Information Technology Request

Roedd y cais yn rhannol lwyddiannus.

Dear Gambling Commission,

I am writing to make an open government request for all the information to which I am entitled under the Freedom of Information Act 2000.

Please forward responses to the attached questions below.

I would like the above information to be provided to me as an electronic document.
If this request is too wide or unclear, I would be grateful if you could contact me as I understand that under the Act, you are required to advise and assist requesters. If any of this information is already in the public domain, please can you direct me to it, with page references and URLs if necessary.

If the release of any of this information is prohibited on the grounds of breach of confidence, I ask that you supply me with copies of the confidentiality agreement and remind you that information should not be treated as confidential if such an agreement has not been signed.
I understand that you are required to respond to my request within the 20 working days after you receive this letter. I would be grateful if you could confirm in writing that you have received this request.

I look forward to hearing from you.

Yours faithfully,

Gloria Zimba.

1. Do you have a formal IT security strategy? (Please provide a link to the strategy)

A) Yes
B) No

2. Does this strategy specifically address the monitoring of network attached device configurations to identify any malicious or non-malicious change to the device configuration?

A) Yes
B) No
C) Don’t know

3. If yes to Question 2, how do you manage this identification process – is it:

A) Totally automated – all configuration changes are identified and flagged without manual intervention.
B) Semi-automated – it’s a mixture of manual processes and tools that help track and identify configuration changes.
C) Mainly manual – most elements of the identification of configuration changes are manual.

4. Have you ever encountered a situation where user services have been disrupted due to an accidental/non malicious change that had been made to a device configuration?

A) Yes
B) No
C) Don’t know

5. If a piece of malware was maliciously uploaded to a device on your network, how quickly do you think it would be identified and isolated?

A) Immediately
B) Within days
C) Within weeks
D) Not sure

6. How many devices do you have attached to your network that require monitoring?

A) Physical Servers: record number
B) PC’s & Notebooks: record number

7. Have you ever discovered devices attached to the network that you weren’t previously aware of?

A) Yes
B) No

If yes, how do you manage this identification process – is it:

A) Totally automated – all device configuration changes are identified and flagged without manual intervention.
B) Semi-automated – it’s a mixture of manual processes and tools that help track and identify unplanned device configuration changes.
C) Mainly manual – most elements of the identification of unexpected device configuration changes are manual.

8. How many physical devices (IP’s) do you have attached to your network that require monitoring for configuration vulnerabilities?

Record Number:

9. Have you suffered any external security attacks that have used malware on a network attached device to help breach your security measures?

A) Never
B) Not in the last 1-12 months
C) Not in the last 12-36 months

10. Have you ever experienced service disruption to users due to an accidental, non-malicious change being made to device configurations?

A) Never
B) Not in the last 1-12 months
C) Not in the last 12-36 months

11. When a scheduled audit takes place for the likes of PSN or Cyber Essentials, how likely are you to get significant numbers of audit fails relating to the status of the IT infrastructure?

A) Never
B) Occasionally
C) Frequently
D) Always

Freedom of Information, Gambling Commission

 

Dear Madam

 

Thank you for your request for information which we are processing as a
request under the Freedom of Information Act 2000.  

 

We aim to deal with all requests promptly and in any event, no later than
20 working days in line with the statutory requirement.  In this case 29
December 2021.

 

For information on how we process your personal information please see our
freedom of information request specific [1]privacy notice on the Gambling
Commission website

 

If you have any queries about this email, please contact us.

 

Kind regards

 

Freedom of Information Team

Gambling Commission
Victoria Square House
Victoria Square
Birmingham B2 4BP

 

 

This email and any files transmitted with it are intended solely for the
use of the individual or entity to whom they are addressed. If you have
received this email in error please return it to the address it came from
indicating that you are not the intended recipient and delete it from your
system. Do not copy, distribute or take action based on this email.
Freedom of Information requests can be submitted either by email
([email address]) or by writing to: FOI request Gambling
Commission Victoria Square House Victoria Square Birmingham B2 4BP Please
clearly state that your request is under the Freedom of Information Act.

References

Visible links
1. https://www.gamblingcommission.gov.uk/ab...

Freedom of Information, Gambling Commission

 

 

Dear Ms Zimba

 

Thank you for your request which has been processed under the Freedom of
Information Act 2000 (FOIA).

 

The Gambling Commission’s response to your enquiries is as follows:

 

1.      Do you have a formal IT security strategy? (Please provide a link
to the strategy)

 

 

 

A)      Yes

 

B)      No

 

 

 

2.      Does this strategy specifically address the monitoring of network
attached device configurations to identify any malicious or non-malicious
change to the device configuration?

 

Not applicable

 

 

A)      Yes

 

B)      No

 

C)      Don’t know

 

 

 

3.      If yes to Question 2, how do you manage this identification
process – is it:

 

Not applicable

 

 

A)      Totally automated – all configuration changes are identified and
flagged without manual intervention.

 

B)      Semi-automated – it’s a mixture of manual processes and tools that
help track and identify configuration changes.

 

C)      Mainly manual – most elements of the identification of
configuration changes are manual.

 

 

 

4.      Have you ever encountered a situation where user services have
been disrupted due to an accidental/non malicious change that had been
made to a device configuration?

 

 

 

A)      Yes

 

 

 

 

5.      If a piece of malware was maliciously uploaded to a device on your
network, how quickly do you think it would be identified and isolated?

 

 

 

The FOIA gives individuals the right to request only recorded information
held by public authorities, such as the Gambling Commission. It does not
provide an avenue for individuals to gain views or opinions of public
authorities or information not held at the time the request is made.

 

This question does not include a request for recorded information.
Therefore we are unable to provide a response.

 

 

 

6.      How many devices do you have attached to your network that require
monitoring?

 

 

 

A)      Physical Servers: 25

 

B)      PC’s & Notebooks: record number - 450

 

 

 

7.      Have you ever discovered devices attached to the network that you
weren’t previously aware of?

 

 

B)      No

 

 

 

If yes, how do you manage this identification process – is it:

 

Not applicable

 

 

A)      Totally automated – all device configuration changes are
identified and flagged without manual intervention.

 

B)      Semi-automated – it’s a mixture of manual processes and tools that
help track and identify unplanned device configuration changes.

 

C)      Mainly manual – most elements of the identification of unexpected
device configuration changes are manual.

 

 

 

8.      How many physical devices (IP’s) do you have attached to your
network that require monitoring for configuration vulnerabilities?

 

 

 

Record Number:  Information not held

 

 

9.      Have you suffered any external security attacks that have used
malware on a network attached device to help breach your security
measures?

 

 

 

A)      No

 

 

 

 

10.     Have you ever experienced service disruption to users due to an
accidental, non-malicious change being made to device configurations?

 

 

 

A)      No

 

 

 

11.     When a scheduled audit takes place for the likes of PSN or Cyber
Essentials, how likely are you to get significant numbers of audit fails
relating to the status of the IT infrastructure?

 

 

As stated previously, the FOIA gives individuals the right to request only
recorded information held by public authorities, such as the Gambling
Commission. It does not provide an avenue for individuals to gain views or
opinions of public authorities or information not held at the time the
request is made.

 

This question does not include a request for recorded information.
Therefore we are unable to provide a response.

 

 

 

 

 

Review of the decision

 

If you are unhappy with the service you have received in relation to your
Freedom of Information request and wish us to conduct a review of our
decision, you should write to FOI Team, Gambling Commission, 4th floor,
Victoria Square House, Victoria Square, Birmingham, B2 4BP or by reply to
this email.

 

If you are not content with the outcome of our review, you may then apply
directly to the Information Commissioner (ICO) for a decision. Generally,
the ICO cannot make a decision unless you have already exhausted the
review procedure provided by the Gambling Commission.  The ICO can be
contacted at:  The Information Commissioner’s Office, Wycliffe House,
Water Lane, Wilmslow, Cheshire SK9 5AF.

 

Kind regards

 

Freedom of Information Team

Gambling Commission
Victoria Square House
Victoria Square
Birmingham B2 4BP

 

This email and any files transmitted with it are intended solely for the
use of the individual or entity to whom they are addressed. If you have
received this email in error please return it to the address it came from
indicating that you are not the intended recipient and delete it from your
system. Do not copy, distribute or take action based on this email.
Freedom of Information requests can be submitted either by email
([email address]) or by writing to: FOI request Gambling
Commission Victoria Square House Victoria Square Birmingham B2 4BP Please
clearly state that your request is under the Freedom of Information Act.