-
FOI request (FOIR-176758449)
Information Technology
Requested Fri 21 February 2020
Responded Wed 04 March 2020Under the Freedom of Information Act 2000 I seek the following information:
1. Are the Data Centre's operated by or for the organisation fit for purpose? For example, is there a Business Continuity Plan, is there Disaster Recovery in place or is it a single site?
2. Is there any capital investment in data centres planned in the next 36 months? For example, Mechanical & Electrical or refresh of equipment within the DC such as network, storage area network?
3. Is data privacy and or information security compliance a priority for the organisation's board?
4. On your Organisation's risk register, are there any Information Technology related risks?
i) If time/ cost allows, please list the top three related risks.
5. Are the cyber security vulnerabilities within the organisation's existing Information Technology estate increasing?
i) Has the organisation had a security breach in the past 12 months?
6. Did the organisation meet its Information Technology savings target in the last Financial Year?
7. What percentage of Information Technology budget is currently allocated to "on-premises" capability vs "cloud" capability?
8. Does the organisation have the skills and resource levels necessary for moving to the cloud?
9. What percentage of the Information Technology department headcount are software developers?
10. In relation to contracts with Amazon Web Services, Microsoft for Azure and/or Google for Google Cloud, was the monthly expenditure higher than budgeted?
i) If yes, has the organisation been able to subsequently reduce the cost whilst maintaining service levels for users?
Response
Q1 - Yes
Q2 - No
Q3 - Yes
Q4 - Failure of IT equipment
Q5 - REFUSED (see below)
Q6 - Information Not Held
Q7 - Information Not Held
Q8 - Yes
Q9 - 27%
Q10 - No
Notice of Refusal Disclosure of information relating to ICT security constitutes a security risk as it would leave the Council's computer assets more vulnerable to a malicious hacking attack.
This means that disclosure would:
• Make the Council more vulnerable to crime (Section 31)
• Risk harming the systems on which the day-to-day business of the Council relies (Section 43) Section 31 (Law Enforcement)
Section 31(1)(a) states that information is exempt if its disclosure is likely to prejudice the prevention or detection of crime.
ICO guidance states that this can be used to protect information on a public authority's systems which would make it more vulnerable to crime.
This exemption can be used by a public authority that has no law enforcement function:
• To protect the work of one that does
• To withhold information that would make anyone, including the public authority itself, more vulnerable to crime
The crime in question would be a malicious attack on the Council's computer systems. Since the disclosure of the withheld information would make the Council's systems more vulnerable to such crime, the exemption is engaged.
The exemption is subject to the public interest test.
There is an overwhelming public interest in keeping the Council's computer systems secure which would be served by non-disclosure.
This outweighs the public interest in accountability and transparency that would be served by disclosure.
Section 43 (Commercial Interests) Section 43(2) states that information is exempt if its disclosure would, or would be likely to, prejudice the commercial interests of any person (including the public authority holding it).
Disclosure of information relating to ICT security puts the council at risk of a malicious hacking attack. This would compromise the Council's ability to provide its services and carry out 'business-as-usual' should our systems be compromised. Were our systems to be compromise, the cost of a system recovery would be detrimental to the Council's commercial interests.
The exemption is subject to the public interest test.
There is an overwhelming public interest in keeping the Council's computer systems secure which would be served by non-disclosure.
This outweighs the public interest in accountability and transparency that would be served by disclosure.
-
Freedom of Information
Contact
Got a question about freedom of information?
Content
The content on this page is the responsibility of our Council's Information Officer.