The CSIA has published guidance on Identity Risk Management in response to the Transformational Government Implementation Plan. The Guidance [PDF, 841KB] and Risk Analysis Tool: Introductory Guide [PDF, 364KB] will help government organisations to effectively manage the various risks related to their ICT and the information they handle on behalf of their customers. The CSIA Risk tool is now available to local authorities through the Government Connect Programme
The Information Assurance (IA) Framework, explains the process of IA governance and provides guidance on implementation and best practice for organisations across the public sector
– Information Assurance Governance Framework
Protecting our information systems - working in partnership to secure a resilient UK information infrastructure, June 2004. (PDF file, 566KB)
– CSIA Protecting our information systems (PDF file)
If you would like a quantity of printed copies of Protecting our information systems, please contact: csia@cabinet-office.x.gsi.gov.uk or call 0207 276 3115.
CSIA information leaflet. (PDF file, 64KB)
– CSIA leaflet (PDF file)
Providing a useful framework plotting the work of both public and private sectors in promoting information assurance awareness, October 2004. (PDF file, 410KB)
– Review of information assurance (PDF file)
These Security Framework documents will be replaced by the new e-Government IA framework following the public consultation following the public consultation (now closed).
Security: e-Government strategy framework policy and guidelines, September 2002. (PDF file, 568KB)
– Security (PDF file)
Assurance: e-Government strategy framework policy and guidelines, September 2002. (PDF file, 219KB)
– Assurance (PDF file)
Business services: e-Government strategy policy framework and guidelines, September 2002. (PDF file, 270KB)
– Business services (PDF file)
Confidentiality: e-Government strategy framework policy and guidelines, September 2002. (PDF file, 270KB)
– Confidentiality (PDF file)
Network defence: e-Government strategy framework policy and guidelines, September 2002. (PDF file, 272KB)
– Network defence (PDF file)
Registration and authentication: e-Government strategy framework and policy guidelines, September 2002. (PDF file, 371KB)
– Registration and authentication (PDF file)
Trust services: e-Government strategy policy framework and guidelines, September 2002. (PDF file, 290KB)
– Trust services (PDF file)
Accreditation Documentation Set (ADS): Information Security Policy Document (ISPD) BS7799, February 2003. (Word 97 document, 718KB; PDF file, 789KB)
– ADS Information Security Policy Document (Word 97)
– ADS Information Security Policy Document (PDF file)
Use of biometrics for identification and authentication - advice on product selection, December 2003. (PDF file, 191KB)
– Biometrics (PDF file)
Security architecture, September 2002. (PDF file, 671KB)
– Security architecture (PDF file)