Received 17 July 2024
Decided 8 August 2024
Refused
Request Reference FOI-0024- 2024
Requester Type Member of the Public
Department of Climate, Energy and the Environment

Under the Public Sector Cyber Security Baseline Standards (Revision 1 November 2022) public bodies are mandated to have in place a Physical and Environmental Security Access Control Policy (section 1.6.1), and Access Control Procedures which outline classification of systems. (section 1.8.1) Under the FOI 2014 can I please request a digital copy of NSCS’s Cyber Security Governance Policy/Processes (or DECC equivalent policy/process where they apply to NCSC) where it relates to classification of systems and environments, and/or vetting requirements for access. Please note, as outlined in my original request, I do not seek the details of specific systems or individuals – I am interested in Information Security and Personnel Security safeguards that are in place within the NCSC.