Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Proposal for Change: Guidance for using Open Internet Tools #9

Open
simplybenuk opened this issue Jul 1, 2021 · 2 comments
Open

Proposal for Change: Guidance for using Open Internet Tools #9

simplybenuk opened this issue Jul 1, 2021 · 2 comments
Labels
2) Response Stage Review by ARB & given to SME's if needed for further development of the proposal

Comments

@simplybenuk
Copy link
Contributor

Name of and link to existing standard this proposal relates to

Guidance for using Open Internet Tools

Purpose and description of proposed change

Think it needs to list all the approved OITs.
The checklist doesn't refer at all to cyber security, but then there's that last section that seems to suggest you need cyber approval to use one.

Existing related standards?

References to related external standards

MOJs approved list https://ministryofjustice.github.io/security-guidance/general-user-video-and-messaging-apps-guidance/#approved-tools

@simplybenuk simplybenuk added the 1) Suggestion Stage Phase 1 - suggested new or amended standard label Jul 1, 2021
@simplybenuk
Copy link
Contributor Author

Just found the link to the existing approved apps, so ignore that part of my comment. I think this need to be linked in the checklist

@TotallyInformation
Copy link
Member

Hi Ben,

The two documents https://nhsengland.github.io/it-standards/#/security/acceptable-cloud-tools and https://nhsengland.github.io/it-standards/#/security/guidance-for-using-open-internet-tools are designed to work together. The first of those now has a list of Corporate Tools which are largely centrally funded and supported, followed by a list of "approved tools" which are things that other, generally non-IT parts of the business have chosen to use - these are not being blocked by IT but probably have no support from us either. Then there is a short list of tools that must not be used.

Is this now sufficient to meet this issue or is more needed?

@TotallyInformation TotallyInformation added 2) Response Stage Review by ARB & given to SME's if needed for further development of the proposal and removed 1) Suggestion Stage Phase 1 - suggested new or amended standard labels Jul 13, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
2) Response Stage Review by ARB & given to SME's if needed for further development of the proposal
Projects
None yet
Development

No branches or pull requests

2 participants