2020007

Request regarding Information Technology.

Published: 26 February 2020

Information requested

  1. Are the Data Centre's operated by or for the organisation fit for purpose? For example, is there a Business Continuity Plan, is there Disaster Recovery in place or is it a single site?
  2. Is there any capital investment in data centres planned in the next 36 months? For example, Mechanical & Electrical or refresh of equipment within the DC such as network, storage area network?
  3. Is data privacy and or information security compliance a priority for the organisation’s board?
  4. On your Organisation’s risk register, are there any Information Technology related risks?
    1. If time/ cost allows, please list the top three related risks.
  5. Are the cyber security vulnerabilities within the organisation’s existing Information Technology estate increasing?
    1. Has the organisation had a security breach in the past 12 months?
  6. Did the organisation meet its Information Technology savings target in the last Financial Year?
  7. What percentage of Information Technology budget is currently allocated to “on-premises” capability vs “cloud” capability?
  8. Does the organisation have the skills and resource levels necessary for moving to the cloud?
  9. What percentage of the Information Technology department headcount are software developers?
  10. In relation to contracts with Amazon Web Services, Microsoft for Azure and/or Google for Google Cloud, was the monthly expenditure higher than budgeted?
    1. If yes, has the organisation been able to subsequently reduce the cost whilst maintaining service levels for users?

NHSCFA response

  1. Are the Data Centre's operated by or for the organisation fit for purpose? For example, is there a Business Continuity Plan, is there Disaster Recovery in place or is it a single site?

    Yes, full business continuity and disaster recovery plans are in place.

  2. Is there any capital investment in data centres planned in the next 36 months? For example, Mechanical & Electrical or refresh of equipment within the DC such as network, storage area network?

    Yes, however this work will be provided by our contracted Management Infrastructure Supplier – Agilisys.

  3. Is data privacy and or information security compliance a priority for the organisation’s board?

    Yes, the Board take a keen interest in our Data Privacy and Information Security compliance. NHSCFA is ISO27001 accredited and maintains compliance with the PSN Code of Connection. It was at the Board’s request that we monitor our Cyber Security as an organisation risk.

  4. On your Organisation’s risk register, are there any Information Technology related risks?

    Yes.

    1. If time/ cost allows, please list the top three related risks.

      Cyber attacks

      Out of hours IT support

      Shortage of skilled IT and analytics resource.

  5. Are the cyber security vulnerabilities within the organisation’s existing Information Technology estate increasing?

    No, they are under constant review and mitigation with regular health checks (Penetration Testing).

    1. Has the organisation had a security breach in the past 12 months?

      No.

  6. Did the organisation meet its Information Technology savings target in the last Financial Year?

    Information Technology was delivered on budget.

  7. What percentage of Information Technology budget is currently allocated to “on-premises” capability vs “cloud” capability?

    There is no recorded percentage allocation, however currently we have a significantly larger on-premises capability.

  8. Does the organisation have the skills and resource levels necessary for moving to the cloud?

    The organisation has a combination of in-house skills and contracted suppliers with the required skills.

  9. What percentage of the Information Technology department headcount are software developers?

    32%

  10. In relation to contracts with Amazon Web Services, Microsoft for Azure and/or Google for Google Cloud, was the monthly expenditure higher than budgeted?

    As budgeted.

    1. If yes, has the organisation been able to subsequently reduce the cost whilst maintaining service levels for users?

Help us improve cfa.nhs.uk

Tell us what's happened so we can fix the problem. Please do not provide any personal, identifiable or sensitive information.

Close

Thanks for the feedback!

Close