System Level Security Policy (SLSP)

Last updated on

Patient Watch Ltd Implementation at [NHS Trust Name] Version 1.0

1. Introduction

1.1 Trust-Specific Information

  • Trust Name: [NHS Trust Name]
  • Department(s): [Specific departments using the system]
  • Trust Information Security Lead: [Name/Contact]
  • Trust Data Protection Officer: [Name/Contact]

1.2 System Description

  • Implementation scope within the Trust
  • Integration with Trust systems
  • Local configuration details
  • Trust-specific use cases

2. Trust Security Requirements

2.1 Local Policies

  • Trust’s Information Security Policy references
  • Local clinical system integration requirements
  • Trust-specific data handling requirements
  • Local access management procedures

2.2 Trust-Specific Controls

  • Local authentication methods
  • Trust network integration
  • Local backup requirements
  • Trust-specific audit requirements

3. Risk Assessment

3.1 Trust-Specific Risks

  • Local threat landscape
  • Integration risks
  • Operational risks specific to this Trust
  • Local environmental risks

3.2 Local Control Measures

  • Trust-approved security controls
  • Local monitoring requirements
  • Trust-specific incident response
  • Local business continuity measures

[… continue with other sections tailored to Trust requirements …]

Document Approval

  • Trust Information Security Manager: [Name/Signature]
  • Trust Caldicott Guardian: [Name/Signature]
  • Patient Watch Security Lead: [Name/Signature]
  • Date: [Date]