Cyber Security & Information Assurance Standards Policy

Purpose

This policy outlines Mirata Ltd's strategic decision to exclusively utilize the NHS Digital - Data Security and Protection Toolkit (DSPT) for information security assurance, explaining our rationale and the benefits this approach provides to our clients.

The NHS Digital - Data Security and Protection Toolkit is an online self-assessment tool that allows organisations to measure their performance against the National Data Guardian’s 10 data security standards. All organisations that have access to NHS patient data and systems must use this toolkit yearly to provide assurance that they are practising good data security and that personal information is handled correctly.
 
  • MIRATA LTD Organisation code: 8K993

Policy Statement

Mirata Ltd has made the deliberate choice to focus solely on the Data Security and Protection Toolkit (DSPT) as our framework for information security assurance. We have chosen not to pursue other certifications for the following reasons:

1. Healthcare Specificity: The DSPT is tailored explicitly for organizations handling NHS patient data, ensuring our security measures are optimized for the healthcare sector's unique challenges.

2. Mandatory Requirement: As a mandatory tool for all organizations accessing NHS patient data, the DSPT ensures we meet and exceed the baseline standards required by our primary operational context.

3. Comprehensive Coverage: The DSPT provides a holistic approach to data security, information governance, and cyber security, negating the need for multiple, potentially overlapping certifications.

4. Regulatory Alignment: By adhering to DSPT standards, we simultaneously ensure compliance with key regulations such as GDPR and the Data Protection Act 2018 as they apply to healthcare data.

5. Continuous Improvement: Annual updates to the DSPT keep our security practices current with evolving threats and best practices specific to the healthcare sector.

6. Resource Optimization: By focusing our efforts on a single, comprehensive framework, we can dedicate more resources to exceeding standards rather than managing multiple certification processes.

7. Clear Benchmarking: The DSPT provides a clear, healthcare-specific benchmark for our clients to assess our security capabilities.

Alternative Certifications

While valuable in their own contexts, Mirata Ltd has chosen not to pursue the following certifications in favour of our exclusive focus on the DSPT:

- Cyber Essentials and Cyber Essentials Plus
- ISO 27001 (Information Security Management)
- IASME Governance Standard
- PCI DSS (Payment Card Industry Data Security Standard)
- NCSC Certified Cyber Professional (CCP) scheme
- CREST accreditations
- CISSP (Certified Information Systems Security Professional)
- SOC 2 (Service Organization Control 2)
- ICO's "Accountability Framework"

We believe that for our specific focus on education, financial services, and healthcare data, the DSPT provides the most relevant and comprehensive framework without the need for these additional certifications.

Client Benefits

Our exclusive use of the DSPT benefits our clients in the following ways:

  1. Specialized Expertise: Clients gain a partner with deep, focused expertise in sector-specific data protection practices.
  2. Streamlined Compliance: Our DSPT compliance simplifies our clients' supply chain security assessments.
  3. Cost-Effectiveness: The efficiency of our focused approach allows us to provide high-quality services at competitive prices.
  4. Continuous Adaptation: Clients benefit from our agility in adapting to the latest data security requirements and best practices.
  5. Alignment with NHS Standards: Our exclusive use of DSPT ensures perfect alignment with NHS data security expectations.
  6. Simplified Due Diligence: Clients can easily verify our security posture through our DSPT compliance status.

Mirata Ltd is committed to maintaining the highest standards of data protection through our dedicated focus on the DSPT. We believe this approach provides the most relevant, efficient, and effective security assurance for our clients in our sector.

Appendix A

Requests for Additional Accreditations:

While Mirata Ltd maintains that the Data Security and Protection Toolkit (DSPT) provides comprehensive coverage for our operations in the healthcare sector, we recognize that some clients may have specific requirements necessitating additional accreditations. In such cases, the following policy applies:

1. Client-Requested Accreditations: If a client determines that an additional standard or accreditation is absolutely necessary for their specific needs, Mirata Ltd will consider undertaking the requested accreditation.

2. Assessment Process: Upon receiving a request for an additional accreditation, Mirata Ltd will conduct an internal assessment to determine the feasibility and impact of pursuing the requested standard.

3. Additional Charges: Should Mirata Ltd agree to pursue an additional accreditation at a client's request, a charge will be necessary to cover the costs associated with the accreditation process. This charge will vary depending on the specific standard required and may include:

  • Application and registration fees
  • Audit and assessment costs
  • Staff training and preparation time
  • Ongoing maintenance and compliance costs

4. Customized Quotation: The exact charge for an additional accreditation will be determined on a case-by-case basis. Mirata Ltd will provide a detailed quotation outlining all associated costs before proceeding with any additional accreditation process.

5. Time frame: Clients should be aware that pursuing additional accreditations may require significant time to complete. The expected time frame will be communicated along with the quotation.

6. Ongoing Commitment: If an additional accreditation is obtained at a client's request, Mirata Ltd will maintain that accreditation for the duration of our contract with the requesting client, subject to any additional ongoing charges.

7. Limited Applicability: Any additional accreditations obtained will be specific to the requesting client's contract and will not automatically apply to services provided to other clients.

Mirata Ltd remains committed to our core focus on the DSPT as the most relevant standard for our operations in our sector. We encourage clients to discuss their specific needs with us to determine whether the DSPT adequately meets their requirements before requesting additional accreditations.

  • 147 Users Found This Useful
Was this answer helpful?

Related Articles

Anti-Spam Policy

Mirata is committed to permission-based email marketing practices, and as a result has...

Accessibility Policy

Mirata recognises the importance of making all its digital services available to the largest...

Service Level Policy

We know that the up-time level for all our services is crucial to you, and at Mirata, it's our...

Privacy Policy

Mirata is committed to your privacy. We will use the information you provide for the purpose of...

Disaster Policy

IT equipment needs to be supported by services which allow Mirata client systems to continue...