Report for January 2020

Report Date
January 2020
Key Achievements in the Last Period

Successfully achieved ISO27001 certification. Huge achievement from the project team.

Project Manager starts 17th February. Substantial re-planning based on estimations and prioritisation required to map out project for 2020.

 

Next Phase Tasks.

 
Implement Data at Rest Encryption.

We committed to doing this by end of first Qtr 2020 in the ISO27001 audit and it’s a requirement for NHS Lothian to give us Data. I'd say this looks very unlikely without Project management.

 
Implement ISO Audit Recommendations

We were given a list of recommendations from trhe ISO audit that will need done. Again, these will need managed as will the Risk Treatment plan and Improvement log. These shoul dbe managed by the Security Working Group which will probably stop.

 
Patching and Maintenance. Agree policy and strategy.

This is critical if we want to get data from NHS Lothian. The policy and processes we put in place for ISO27001 arent achievable with the current reource levels. We need to arrange for third part vendors to come in an assist with some of the components. This needs Management. Without changing  the Policy there is no way we can currently get data off NHS Lothian. I believe NHS Digital are also heading in this direction (as per CJD audit documentation). This is currently a massive black whole that needs agreement and management now that were past the ISO Audits.

 
TSL 1.1 to 1.2 Upgrade

Again this is a key requirement for NHS Lothian and and an ISO27001 commitment that we will be audited on. We currently have no plan to put this in place although Stehen has begun the investigation process.

 
Further SEIM / Splunk Delivery.

The initial Splunk delivery was build around achieving ISO27001 Centification which was targeted at Security Monotoring and Alerting, specifically GPG13. We have little or no Alerting in place for actual platform monitoring and alerting, your basic standard stuff. This is actually where we would gain the most benefit from Splunk and was always seen as the next phase.

 
Annual Penetration Test.

We committed to an annual Penetration Test as part of our ISO Scope. As this ws our first year, its wasnt raised as an Incnformity that we hadnt done one for over a year. It still needs done though and urgently.

 
Internal ISO27001 Audit (1)  Feb.

This will need to be agreed and planned as it was unclear who would be carrying these out going forward. Alisair Fenemore took an action to clarify if UoE Internal audit should have a role to play in this. There is an agenda and meeting planned. Internal audit involvement needs to be clarified beforehand.

 
Internal ISO27001 Audit (2)  Aug.

As above.

 

Internal management Review

Not planned but should be ASAP as this is our only Inconformity. we should really get right on top of this one.

 

Issues & Risks

Ref Title Current Risk Management Approach Risk Owner Date of Last Review  
1 Patching requirement to the Defined Standard is not achievable with current resource levels. RED Reduce David Fergusson 27-Nov-2019

view

2 Getting Data from NHS Lothian. RED Reduce David Fergusson 27-Nov-2019

view

3 Removal Of Project management Resource. RED Reduce David Fergusson  

view

 

 

 

Milestones

Stage Milestone Due Date Previous Date Complete  
Deliver Implement Encryption of Data At Rest. No date available No date available No

view

Deliver Implement ISO Audit Recommendations No date available No date available No

view

Design Patching. Agree policy and strategy. No date available No date available No

view

Integrate TLS 1.1 to 1.2 Upgrade No date available No date available No

view

Build Further SEIM (Splunk) Development No date available No date available No

view

Deliver Annual Penetration Test. No date available No date available No

view

Deliver Internal ISO27001 Audit. No date available No date available No

view

Deliver Internal Management Review No date available No date available No

view

Close Close Project 31-Jul-2020 No date available No

view

 

Project Status
RAG Status
Time
AMBER
Cost
AMBER
Scope
AMBER
Overall
AMBER
RAG Commentary
Project Manager starts 17th February. Substantial re-planning based on estimations and prioritisation required to map out project for 2020.
Change Status
Time
No Change
Cost
No Change
Scope
No Change
Overall
No Change
Has formal escalation taken place?
No
Change Commentary
planning for rest of project to maintain the DSH and address NHS requirements to be put in place
Activity
Approved budget
0.0 days
Activity this month
0.0 days
Activity this year
0.0 days
Activity to date
0.0 days
Estimate to complete current year
0.0 days
Estimate to complete future years
0.0 days

Project Info

Not available.

Documentation

Not available.