Example: air traffic controller

MOBILE DEVICE MANAGEMENT POLICY - East …

MOBILE DEVICE MANAGEMENT POLICY East Cheshire NHS Trust Page 2 of 19 MOBILE DEVICE MANAGEMENT POLICY Mar 17 Integrated Governance Manager POLICY Title: MOBILE DEVICE MANAGEMENT POLICY Executive Summary: To formalise the requirements for all staff when utilising MOBILE devices (either personal or trust-owned) to ensure that all Trust information is secured. Supersedes: Version 1 Description of Amendment(s): Minor changes, including list of approved devices and roles and responsibilities This POLICY will impact on: All staff - Clinical practices, administrative practices, employees, corporate decision making. Financial Implications: POLICY Area: Corporate Document Reference: ECT002764 Version Number: Version 1 Effective Date: March 2017 Issued By: Director of Corporate Affairs & Governance Review Date: March 2020 Author: Integrated Governance Manager Impact Assessment Date: March 2017 APPROVAL RECORD Committees / Group Date Consultation: Information Governance & Records Group 8/3/2017 Approved by Committees: Information Governance & Records Group 8/3/2017 Approved by Director: Director of Corporate Af

East Cheshire NHS Trust Page 4 of 19 Mobile Device Management Policy – v.2 – Mar 17 Integrated Governance Manager 1. PURPOSE This document details the requirements for the use of portable mobile devices and removable media by

Tags:

  Policy, Devices, Mobile, Management, Mobile device management policy

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of MOBILE DEVICE MANAGEMENT POLICY - East …

1 MOBILE DEVICE MANAGEMENT POLICY East Cheshire NHS Trust Page 2 of 19 MOBILE DEVICE MANAGEMENT POLICY Mar 17 Integrated Governance Manager POLICY Title: MOBILE DEVICE MANAGEMENT POLICY Executive Summary: To formalise the requirements for all staff when utilising MOBILE devices (either personal or trust-owned) to ensure that all Trust information is secured. Supersedes: Version 1 Description of Amendment(s): Minor changes, including list of approved devices and roles and responsibilities This POLICY will impact on: All staff - Clinical practices, administrative practices, employees, corporate decision making. Financial Implications: POLICY Area: Corporate Document Reference: ECT002764 Version Number: Version 1 Effective Date: March 2017 Issued By: Director of Corporate Affairs & Governance Review Date: March 2020 Author: Integrated Governance Manager Impact Assessment Date: March 2017 APPROVAL RECORD Committees / Group Date Consultation: Information Governance & Records Group 8/3/2017 Approved by Committees: Information Governance & Records Group 8/3/2017 Approved by Director: Director of Corporate Affairs & Governance 8/3/2017 East Cheshire NHS Trust Page 3 of 19 MOBILE DEVICE MANAGEMENT POLICY Mar 17 Integrated Governance Manager Content 1.

2 PURPOSE 4 2. SCOPE 4 3. ROLES AND RESPONSIBILITIES 5 3. GUIDANCE 6 4. REFERENCES AND BIBLIOGRAPHY 8 5. ASSOCIATED DOCUMENTS 9 APPENDIX 1 List of Trust-Owned Approved devices 10 APPENDIX 2 List of approved Applications to be used in connection with business 11 APPENDIX 3 Trust-Owned MOBILE DEVICE Acceptance of Use Declaration - Issue of MOBILE Media Agreement 12 APPENDIX 4 Staff-Owned MOBILE DEVICE Acceptance of Use Declaration 14 East Cheshire NHS Trust Page 4 of 19 MOBILE DEVICE MANAGEMENT POLICY Mar 17 Integrated Governance Manager 1. PURPOSE This document details the requirements for the use of portable MOBILE devices and removable media by East Cheshire NHS Trust staff, and details the requirements that must be in place for the secure operation of such devices .

3 East Cheshire NHS Trust recognises the advantages in the utilisation of portable devices and other handheld devices provided for staff during the performance of their daily duties. As such, this document provides guidance on the use of such devices within the Trust s environment. It is also recognised that Remote Access is a valuable method for employees to connect to the Trust s network resources, when away from Trust premises. This document covers the use of all portable computing storage devices and remote access by East Cheshire NHS Trust staff, both Trust-owned and Staff-owned devices . This POLICY forms part of staff member s contractual obligations and code of conduct. It is accepted that technology may make significant advances during the lifetime of this POLICY and to this end, Appendix 1 (list of approved devices ) and Appendix 2 (list or approved applications) should be consulted as to whether a DEVICE or application is approved for use as these lists will be updated on a regular basis when appropriate.

4 This POLICY ensures that any use of a portable DEVICE , MOBILE communications or remote access working adheres to the following principles: To provide secure access to the Trust s information systems To preserve the integrity, availability and confidentiality of the Trust s information and information systems To manage the risk of serious financial loss, loss of patient and public confidence or other serious business impact which may result from a failure in security. In order to comply with all relevant regulatory and legislative requirements (including Data Protection laws) and to ensure that the organisation is adequately protected under computer misuse legislation. As part of the provision of Information MANAGEMENT and Technology services (IM&T) to staff within the organisation, staff may purchase their own portable computing equipment for use, on an ad hoc basis, on Trust business.

5 As such, it is essential that such devices are covered by appropriate security controls in compliance with Principle 7 of the Data Protection Act 1998 and ISO27001: Code of Practice for Information Security. Note: All MOBILE media is to be used for corporate information only and NOT for storing or processing clinical information, this with the exception of approved apps only. 2. SCOPE This POLICY applies to all staff employed by East Cheshire NHS Trust, including bank, agency and locum staff, students, voluntary staff, contractors and trainees on temporary placement, as well as those staff holding honorary contracts. East Cheshire NHS Trust Page 5 of 19 MOBILE DEVICE MANAGEMENT POLICY Mar 17 Integrated Governance Manager 3. GUIDANCE Portable devices For the purpose of this document, a Portable DEVICE is defined as any DEVICE that may synchronise with another computer, and may be any of the following items: Laptop and notebook computers IPads / Tablets Smart phones including IPhones and any other MOBILE system that may fall into this category, including Blackberry s Webcams USB memory sticks, (only for temporary storage of information, information to be transferred to secure server as soon as practicable and deleted from USB stick) MP3 players (including iPods), (must not be used at any time for storing personal or commercial information) CD s, DVD s Any other item that may be utilised to store or transport data.

6 This list is not to be considered exhaustive. Any portable DEVICE used in connection with the organisation must be encrypted to a minimum of 256bit encryption. There are no exceptions. Further guidance may be obtained from the Information Security Manager in relation to what is defined as a portable media DEVICE and encryption. Use of own devices The use of staff members own devices is permitted according to the following guidelines: - staff will only be allowed access to the Trust s WiFi network; there will be no access to the Trust s secured drives; - Staff will NOT save/store confidential or patient identifiable information on their personal devices Some requirements specific to staff-owned devices may differ to those contained within this document.

7 This POLICY concentrates on Trust-owned devices , however where requirements relating to staff-owned devices differ, staff should refer to the section identified within the text. Working Procedures All MOBILE devices issued by the organisation are issued to a named individual only and must not be shared or used by anyone who is not recorded as the asset owner, this for audit purposes and to comply with the Data Protection Act 1998. The exception to this requirement will be when a Business Group provides a generic business group DEVICE and the information East Cheshire NHS Trust Page 6 of 19 MOBILE DEVICE MANAGEMENT POLICY Mar 17 Integrated Governance Manager security requirements in these instances are the responsibility of the assigned user at any one time.

8 Business Groups are to implement a signing-in/signing-out log which is to be completed each time the DEVICE changes hands. Transfer of any DEVICE between staff members must only be done via the IT Servicedesk. Transfer of MOBILE phones to be done via the Telecommunications manager. All laptops, notebooks, USB Pens, IPads, Blackberrys and other Smartphones must be encrypted. Staff-owned devices must have the password facility activated. Use the minimum information necessary removing as much identifying data as possible. Do not copy documents containing personal or commercial data from the organisations servers without express permission of Information Governance Do not allow information to be seen by individuals who do not need to see it. Only use the equipment in a public area if you absolutely have to.

9 Asset MANAGEMENT Any business related software applications on MOBILE media devices must be approved, appropriately licensed and recorded on the Merseyside & Lancashire Commissioning Support Unit IT (MLSCU IT) licence asset register. The MLCSU IT Department will maintain a software application asset list to ensure licensing conditions are not breached. Procurement of additional software for business must adhere to Information Governance procedures, including the potential for a Privacy Impact Assessment to be completed. MOBILE devices must not be readily identifiable as belonging to, or associated with East Cheshire NHS Trust. If the DEVICE can be associated with the Trust or the NHS, this may increase the impact ( risk) to Trust s reputation in the event of loss or theft.

10 However, all Trust-owned MOBILE devices must carry asset identification. All iPads should have Airwatch ( MOBILE DEVICE MANAGEMENT ) installed before they are issued. Security Staff are personally responsible for the security of the MOBILE media DEVICE in their possession at all times whether this is on Trust premises, the premises of other organisations, in the car, on public transport or at home and will be liable for any cost resulting from the loss or accidental damage of the DEVICE as a result of carelessness. Where a DEVICE has been stolen, and on production of a Police Crime Report, the Trust will be liable. Where staff are using their own DEVICE , it is the Trust position that where this is the choice/decision of the member of staff concerned, all responsibility and liability for the DEVICE in terms of loss/damage will remain with the member of staff.


Related search queries