Mandatory
Not optional, not risk based.
- Hard drive encryption on every computer holding personal or sensitive information, laptops included
- Encryption on removable media
- Device encryption and access controls on mobiles and tablets
- An incident policy that says who notifies the LAA, and when
- An induction plan and an annual training plan for staff
- Records of who accessed personal data, with an audit trail that somebody actually reviews
- Secure destruction of records and of old electronic media
- A remote and home working policy
- Business continuity and disaster recovery plans
- A valid Cyber Essentials Basic certificate, renewed every twelve months. Clause 16.19 of the 2025 Standard Crime Contract, checked at verification and again at annual review