **shared information governance policies and procedures**, such as data sharing protocols, security standards, and incident response frameworks, to ensure consistency and interoperability.
* **Integrated Risk Management:** A coordinated approach to **risk management**, including cybersecurity risks, should be adopted at the Strategic Authority level. This involves sharing risk registers, conducting joint risk assessments, and developing overarching risk mitigation strategies.
* **Joint Training and Awareness Initiatives:** Strategic Authorities can leverage their scale to deliver **joint cybersecurity training and awareness initiatives** for staff and councillors across the devolved area, promoting a unified security culture.
* **Shared Security Monitoring and Incident Response Capabilities:** Exploring the potential for **shared security monitoring tools and incident response capabilities** across a Strategic Authority could enhance efficiency and effectiveness in detecting and responding to cyber threats. Initiatives like a Security Operations Centre (SOC) style tooling, and aggregating and analysing system logs can be beneficial.
* **Alignment with National Frameworks:** Devolved structures must ensure their information governance and resilience practices align with national frameworks such as the **Cyber Assessment Framework (CAF)** and guidance from the **Information Commissioner’s Office (ICO)** and the **National Cyber Security Centre (NCSC)**.

#### 9.5 Call to Action

The move towards greater Local Authority devolution in England presents a significant opportunity to empower local communities and drive growth. However, to realise the full benefits of devolution while safeguarding public trust and ensuring the continuity of essential services, Local Authorities must **prioritise and strengthen their Information Governance and cyber resilience capabilities within these new devolved structures.**

**We urge all Local Authorities to proactively engage with the devolution agenda and to take immediate steps to integrate robust information governance and resilience practices into their strategic planning and operational delivery.** Failure to do so could expose devolved areas to increased data security risks, potential service disruptions, and a loss of public confidence.

#### 9.6 Strategic Plan and Action Points

To effectively navigate the devolved landscape and enhance Information Governance, resilience, and integration, Local Authorities should adopt the following strategic plan with actionable points:

**Strategic Goal 1: Establish Robust Information Governance Frameworks within Devolved Structures**

* **Action 1.1:** Within six months of the establishment of a new Strategic Authority or significant expansion of mayoral powers, convene a cross-authority **Information Governance Steering Group** to oversee the development and implementation of coordinated information governance strategies.
* **Action 1.2:** Conduct a comprehensive review of existing **Data Sharing Agreements** between constituent councils and identify any new data sharing requirements arising from devolved functions. Update agreements to ensure legal compliance and robust security measures within twelve months.
* **Action 1.3:** Develop a **Strategic Authority-level information charter** outlining how data is handled across the devolved area and how citizens can raise concerns, to be published within nine months.
* **Action 1.4:** Ensure the **Senior Information Risk Owner (SIRO)** roles within constituent authorities have clear lines of communication and collaboration with any relevant roles established at the Strategic Authority level. Define responsibilities for information risk management across the devolved structure within three months.
* **Action 1.5:** Maintain a comprehensive and accessible **Register of Processing Activities (ROPA)** that accurately reflects data processing activities within the context of devolved functions and shared services, reviewed and updated at least annually.

**Strategic Goal 2: Enhance Cyber Resilience Across Devolved Areas**

* **Action 2.1:** Within three months, conduct a joint **cyber risk assessment** across the Strategic Authority area, utilising the **Cyber Assessment Framework (CAF)** or equivalent, to identify shared vulnerabilities and interdependencies.
* **Action 2.2:** Develop and implement a **coordinated Cyber Incident Response Plan** that outlines protocols for communication, collaboration, and recovery across the Strategic Authority in the event of a significant cyber incident, to be tested annually through joint exercises.
* **Action 2.3:** Establish **minimum cybersecurity standards for all third-party vendors** providing services to the Strategic Authority and constituent councils, ensuring these are incorporated into contracts and regularly audited for compliance within twelve months.
* **Action 2.4:** Implement and maintain **network segmentation** and other appropriate security controls to limit the potential impact of cyber incidents across the devolved infrastructure.
* **Action 2.5:** Deliver **joint cybersecurity training and awareness programs** for staff and councillors across the Strategic Authority area at least annually, tailored to the specific risks and responsibilities within the devolved context. Increase the frequency of phishing tests.
* **Action 2.6:** Actively participate in regional **WARP (Warning, Advice and Reporting Point)** initiatives and establish clear channels for sharing threat intelligence across the Strategic Authority.

**Strategic Goal 3: Foster Integration of Information Governance and Resilience Practices**

* **Action 3.1:** Establish a **joint working group** comprising information governance and cybersecurity professionals from across the Strategic Authority to promote collaboration and the integration of their respective strategies and plans within three months.
* **Action 3.2:** Identify opportunities for **shared security monitoring tools and incident response capabilities** at the Strategic Authority level, conducting a feasibility study within twelve months.
* **Action 3.3:** Develop **joint policies and procedures** for key areas such as data breach notification, acceptable use of technology, and secure remote working that are applicable across the Strategic Authority, where appropriate.
* **Action 3.4:** Conduct **regular reviews and audits** of information governance and resilience practices across the devolved area to ensure consistency, effectiveness, and alignment with national guidance and legislation.
* **Action 3.5:** Share **lessons learned** from any security incidents or data breaches across the Strategic Authority to promote continuous improvement and collective resilience.

By implementing this strategic plan and prioritising these actionable points, Local Authorities in England can effectively navigate the opportunities and challenges of devolution, ensuring the secure and responsible management of information and the resilience of vital public services for the benefit of their communities.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://guidance.ctag.org.uk/data-handling-guidelines-version-6.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
