-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Collab Cafe Write Up: Information Governance #30
Comments
First attempt at this. Source Hackmd here SATRE Collaboration Café 6th June: Information Governance of Trusted Research EnvironmentsOn Tuesday 6th June the SATRE Project held it's second Collaboration Café. Over 40 attendees across the UK TRE Commmunity contributed to an Information Governance theme. The discussions helped generate Chapter 1 of the SATRE Specification. Information GovernanceInformation Governance (IG) has been identified as one of the 3 SATRE Capability Pillars. The Collaboration Cafe invited the SATRE Community to come together and discuss which key areas reccomendations should be made towards IG standards in the SATRE Specification Information Goverance is one of the 3 SATRE Capability Pillars Topics DiscussedParticipants were asked propose areas of interest and discuss in breakout rooms. Here's a summary of the main points: Compliance, monitoring and reportingTRE organisations must be able to monitor compliance with internal and external laws and standards. The discussion concluded that it is mandatory for organizations to put in place processes to demonstrate compliance to accredited standards such as IS0270001, NHS Data Security and Protection Toolkit (DSPT) or Cyber Essentials (CE+). Additionally, organizations should share their complaince reports with regulatory bodies that manage the accreditations Policy Regulation and ManagementThe discussion stressed the need for a common understanding of information governance. Topics such as change management, policy/procedural reviews, and organizational structure play a crucial role. It also suggests mapping the information governance parts to an organizational model to track responsibilities and tasks. Risk managementThe focus is on managing risks within a TRE. It was suggested that a risk-based approach be adopted, which involves asset grouping, threat identification, vulnerability assessment, and understanding the impact of a potential breach. Automation and guidance on risk management were also recommended. Project managementKey considerations here include defining project team roles and handling the entire data lifecycle, which encompasses aspects like data source, consent, ethics approval, and data sharing agreements. The idea of separating technical and policy aspects was discussed but considered risky, emphasizing that technical controls form the basis for compliance with standards/regulations. Member accreditationIt was agreed that there need to be checks and criteria for identity and verification on anyone accessing the TRE, including affiliation verification, role-based training, and offboarding procedures. It was also emphasized that a clear chain of responsibility is essential to maintain accountability. Training and competencyRegular, role-specific training was discussed, and it was suggested that it doesn't always need to be annual, particularly if the training burdens are high. Alternative methods for demonstrating competency, such as tests or assessments of skills/knowledge were proposed. Policy regulation and managementThis should involve processes and policies responsive to requirements. A risk-based approach to access, data classification, and a process to assess legal and regulatory implications of handling data throughout its lifecycle were recommended. SummaryThe Collaboration Café on Information Governance allowed for many interesting discussions from SATRE members who think about and implement Information Governance in their roles. The discussions held were used to directly contribute to the SATRE Specification Document. The SATRE Community members created GitHub Issues and Pull Requests to collaboratively update the document. You can find the Information Governance section created from this Collaboration Café here. For more information about SATRE Collaboration Cafés and how they are run, please see our blog post. The SATRE project is extremely grateful for ongoing support and input from community members to collaboratively build the SATRE Specification. |
Summary of issue
Write up a blog post to be posted on the SATRE Medium Page that summarises ideas and GH Issues that came from the Collab Cafe on 6th June.
What needs to be done?
Who can help?
Issue checklist
SATRE backlog (public)
project boardThe text was updated successfully, but these errors were encountered: