Date: Mon, 20 Sep 2010 12:53:49 +0100 Subject: City of Bradford MDC: FoI Request 1008039 From: Peter Silcock To: xxxxxxxxxxxxxxxxxxxxxx@xxxxxxxxxxxxxx.xxx Cc: Freedom of Information Dear Mr Schneider, Thank you for your request under the terms of the Freedom of Information Act. I have inserted the answers to your questions into the original text below. Provide, name, address and telephone number for the following people: * Senior Information Risk Owner Becky Hellard Strategic Director (Corporate Services) 1st Floor, Britannia House Bradford BD1 1HX. 01274 432800 * Governance Manager * Information Security Officer/Manager * Information Technology Security Officer/Manager The three roles above are performed by: Peter Silcock Corporate Information Security Officer 1st Floor, Britannia House Bradford BD1 1HX. 01274 435991 * Caldecott Guardian Paul Taylor Olicana House Chapel Street Bradford BD1 5RE 01274 432479 PCI-DSS Does your organisation process electronic payment cards? - Yes How much money is processed from electronic payment cards per annum? - £1,179,000 (in 2009-10) How many electronic payment card transactions are processed per annum? - 131,225 (in 2009-10) Are you PCI-DSS compliant? - Yes ISO 27001 Are you or have you considered becoming ISO 27001 compliant or certified? - Have considered - superseded by GovConnect Government Connect Are you connected and operationally utilising the Government Connect network? - Yes If not have you considered connecting to Government Connect and why was the decision made not to connect? - n/a Do you meet the Government Connect version three requirements? - Yes Please supply your latest CLAS consultant annual Government Connect assessment/audit report, blanking out any statements which could contravene a security concern from a third party reading it. - Not available for security reasons Do you meet the Government Connect version four requirements? - Unknown (assessment in progress) Please supply the latest internal report for the Government Connect version four Audit/Assessment, blanking out any statements which could contravene a security concern from a third party reading it. - Not available for security reasons. Criminal Justice Network Are you connected to and operationally utilising the Criminal Justice Network? If not have you considered connecting to the Criminal Justice Network and why was the decision made not to connect? - Yes , connected. Please supply your latest annual assessment/audit report, blanking out any statements which could contravene a security concern from a third party reading it. - Not available. NHS N3 Network Are you connected to and operationally utilising the NHS N3 Network? If not have you considered connecting to the NHS N3 network and why was the decision made not to connect? - We will conect to N3 via GCSx later this year. Please supply your latest N3 Connection assessment/audit report, blanking out any statements which could contravene a security concern from a third party reading it. - Not available. Do both schools and the Council share the same physical network responsible for voice and data communications? No. If you are not satisfied with this response you may ask for a review of this decision by contacting xxx@xxxxxxxx.xxx.xx or by writing to Freedom of Information, 7th Floor, City Exchange, 61 Hall Ings, Bradford, West Yorkshire, BD1 5SG. If you are still not satisfied with the outcome of the internal review you have the right of appeal to the Information Commissioner who can be contacted at: Information Commissioner's Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF Tel: 01625 545700 URL: http://www.informationcommissioner.gov.uk Regards, Peter Silcock Strategic Information Manager (Technical) / CISO Department of Corporate Services Business Transformation * Revenues & Benefits * Finance * Human Resources * Legal and Democratic City of Bradford Metropolitan District Council, 1st Floor Britannia House, Hall Ings, Bradford BD1 1HX Tel: 01274 435991 Mob: 07582 101311 Fax: 01274 742465 e-mail: <> Visit our website at www.bradford.gov.uk This E-mail may contain information that is privileged, confidential or otherwise protected from disclosure. It must not be used by, or its contents copied or disclosed to persons other than the intended recipient. Any liability (in negligence or otherwise) arising from any third party acting, or refraining from acting, on any information contained in this E-mail is excluded. If you are not the intended recipient, please notify the sender and delete the message from your system immediately. Please consider the environment before printing this email.