Keeping data secure : Your commitment to safe working
Overview
To access the Integrated Data Service (IDS) you must be either:
- an accredited researcher
- completing the application process to become accredited
Once you are accredited and your project is approved, you will have access to the IDS Hub. This is a secure platform where authorised users can access IDS data, products, and services.
You are committing to working safely inside the IDS Hub by following these guidelines.
Accountability
- It is your responsibility to commit to working safely and to ensure that you do not compromise the security of the IDS, accidentally or deliberately.
- You should only use your approved organisational device to access the IDS.
- You must read, sign and follow the IDS Security Operating Procedures (SyOPs) and inform security of any suspected or actual security incidents, inappropriate use, or any known threats.
Physical security
- You must be an accredited and approved researcher to be able to access data within IDS.
- IDS must only be accessed from secure and approved working locations as per your Assured Organisational Agreement (AOC) agreement
- Access from public places, such as a train or canteen, or an unauthorised network is not permitted.
- You must have completed the mandatory training as part of the accreditation process.
Device and password security
- Choose a strong password that is difficult to guess and at least eight characters in length, or 16 characters for administrators or privileged accounts.
- Create a unique password for every device and system that you use, such as laptops or virtual machines.
- Keep your password confidential.
- Follow your organisation's security policies to ensure your device remains updated and free of malware and viruses.
- Enable two-step verification.
- Ensure others cannot see your screen when you are accessing data in the IDS Hub – keep it private.
Further information is available in the SyOps.
Responsible safe working
You must always be aware of the sensitivity of the data you are accessing or working on and the rules on how to handle it safely. This also applies to your role and the legal responsibilities and General Data Protection Regulation (GDPR) compliance associated with it.
This includes making sure that you:
- do not extract or output any data held within the IDS by any method other than the authorised and agreed output route
- make sure your internet connection is secure, and you are following your organisation’s security policy
- lock your screen when you have finished working or step away from your device
- do not take pictures or videos of your screen whilst using the IDS
- do not email or share information from inside the IDS
- do not share your location, for example, by geotagging
- only access the IDS from within the UK
Policies
These policies apply to all IDS users, regardless of the role they have been assigned.
- Collecting and Using Special Category Data Policy (opens in a new tab)
- Data Ethics Policy (opens in a new tab)
- Data Linkage and Matching Policy (opens in a new tab)
- Data Protection Policy (opens in a new tab)
- Data Standards Policy (opens in a new tab)
- Metadata Policy (opens in a new tab)
- Research and Data Access Policy (opens in a new tab)