This is an HTML version of an attachment to the Freedom of Information request 'Council Use of IT Software'.

Annex

31 Law enforcement

(1) Information which is not exempt information by virtue of section 30 is exempt information if its disclosure under this Act would, or would be likely to, prejudice—

(a) the prevention or detection of crime,

43 Commercial interests

(1) Information is exempt information if it constitutes a trade secret.

(2) Information is exempt information if its disclosure under this Act would, or would be likely to, prejudice the commercial interests of any person (including the public authority holding it).

(3) The duty to confirm or deny does not arise if, or to the extent that, compliance with section 1(1)(a) would, or would be likely to, prejudice the interests mentioned in subsection (2).

Factors for withholding

Factors for disclosure

  • Necessity of ensuring security of ICT systems and personal data included on these.

  • Adverse and prejudicial impact on the Council's business and its staff and residents if systems are hacked or phished.

  • In addition such damage to systems would lead to severe commercial prejudice of the Council's operations and additional costs for residents.

  • Accountability for public finances

Reasons why public interest favours withholding information

  • It has been established by the Council that ICT systems can be vulnerable to hacking or phishing if sufficient information about the systems is known.

  • Such attacks on ICT generally have a serious adverse effect on clients and residents, and can lead to theft of personal data, with resultant prejudicial impacts on services and individuals.

  • They also have commercial implications, in costs to the Council (and residents) to rectify losses or damage to data.

  • The Information Commissioner has advised all authorities to take security of electronic data seriously and to put in place appropriate safeguards to protect clients and operations.

  • In response to this, security polices and procedures have been set up to establish what data should be protected or restricted and to withhold this from the public domain.

  • It is judged that the requested data falls within this definition and consequently a decision has been taken that it will not be released.

  • While the Council is accountable for its public finances, it is judged that the information requested has no public interest value (it will not increase information on accountability or processes).

  • The information requested is therefore refused.

Type of information

Applicable Exemption

ICT software systems in use and the service using these.

S31 (1) (a) S43 (2)

2