Paul Kelly and Robert Mackenzie
Scott-Moncrieff
Scottish Government Social Research
2009
ISBN 978 0 7559 7483 4 (Web only publication)
This document is also available in pdf format (420k)
CONTENTS
1 EXECUTIVE SUMMARY
2 INTRODUCTION
Background
Aims and Objectives
Approach
3 RESULTS OF REVIEW
Security Policy
Security Organisation
Risk Assessment and Asset Management
Staff Education
Incident Reporting
Integrity of Installed Software Environment
Compliance with Security Requirements
Physical and Environmental Security
Network and Data Management
4 RECOMMENDATIONS
Recommendations for Contractors
Recommendations for Scottish Government
5 ANNEX 1
6 ANNEX 2
The views expressed in this report are those of the researcher and
do not necessarily represent those of the Department or Scottish Ministers.