Information Security & Access
Information Security & Access – Further Reading
This handout supports the session ‘Information Security & Access’. It signposts authoritative UK guidance on cyber security, information security governance, access controls, incident management, and recognised information security standards.
Core Further Reading
National Cyber Security Centre (NCSC) – Cyber Security Guidance
- NCSC advice and guidance:https://www.ncsc.gov.uk/
- Cyber Assessment Framework (CAF): https://www.ncsc.gov.uk/collection/cyber-assessment-framework
Why this matters:
The NCSC is the UK’s technical authority for cyber security. Its guidance supports organisations to protect information assets, manage cyber risks, and respond to incidents, including access control, secure transfer and incident management.
The National Archives (UK) – Information Security
- Information management and security guidance:https://www.nationalarchives.gov.uk/information-management/manage-information/
Why this matters:
Provides UK public-sector guidance on protecting information across its lifecycle, including access restrictions, secure handling, and accountability for records in all formats.
National Records of Scotland (NRS) – Information Security Guidance
- Model RMP – Element 8 (Information security):https://www.nrscotland.gov.uk/records-and-archives/model-records-management-plan-guidance/?section=element-8-information-security
Why this matters:
Sets statutory expectations under the Public Records (Scotland) Act 2011 for how authorities protect records, apply access controls, manage secure storage, and monitor compliance.
ISO/IEC 27001 – Information Security Management Standard
- ISO/IEC 27001 overview (BSI):https://www.bsigroup.com/en-GB/products-and-services/standards/iso-iec-27001-information-security-management-system/
- ISO standard description: https://www.iso.org/standard/27001
Why this matters:
ISO/IEC 27001 provides a globally recognised framework for managing information security risks, covering governance, access control, incident management and continuous improvement.
Additional UK Records Management Resources
UK Government Security Classifications
https://www.gov.uk/government/publications/government-security-classifications
Explains how information should be classified and protected based on sensitivity and risk.
Information Commissioner’s Office (ICO) – Security & Data Protection
https://ico.org.uk/for-organisations/guide-to-data-protection/
Supports secure handling of personal data and links information security with data protection obligations.
One of the best sources of information is the National Cyber Security Centre they have resources on all topics relating to cyber security risks
All topics | National Cyber Security Centre
There is also a toolkit for small business to help you identify what you can do to prevent cyber threats from affecting your business or activities.
https://cybertoolkit.service.ncsc.gov.uk/layer/foundation
What is phishing?
What are malware and ransomware?
Using online services safely
Using online services safely | National Cyber Security Centre
