security and compliance update december 2015...december 2015 the security of customer data and the...

2
Congenica Ltd, Wellcome Genome Campus, Hinxton, Cambridge, CB10 1RQ, UK www.congenica.com, [email protected] Registered in England & Wales, Company No. 8273616 Registered office address: Merlin Place, Milton Road, Cambridge, CB4 0DP Security and Compliance Update December 2015 The security of customer data and the regulatory compliance of our systems are of paramount importance to Congenica. This brief summary provides an overview of our security and compliance systems. We are ISO27001:2013 certified ISO 27001 ("Information Security Management") provides requirements for establishing, implementing, maintaining and improving an information security management system (ISMS). Organisations that meet the standard may gain official certification issued by an independent and accredited certification body on successful completion of a formal audit process. Specifically, the ISO standard examines: Information, operational and physical security Human Resources Asset management How the company controls access to business developments How the company deals with incidents and disaster recovery How the company communicates and transfers data within its self and externally Ensuring compliance with all relevant laws and regulations We are compliant with the Information Governance Toolkit Information Governance (IG) deals with the way Congenica processes or handles information, specifically personal information relating to patients, employees and to the company. Completion of assessment (attainment levels 2-3) demonstrates that Congenica can be trusted to maintain the confidentiality and security of personal information. It draws together legal ruling such as the Data Protection Act and guidance from the Department of Health and presents them as a single standard as a set of IG requirements. Assessment is against requirements for: Management structures and responsibilities Data protection and confidentiality Information security We are registered with the Information Commissioner’s Office (ICO) The ICO is the UK’s independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals.

Upload: others

Post on 09-Aug-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Security and Compliance Update December 2015...December 2015 The security of customer data and the regulatory compliance of our systems are of paramount importance to Congenica. This

CongenicaLtd,WellcomeGenomeCampus,Hinxton,Cambridge,CB101RQ,UK

www.congenica.com,[email protected]&Wales,CompanyNo.8273616

Registeredofficeaddress:MerlinPlace,MiltonRoad,Cambridge,CB40DP

SecurityandComplianceUpdateDecember2015

ThesecurityofcustomerdataandtheregulatorycomplianceofoursystemsareofparamountimportancetoCongenica.Thisbriefsummaryprovidesanoverviewofoursecurityandcompliancesystems.WeareISO27001:2013certified

ISO27001("InformationSecurityManagement")providesrequirementsforestablishing,implementing,maintainingandimprovinganinformationsecuritymanagementsystem(ISMS).Organisationsthatmeetthestandardmaygainofficialcertificationissuedbyanindependentandaccreditedcertificationbodyonsuccessfulcompletionofaformalauditprocess. Specifically,theISOstandardexamines:• Information,operationalandphysicalsecurity• HumanResources• Assetmanagement• Howthecompanycontrolsaccesstobusinessdevelopments• Howthecompanydealswithincidentsanddisasterrecovery• Howthecompanycommunicatesandtransfersdatawithinitsselfandexternally• Ensuringcompliancewithallrelevantlawsandregulations

WearecompliantwiththeInformationGovernanceToolkit

InformationGovernance (IG)dealswith thewayCongenicaprocessesorhandles information, specificallypersonal information relating to patients, employees and to the company. Completion of assessment(attainment levels 2-3) demonstrates that Congenica can be trusted tomaintain the confidentiality andsecurity of personal information. It draws together legal ruling such as the Data Protection Act andguidance from the Department of Health and presents them as a single standard as a set of IGrequirements.Assessmentisagainstrequirementsfor:• Managementstructuresandresponsibilities• Dataprotectionandconfidentiality• Informationsecurity

WeareregisteredwiththeInformationCommissioner’sOffice(ICO)

The ICO is the UK’s independent authority set up touphold information rights in the public interest,promotingopennessbypublicbodiesanddataprivacyforindividuals.

Page 2: Security and Compliance Update December 2015...December 2015 The security of customer data and the regulatory compliance of our systems are of paramount importance to Congenica. This

CongenicaLtd,WellcomeGenomeCampus,Hinxton,Cambridge,CB101RQ,UK

www.congenica.com,[email protected]&Wales,CompanyNo.8273616

Registeredofficeaddress:MerlinPlace,MiltonRoad,Cambridge,CB40DP

CustomerData

ToenableCongenicatodeliverarobustserviceweensurethat:• Customerdataisencryptedatalltimes,bothintransitandatrest• Ourstoragesolutionsaresecure,reliableandscalable• Ourinfrastructuretosupportwebservicesarefitforpurpose

All of the services we use have the highest levels of physical and virtual security, and are listed asrecommended suppliers on the UK Government’s Digital Marketplace. The services on the DigitalMarketplacearealreadyontheG-Cloud,DigitalServicesorCrownHostingDataCentresframework.

Regulatory requirements are based on the high levels of data security specified in NHS England’s DataProtectionPolicy. NHSEngland is fullycompliantwiththeprinciplesof theDataProtectionAct includingthatpersonaldatashallnotbetransferredoutsideoftheEuropeanEconomicAreaunlessthereisadequateprotection.WhenworkingwithcustomersoutsidetheUK,weensurethatdatahandlingiscompliantwithlocalregulatoryrequirements.

Toensurethatwemaintainthehighestlevelsofsecurityforourcustomer’sdata,wecontinuallyreviewourservices to address best practices across the industry, and evaluate the performance of our existingprovisionsagainstothersolutionsavailableinthemarketplace.We have a full-time Quality Assurance and Regulatory Affairs Manager who oversees all of theseprocedures and maintains company documentation and training as well as ensuring that Congenicacontinuestoadheretoallcurrentstandardsandregulations.Forfurtherinformationpleasecontactusatinfo@congenica.com