This policy is fully drafted and structured, ready to brand and complete for your service. It covers:
1. Purpose
2. Scope
3. Policy statement and principles
4. Definitions
5. Information classification and handling
6. Access control and user account management
7. Passwords and multi-factor authentication
8. Encryption
9. Device and endpoint security
10. Network security
11. Cloud services and supplier assurance
12. Physical and environmental security
13. Backup, business continuity and availability
14. Information security incident management
15. Roles and responsibilities
16. Training and awareness
17. Monitoring, audit and review
18. Related documents
19. Glossary
20. References
Legislation & standards it maps to
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
UK General Data Protection Regulation (UK GDPR)
Data Protection Act 2018
Computer Misuse Act 1990
Privacy and Electronic Communications Regulations 2003 (PECR)
Network and Information Systems Regulations 2018 (NIS Regulations 2018)
Care Quality Commission (Registration) Regulations 2009
Human Rights Act 1998
Who it applies to
All directors, employees, bank and agency staff, contractors, clinicians, volunteers and third-party suppliers who access, process or store information on behalf of [Organisation Name]
How it works
Buy securely with Stripe - instant, no VAT, no account needed.
Download your editable Word file from the link we email you straight away.
Complete the placeholders for your service, then have it approved before use.
Add the optional updates subscription and we keep it current as guidance changes.