NDG and NHS England issue joint statement about NHS Data Security and Protection Toolkit

Imported from official source

Cybersecurity Classified by Officially

The statement explains why NHS England is adopting the Cyber Assessment Framework and moving away from the NDG 10 data security standards as the assessment mechanism for the NHS Data Security and Protection Toolkit.

Dr. Nicola Byrne, National Data Guardian for health and social care

Today, the National Data Guardian (NDG) and NHS England jointly announced a significant update to how health and social care organisations measure and self-report their data security capabilities.

This change, part of the Department of Health and Social Care’s cyber security strategy for health and social care: 2023 to 2030, aims to align health and care with cyber resilience standards across other sectors.

Starting from 2 September 2024, the NHS Data Security and Protection Toolkit (DSPT) will gradually transition from using the NDG’s 10 data security standards to the National Cyber Security Centre’s Cyber Assessment Framework (CAF) as its underpinning assessment mechanism. NHS England will notify organisations when it is their turn to transition and guide them through the process.

Introduced in the National Data Guardian’s 2016 review of data security, consent, and opt-outs, the 10 data security standards have been essential in protecting patient information by encouraging a focus on three key areas: people, process and technology. While these core principles remain fundamental within the CAF, the rapidly changing landscape of technology and cyber threats requires the more advanced approach the CAF provides.

Dr. Nicola Byrne, the National Data Guardian, said:

This is an extract. The publication continues at the source.

Read the original at the source: https://www.gov.uk/government/news/ndg-and-nhs-england-issue-joint-statement-about-nhs-data-security-and-protection-toolkit

Officially imported this from National Data Guardian’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
National Data Guardian — imported from official source
Official source
https://www.gov.uk/government/organisations/national-data-guardian.atom ATOM
Imported
September 20, 2026 19:53
Versions
1 recorded
Identity
https://www.gov.uk/government/news/ndg-and-nhs-england-issue-joint-statement-about-nhs-...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.