Your Ref:
Our Ref: FOI/116794 /
Mr Dave Schneider
Email: / Date: 24 September 2010
Dear Mr Schneider
Freedom of Information request 116794
Thank you for your recent request received 18 August 2010 and actioned under the Freedom of Information Act 2000 in which you requested the following information:
Provide, name, address and telephone number for the following people:
- Senior Information Risk Owner
- Governance Manager
- Information Security Officer/Manager
- Information Technology Security Officer/Manager
- Caldecott Guardian
- Does your organisation process electronic payment cards?
- How much money is processed from electronic payment cards per annum?
- How many electronic payment card transactions are processed per annum?
- Are you PCI-DSS compliant?
ISO 27001
- Are you or have you considered becoming ISO 27001 compliant or certified?
Government Connect
- Are you connected and operationally utilising the Government Connect network?
- If not have you considered connecting to Government Connect and why was the decision made not to connect?
- Do you meet the Government Connect version three requirements?
- Please supply your latest CLAS consultant annual Government Connect assessment/audit report, blanking out any statements which could contravene a security concern from a third party reading it.
- Do you meet the Government Connect version four requirements?
- Please supply the latest internal report for the Government Connect version four Audit/Assessment, blanking out any statements which could contravene a security concern from a third party reading it.
Criminal Justice Network
- Are you connected to and operationally utilising the Criminal Justice Network?
- If not have you considered connecting to the Criminal Justice Network and why was the decision made not to connect?
- Please supply your latest annual assessment/audit report, blanking out any statements which could contravene a security concern from a third party reading it.
NHS N3 Network
- Are you connected to and operationally utilising the NHS N3 Network?
- If not have you considered connecting to the NHS N3 network and why was the decision made not to connect?
- Please supply your latest N3 Connection assessment/audit report, blanking out any statements which could contravene a security concern from a third party reading it.
- Do both schools and the Council share the same physical network responsible for voice and data communications?
Liverpool City Council (LCC) had a contract with Liverpool Direct Limited (LDL) for the provision of IT services and support; some areas therefore are not covered by LCC employers but by the services provided by LDL.
Staff Details
- Susan Curran
- Wendy Twigge is the Information Manager. The Information Team covers Data Protection Act (DPA) 1998, Freedom of Information Act (FOIA) 2000 and The Environmental Information Regulations (EIR) 2004 requests.
- Dave Crone.
- Sandra Campbell
- No
- N/A
- N/A
- N/A
ISO 27001
- Yes
Government Connect
- Yes
- N/A
- Yes
- This information is exempt from disclosure by virtue of Section 41 of FOIA which state that public authority do not have to disclosure information provided by third party if the disclosure will constitute a breach of confidence actionable by that or any other person. We would also consider that Exemption 24 applies to this response as disclosure of this information would enable infiltration into the council’s network and would provide a staging post to attach this or other UK Government ICT.
- Yes
- This information is exempt from disclosure by virtue of Section 41 of FOIA which state that public authority do not have to disclosure information provided by third party if the disclosure will be constitute a breach of confidence actionable by that or any other person. We also consider Section 23 applies as it is information supplied by or relating to specified bodies dealing with security matters. You may wish to refer any queries of this nature to GCHQ on 10242 221491 ext 30306.
Criminal Justice Network
- Yes
- N/A
- We do not hold this information.
NHS N3 Network
- We connect through their firewall to allow Hospital based social workers to access the LCC network
- N/A
- N/A
- No
