FOI Request

Dave Schneider made this Freedom of Information request to Kirklees Borough Council

The request was partially successful.

From: Dave Schneider

18 August 2010

Sir/Madam,

I wish to make a request under the Freedom of Information Act. The
following questions and information I wish to have sent to me are
as follows:

Provide, name, address and telephone number for the following
people:
• Senior Information Risk Owner
• Governance Manager
• Information Security Officer/Manager
• Information Technology Security Officer/Manager
• Caldecott Guardian

PCI-DSS
Does your organisation process electronic payment cards?
How much money is processed from electronic payment cards per
annum?
How many electronic payment card transactions are processed per
annum?
Are you PCI-DSS compliant?

ISO 27001
Are you or have you considered becoming ISO 27001 compliant or
certified?

Government Connect
Are you connected and operationally utilising the Government
Connect network? If not have you considered connecting to
Government Connect and why was the decision made not to connect?
Do you meet the Government Connect version three requirements?
Please supply your latest CLAS consultant annual Government Connect
assessment/audit report, blanking out any statements which could
contravene a security concern from a third party reading it.
Do you meet the Government Connect version four requirements?
Please supply the latest internal report for the Government Connect
version four Audit/Assessment, blanking out any statements which
could contravene a security concern from a third party reading it.

Criminal Justice Network
Are you connected to and operationally utilising the Criminal
Justice Network? If not have you considered connecting to the
Criminal Justice Network and why was the decision made not to
connect?
Please supply your latest annual assessment/audit report, blanking
out any statements which could contravene a security concern from a
third party reading it.

NHS N3 Network
Are you connected to and operationally utilising the NHS N3
Network? If not have you considered connecting to the NHS N3
network and why was the decision made not to connect?
Please supply your latest N3 Connection assessment/audit report,
blanking out any statements which could contravene a security
concern from a third party reading it.
Do both schools and the Council share the same physical network
responsible for voice and data communications?

Yours faithfully,

Dave Schneider

Link to this

From: Freedom Info
Kirklees Borough Council

1 September 2010

Dear Mr Schneider

I refer to your recent enquiry and enclose the council's response below:

Provide, name, address and telephone number for the following

people: No posts in the organisation with these titles

o Senior Information Risk Owner

o Governance Manager

o Information Security Officer/Manager

o Information Technology Security Officer/Manager

o Caldecott Guardian

PCI-DSS

Does your organisation process electronic payment cards?

How much money is processed from electronic payment cards per

annum?

How many electronic payment card transactions are processed per

annum?

Are you PCI-DSS compliant?

All information in respect of the Council's position regarding PCI-DSS is
classified as `restricted'

ISO 27001

Are you or have you considered becoming ISO 27001 compliant or

certified? The council is considering the implications of becoming
ISO 27001 compliant

Government Connect

All information in respect of the Council's position regarding the
Government Connect network is classified as `restricted'

Are you connected and operationally utilising the Government

Connect network?. If not have you considered connecting to

Government Connect and why was the decision made not to connect?

Do you meet the Government Connect version three requirements?

Please supply your latest CLAS consultant annual Government Connect

assessment/audit report, blanking out any statements which could

contravene a security concern from a third party reading it.

Do you meet the Government Connect version four requirements?

Please supply the latest internal report for the Government Connect

version four Audit/Assessment, blanking out any statements which

could contravene a security concern from a third party reading it.

Criminal Justice Network

All information in respect of the Council's position regarding the
Criminal Justice network is classified as `restricted'

Are you connected to and operationally utilising the Criminal

Justice Network? If not have you considered connecting to the

Criminal Justice Network and why was the decision made not to

connect?

Please supply your latest annual assessment/audit report, blanking

out any statements which could contravene a security concern from a

third party reading it.

NHS N3 Network

All information in respect of the Council's position regarding NHS N3
network is classified as `restricted'

Are you connected to and operationally utilising the NHS N3

Network? If not have you considered connecting to the NHS N3

network and why was the decision made not to connect?

Please supply your latest N3 Connection assessment/audit report,

blanking out any statements which could contravene a security

concern from a third party reading it.

Do both schools and the Council share the same physical network

responsible for voice and data communications?

Yours sincerely

Information Access Team

E: [email address]

Link to this

Alex Skene left an annotation (22 September 2010)

They say that some of the information "is restricted" - this is not a valid excuse under the FOI Act. I'd recommend asking for an internal review.

Link to this

phil left an annotation (23 September 2010)

Agreed, the fact that the information is marked as "Restricted" does not mean it is exempt from disclosure under the terms of the Freedom of Information act.

I'm suprised that the Kirklees Information Access Team does not appear to be aware of this trivial fact. Perhaps they require further training.

It does however, confirm that the information exists.

Link to this

Dave Schneider left an annotation (24 September 2010)

Don't worry I'm sure it will be. They're hiding behind information possibly being classified.

Well I can tell you from a professional angle it is not Restricted, as alot of the questions are yes or no.

Obviously fake professionals in this organisation!

Link to this

From: Dave Schneider

24 September 2010

Dear Kirklees Borough Council,

Please pass this on to the person who conducts Freedom of
Information reviews.

I am writing to request an internal review of Kirklees Borough
Council's handling of my FOI request named 'FOI Request' regarding
information about various Information Security Posts, GOvernment
Connect, NHS N3, CJX and Schools.

Alot of the questions being asked are yes or no answers. Where
peoples names, positions and contact details are being requested
you MUST give a reply containing genuine information as it is in
the public interest. The ICO will confirm this and I can give you
plenty of example cases.

Where documentation has been requested, other COuncils have
provided this. I have also asked for documentation to be blanked
out with a marker pen if you feel the information is sensitive,
however this should not be excessively used. A good example is the
MP's expenses documentation being released. FOr clarification
please speak to the ICO.

From a professional point of view, I feel you are hiding behing the
Governments Protective Marking Scheme (GPMS) and misleading the
public. SOme of the information is Restricted, but you are stateing
all information is restricted which is a false and misleading.

A full history of my FOI request and all correspondence is
available on the Internet at this address:
http://www.whatdotheyknow.com/request/fo...

I look forward to your positive response and hope we do not have to
involve the ICO thereby wasteing further public monies.

Yours faithfully,

Dave Schneider

Link to this

From: Freedom Info
Kirklees Borough Council

5 October 2010


Attachment 3471.doc
30K Download View as HTML


Dear Mr Schneider

I refer to previous correspondence regarding your recent enquiry.

Please find attached the Councils' response.

Yours sincerely

Information Access Team

E: [email address]

Link to this

Things to do with this request

Anyone:
Kirklees Borough Council only: