Skip to main content

Written question asked by Maria Miller (Conservative) on Tuesday, 26 February 2008, in the House of Commons. It was due for an answer on Thursday, 28 February 2008. It was answered by Lord Brennan of Canton (Labour) on Wednesday, 5 March 2008 on behalf of the Department for Children, Schools and Families.


Children: Databases

Question
(7) what plans there are to review the role of self-certification as referred to in the written statement of 21 February 2008, Official Report, columns 55-58WS, on ContactPoint; and if he will make a statement;
Answer

In response to question 190741, ContactPoint User Acceptance Testing is scheduled to take place between July and September 2008.We plan to engage a representative set of future ContactPoint users to:"Verify that CP meets the stated business requirements, and its practical readiness,""Ensure the end to end system and processes meet the defined acceptance criteria."User Acceptance Testing will form an important part of assessing ContactPoint is in readiness for deployment.In response to question 190742, all data inputs to ContactPoint will be delivered over secure electronic channels. The frequency of updates of this data will vary depending on what is practicable and desirable for each source.In response to question 190743, (a) All partner organisations will be supported through their accreditation process by the local authority acting as an independent sponsor. Those performing the sponsor roles will be trained and appropriately qualified, (b) Ongoing monitoring will be performed at multiple levels across the ContactPoint delivery structure.The following will be in place:"monitoring of user access by line management;""compliance checks—that line management is monitoring user access by each organisation's internal audit or compliance team;""monitoring—that line management are monitoring their users by the local ContactPoint management team;""compliance checks— that the local authority ContactPoint team is performing its monitoring role by each local authority's internal audit or compliance team;""monitoring - that line management are monitoring their users by the local ContactPoint management team;""compliance checks - that the local authority ContactPoint team is performing its monitoring role by each local authority's internal audit or compliance team;""local authorities will log and monitor complaints and data subject access requests, identifying where follow up checking needs to take place;""discussions will be held between local authority internal audit and the internal audit of those organisations using ContactPoint to ensure congruence of risk assessments and sharing of lessons learned;""regular reviews of local authority ContactPoint team activities;""spot checks by organisation, local authority and nationally;""national reviews of management information based on a range of security""parameters;"Any areas of concern flagged by monitoring will be linked to mandatory follow-up procedures, including internal disciplinary action which could lead to dismissal and/or criminal prosecution.All monitoring is linked to a process of continual improvement, with the objective of strengthening the effectiveness of monitoring, detection and follow-up activity.In response to question 190745, accreditation will ensure a range of organisational policies and procedures are in place in each accredited organisation. These include a requirement to appoint responsible and accountable officers, to train staff, to set out accountabilities, to plan and implement a programme of inspections and audits, and to report issues to the sponsoring local authority.Auditing is a multi-level series of cross checks, executing monitoring activities, and checking that monitoring is taking place.Responsibilities will be set out clearly and will be covered in training and supporting materials (such as guidance and user manuals). Regular meetings will be used (between local authorities and partner organisations, and between the national team and local authorities) to ensure messages on responsibilities continue to be understood, to promote best practice, to raise and resolve issues around compliance, and to discuss other operational issues or difficulties.In response to questions 190746 and 190747, in determining the security policy for ContactPoint, the Government guidance on risk assessment and security controls set out in the Cabinet Office's Manual of Protective Security was followed. A risk assessment was carried out, in 2005, at the start of the ContactPoint project before any solution design or requirements were specified. It was updated in June 2006. Deloitte concluded that the approach followed was valid.ContactPoint has been designed to be highly secure and has controls at different levels to protect against security breaches. This will be kept under continuous review.Security is, and always has been, of paramount importance to the ContactPoint project and this was recognised in the Deloitte report.ContactPoint will not be deployed until it has been subject to rigorous penetration testing by people who are experts in the IT security field and approved by the Communications and Electronics Security Group.The Department's aim is to ensure that any potential risks from ContactPoint will be less than the risks from not having it.In response to questions 190748 and 190749, the accreditation plans were under development at time of the Deloitte review and indicated that self-certification would be used where appropriate in order to minimise burdens.Self-certification will be reviewed as part of the risk assessment scheduled to be completed by May 2008. Unacceptable risks to security will not be introduced by the use of self-certification.Self-certification of local partner organisations will be subject to verification by a local authority sponsor who will assure compliance with procedures. Funds have been allocated to local authorities to support these roles.In response to question 190751, there will be no access to the CAP itself, nor any of the details within it, from ContactPoint. If the ContactPoint user believes that they should contribute to, or see, the CAP assessment they would contact the practitioner whose details have been provided to ContactPoint as the person ‘holding’ the CAF.Practitioners will only become involved in CAP assessment with the informed, explicit consent of the child or young person (or their parent/carer where appropriate).


Secondary information

Type
Written question
Reference
190748; 472 c2636-8W
Session
2007-08
Subjects
Children Databases
Link
View this Written question on www.publications.parliament.uk