Data Security & Protection Training Log: 2025/26

Policy: All staff must complete the NHS "Data Security and Protection" e-learning module annually to ensure compliance with the DSPT 95% training requirement.

Staff Name Role Course Name Completion Date Certificate Ref
[SIRO Name] SIRO / DPO NHS Data Security & Protection (Level 1) [Date] [Ref #]
[SIRO Name] SIRO / DPO GDPR Training 9/1/2025 [Ref #]
[SIRO Name] SIRO / DPO Information Governance 21/12/2025 [Ref #]
[SIRO Name] SIRO / DPO Information Security, Data Protection, Freedom of Information 24/7/2024 [Ref #]
[DPO Name] CTO NHS Data Security & Protection (Level 1) [Date] [Ref #]

Internal Training Topics Covered (2025):

In addition to the NHS module, we held an internal briefing on:

  • Northflank Secrets Management: Handling DB credentials securely.
  • Incident Response: Walking through the "Restoration Test Log" procedures.
  • Phishing Awareness: Reviewing email security protocols for the @checktick.uk domain.

Role: Senior Information Risk Owner (SIRO)

Appointed Individual: [SIRO Name] Accountable To: The Board (Founding Partners)

Primary Responsibilities:

  1. Accountability: Overall ownership of the organization’s information risk policy.
  2. Culture: Driving a culture of data security and protection across all operations.
  3. Assurance: Providing board-level assurance that information risks are managed effectively.
  4. Incident Oversight: Acting as the final decision-maker on reporting data breaches to the ICO/DSPT.
  5. DSPT Submission: Final sign-off for the annual Data Security and Protection Toolkit submission.

Regular Actions:

  • Monthly review of the Asset Register and Vulnerability Reports.
  • Annual review of the Business Continuity and Disaster Recovery Plan.

Mandatory Training & Awareness Log: 2025/26

Target Completion: 100% | Actual Completion: 100%

1. Staff Completion Records

Name Role NHS Data Security L1 Secure Development Last Review
[SIRO Name] SIRO / DPO βœ… [Date] βœ… [Date] [Current Month]
[DPO Name] CTO / Cyber Lead βœ… [Date] βœ… [Date] [Current Month]

2. Activity Schedule

Activity Interval Description
NHS Data Security Awareness Annual Statutory requirement for all health-related staff.
OWASP / Secure Coding Annual Technical deep-dive for the CTO and developers.
BCDR Drill Annual Practical walkthrough of the disaster recovery plan.
Security Briefings Monthly Review of recent logs, alerts, and new policy updates.

3. Monitoring & Enforcement

The SIRO performs a quarterly review of this log. In the event of a training expiry, access to administrative systems (Northflank/GitHub) is restricted until the refresher is completed and evidence is provided.