Information Security Management Policies

May 12, 2026 Cabinet (Cabinet collective) Approved View on council website
Full council record

Decision

The Cabinet had before it a report * from the Head of Digital Transformation and Customer Engagement reviewing the Information Security Management policies.

RESOLVED that:

  1. Cabinet recommend to Full Council the approval of the attached policies for implementation within the Council. Namely, Access Control, Asset Management, Operations Security, Physical Environment Security, Remote Working, and Encryption and Cryptography Policy.
  1. That delegated authority be given to the Deputy Chief Executive and Senior Information Risk Owner (SIRO) in consultation with the IT and Information Governance (ITIG) Board to agree future changes to the attached policies. This to also include authority to sign off future new policies that may be required to support Information Security Management within the Council.
  1. That delegated authority be given to the Deputy Chief Executive and Senior Information Risk Owner (SIRO) in consultation with the IT and Information Governance (ITIG) Board to agree future changes to the Data Protection, Information Security and Records Management policies in relation to supporting the DWP MOU work.

Note: * Report previously circulated.

Related Meeting

Cabinet - Tuesday, 12 May 2026 - 5.15 pm on May 12, 2026

Supporting Documents

App1 Access Control Policy.pdf
App2 Asset Management Policy.pdf
App3 Encryption and Cryptographic policy.pdf
Cabinet ICT Policies Report.pdf
App5 PhysEnvSecurityDraft.pdf
App6 Remote Working policy.pdf
App4 Operations SecurityDraft.pdf

Details

OutcomeRecommendations Approved
Decision date12 May 2026