Information Security & Access

Information Security & Access – Further Reading 

This handout supports the session ‘Information Security & Access’. It signposts authoritative UK guidance on cyber security, information security governance, access controls, incident management, and recognised information security standards. 

Core Further Reading 

National Cyber Security Centre (NCSC) – Cyber Security Guidance 

Why this matters:
The NCSC is the UK’s technical authority for cyber security. Its guidance supports organisations to protect information assets, manage cyber risks, and respond to incidents, including access control, secure transfer and incident management. 

The National Archives (UK) – Information Security 

Why this matters:
Provides UK public-sector guidance on protecting information across its lifecycle, including access restrictions, secure handling, and accountability for records in all formats. 

National Records of Scotland (NRS) – Information Security Guidance 

Why this matters:
Sets statutory expectations under the Public Records (Scotland) Act 2011 for how authorities protect records, apply access controls, manage secure storage, and monitor compliance. 

ISO/IEC 27001 – Information Security Management Standard 

Why this matters:
ISO/IEC 27001 provides a globally recognised framework for managing information security risks, covering governance, access control, incident management and continuous improvement. 

Additional UK Records Management Resources 

UK Government Security Classifications 

https://www.gov.uk/government/publications/government-security-classifications

Explains how information should be classified and protected based on sensitivity and risk. 

Information Commissioner’s Office (ICO) – Security & Data Protection 

https://ico.org.uk/for-organisations/guide-to-data-protection/

Supports secure handling of personal data and links information security with data protection obligations. 

 

One of the best sources of information is the National Cyber Security Centre they have resources on all topics relating to cyber security risks   

All topics | National Cyber Security Centre 

There is also a toolkit for small business to help you identify what you can do to prevent cyber threats from affecting your business or activities.  

https://cybertoolkit.service.ncsc.gov.uk/layer/foundation  

What is phishing? 

What are malware and ransomware? 

Using online services safely 

Using online services safely | National Cyber Security Centre