FOI Request

Dave Schneider made this Freedom of Information request to Norfolk County Council

The request was successful.

From: Dave Schneider

18 August 2010

Sir/Madam,

I wish to make a request under the Freedom of Information Act. The
following questions and information I wish to have sent to me are
as follows:

Provide, name, address and telephone number for the following
people:
• Senior Information Risk Owner
• Governance Manager
• Information Security Officer/Manager
• Information Technology Security Officer/Manager
• Caldecott Guardian

PCI-DSS
Does your organisation process electronic payment cards?
How much money is processed from electronic payment cards per
annum?
How many electronic payment card transactions are processed per
annum?
Are you PCI-DSS compliant?

ISO 27001
Are you or have you considered becoming ISO 27001 compliant or
certified?

Government Connect
Are you connected and operationally utilising the Government
Connect network? If not have you considered connecting to
Government Connect and why was the decision made not to connect?
Do you meet the Government Connect version three requirements?
Please supply your latest CLAS consultant annual Government Connect
assessment/audit report, blanking out any statements which could
contravene a security concern from a third party reading it.
Do you meet the Government Connect version four requirements?
Please supply the latest internal report for the Government Connect
version four Audit/Assessment, blanking out any statements which
could contravene a security concern from a third party reading it.

Criminal Justice Network
Are you connected to and operationally utilising the Criminal
Justice Network? If not have you considered connecting to the
Criminal Justice Network and why was the decision made not to
connect?
Please supply your latest annual assessment/audit report, blanking
out any statements which could contravene a security concern from a
third party reading it.

NHS N3 Network
Are you connected to and operationally utilising the NHS N3
Network? If not have you considered connecting to the NHS N3
network and why was the decision made not to connect?
Please supply your latest N3 Connection assessment/audit report,
blanking out any statements which could contravene a security
concern from a third party reading it.
Do both schools and the Council share the same physical network
responsible for voice and data communications?

Yours faithfully,

Dave Schneider

Link to this

From: FOI
Norfolk County Council

18 August 2010

Dear Mr Schneider,

FREEDOM OF INFORMATION ACT 2000 - INFORMATION REQUEST

Thank you for your Freedom of Information request, received by us today,
August 18.

Our twenty working day deadline for your request is September 16 and we
aim to respond as soon as possible within the time period.

You will be informed in advance if there is a charge for supplying copies
of the information. We will also provide an explanation if any
information is not released to you. If the requested information contains
references to any third parties, we may need to consult with them before
deciding whether or not to release the information.

Should you have any queries regarding your request, please feel free to
contact us at [Norfolk County Council request email] .

Yours sincerely,

Deirdre Sharp

show quoted sections

Link to this

From: Sharp, Deirdre
Norfolk County Council

20 August 2010

Dear Mr Schneider,

I am in the process of collating information in order to respond to your
request of August 18 2010.

Our IT Security Officer has asked me to seek clarification regarding the
following elements of your request:

Government Connect

Please supply your latest CLAS consultant annual Government Connect
assessment/audit report, blanking out any statements which could
contravene a security concern from a third party reading it.

This appears to refer to the CoCo reassessment contracted to Siemens by
DWP, and described at the following website
[1]http://www.govconnect.gov.uk/reassessmen...

Can you confirm to me that what you have in mind is the feedback described
in the flowchart on this site?

Please supply the latest internal report for the Government Connect
version four Audit/Assessment, blanking out any statements which
could contravene a security concern from a third party reading it.

By internal report, do you mean here the pro-forma submitted by an
authority to Siemens as described on the above website, or do you mean the
authority's report from its IT Healthcheck, also referred to on the above
site, or do you have in mind some other document?

Can you confirm that you have not requested this council's Code of
Connection itself.

I am 'stopping the clock' on your request pending receiving your
clarification.

Yours sincerely,

Deirdre Sharp

The information contained in this email is intended only for the person or organization to which it is addressed. If you have received it by mistake, please disregard and notify the sender immediately. Unauthorized disclosure or use of such information may be a breach of legislation or confidentiality and may be legally privileged.

Emails sent from and received by Members and employees of Norfolk County Council may be monitored. They may also be disclosed to other people under legislation, particularly the Freedom Of Information Act 2000.

Unless this email relates to Norfolk County Council business it will be regarded by the Council as personal and will not be authorized by or sent on behalf of the Council. The sender will have sole responsibility for any legal actions or disputes that may arise.

References

Visible links
1. http://www.govconnect.gov.uk/reassessmen...

Link to this

From: Sharp, Deirdre
Norfolk County Council

15 September 2010


Attachment Schneider.D 01 Response.doc
37K Download View as HTML

Attachment GovConnect.pdf
147K Download View as HTML


Dear Mr Schneider,

I have now processed your request of August 18. I have done so on the
basis of my understanding of it as expressed in my e-mail to you of August
20, to which I have not yet had a response.

Our detailed response is attached. If you are dissatisfied with it or our
handling of your request you have the right of appeal through the
Council's internal complaints procedure by setting out the grounds of your
appeal in writing to the Freedom of Information Officer at:

Freedom of Information & Data Protection Unit
The Archive Centre
Martineau Lane
Norwich NR1 2DQ

e-mail: [1][Norfolk County Council request email]
Telephone: 01603 222661

If you are dissatisfied after pursuing the complaints procedure, you may
apply to the Information Commissioner under Section 50 of the Act for a
decision whether your request for information has been dealt with in
accordance with the requirements of Part I of the Act. Contact details as
follows:-

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Telephone 01625 545 700
[2]www.informationcommissioner.gov.uk

Yours sincerely,

Deirdre Sharp

<<Schneider.D(01)Response.doc>> <<GovConnect.pdf>>

The information contained in this email is intended only for the person or organization to which it is addressed. If you have received it by mistake, please disregard and notify the sender immediately. Unauthorized disclosure or use of such information may be a breach of legislation or confidentiality and may be legally privileged.

Emails sent from and received by Members and employees of Norfolk County Council may be monitored. They may also be disclosed to other people under legislation, particularly the Freedom Of Information Act 2000.

Unless this email relates to Norfolk County Council business it will be regarded by the Council as personal and will not be authorized by or sent on behalf of the Council. The sender will have sole responsibility for any legal actions or disputes that may arise.

References

Visible links
1. mailto:[Norfolk County Council request email]
2. http://www.informationcommissioner.gov.uk/

Link to this

Things to do with this request

Anyone:
Norfolk County Council only: