Security
Who should I talk to about Security in the NHSBSA?
‘Security’ is a wide ranging topic, and the NHSBSA have a number of different roles to support us build and deliver our services securely.
Information Security
Information Security are responsible for:
- Handling security incidents
- Security assurance
- Business continuity
Information Governance
Information Governance (IG) are responsible for
- Data protection / GDPR requirements
- Data Protection Impact Assessments
Security Operations
Security Operations (SecOps) are responsible for:
- IT Health Checks
- Security architecture
-
Secure development
REVIEWSecurity is everyone’s responsibility
-
Keeping our software up to date with the latest versions of dependant libraries and runtimes
-
Secrets detection
REVIEWAvoid committing ‘secrets’ such as API keys into source control
-
Rewriting Git history
REVIEWRemoving sensitive data such as non-revokable secrets or contributor identities from Git
-
Security headers
REVIEWUse HTTP headers to protect our users
-
Content Security Policy
REVIEWUse CSP as the modern approach to securing our web applications
Improve the playbook
If you spot anything factually incorrect with this page or have ideas for improvement, please share your suggestions.
Before you start, you will need a GitHub account. Github is an open forum where we collect feedback.
Published: