12
Information Governance and Technology Risks and Technology Risks NHS 2013 A Brave New World … Peter Sheppard South Coast Audit

Information Governance and Technology Risks in NHS 2013

Embed Size (px)

DESCRIPTION

A presentation on Information Governance and Technology risks in the new NHS and making use of your internal audit resources to gain adequate assurance.

Citation preview

Page 1: Information Governance and Technology Risks in NHS 2013

Information Governance and Technology Risks and Technology Risks

NHS 2013

A Brave New World …

Peter SheppardSouth Coast Audit

Page 2: Information Governance and Technology Risks in NHS 2013

Purpose of Session

Food for thought – Recognising Information and

Technology risks

Constructive challenge – Posing the right questions

to management

Internal Audit - Making effective use of your Internal Internal Audit - Making effective use of your Internal

Audit resources to obtain assurance.

Page 3: Information Governance and Technology Risks in NHS 2013

The brave new world….

Page 4: Information Governance and Technology Risks in NHS 2013

Governing Information Risk –Context and Expectations

Information risk to be managed in a robust manner

Assurance to be provided in a consistent manner

Structured approach is necessary

– Identify Information Assets– Assign ownership– Assign ownership– Formalise and standardise information risk management

Builds on upon existing NHS Information Governance

Page 5: Information Governance and Technology Risks in NHS 2013

Information Risk Management Roles

Page 6: Information Governance and Technology Risks in NHS 2013

Managing Informatics Risks

Risk Mitigation

TrainingTraining

PoliciesPolicies

IntegrityIntegrity

ConfidentialityConfidentiality

ObsolescenceInvestment

Strategy

Testing

ProcessesProcesses

TrainingTraining

AvailabilityAvailability

IntegrityIntegrity

Innovation

Patient

Safety

Technical controls

Project Management

Page 7: Information Governance and Technology Risks in NHS 2013

Source: ISACA

Page 8: Information Governance and Technology Risks in NHS 2013

Consumerization of technology

Page 9: Information Governance and Technology Risks in NHS 2013

Bring Your Own Device (BYOD)Improving efficiency and effectiveness?

Empowering staff

Mobile working (getting care closer to patient)

Flexibility

Saving office costs

Enabling future organisational development

Does BYOD fit organisational needs?

BUSINESS CASE

Page 10: Information Governance and Technology Risks in NHS 2013

Bring Your Own Device (BYOD)Risks… the flip side

Sensitive Data Leakage

Unauthorised connection & Interception

Malware & data retrieval

Usability

Support costs

Theft

How do we mitigate the risks?

Page 11: Information Governance and Technology Risks in NHS 2013

BYOD: Ideas to mitigate risks…

Policy & Standards

Risk mitigation

Device Management

Remote wipe and tracking

User Support and Training

Virtual Desktop

Infrastructure

and tracking

Encryption Access Controls

and Training

Page 12: Information Governance and Technology Risks in NHS 2013

Assurance through Management and Internal Audit … Talk to us!

Informatics supports modern business processes. Informatics supports modern business processes.

Expect your management team to provide assurance

Use internal audit to gain independent assurance on

the control environment

We can help by integrating Informatics Assurance

within Internal Audit plans, Governance and Risk

Management, as well as providing independent Management, as well as providing independent

support and advice.

Peter Sheppard BSc (Hons) CISA CITP MBCS MRSC

Associate Director of IM&T Audit Services

01424 77 67 50 [email protected]