11.07.2015 Views

The Foundation Programme Reference Guide - Academy of Medical ...

The Foundation Programme Reference Guide - Academy of Medical ...

The Foundation Programme Reference Guide - Academy of Medical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

e. Security standards for <strong>Foundation</strong> <strong>Programme</strong> e-portfoliosLevels <strong>of</strong> aggregation for foundation e-portfolio analysis dataAppendix 11e: Table 2: Levels <strong>of</strong> aggregationLevel <strong>of</strong> aggregationIndividual foundation doctor<strong>Foundation</strong> placement<strong>Foundation</strong> <strong>Programme</strong><strong>Foundation</strong> school/deaneryUK <strong>Foundation</strong> <strong>Programme</strong> Office (UKFPO)LEPAccess to aggregated dataIndividual foundation doctorEducational supervisorFTPD/TNominated programme administrativesupportFSDFSMNominated foundation school administrativestaffDeanNominated deanery administrative staffNominated UKFPO staffNominated person from the LEPSection 5 – Database securityStandards:All <strong>Foundation</strong> <strong>Programme</strong> e-portfolios must employ strategies to reduce the risk <strong>of</strong>unauthorised access.All <strong>Foundation</strong> <strong>Programme</strong> e-portfolios must employ strategies to reduce the risk <strong>of</strong> data loss.All <strong>Foundation</strong> <strong>Programme</strong> e-portfolios must comply with current government legislation andguidance relating to data security.Rationale:To encourage full participation <strong>of</strong> the <strong>Foundation</strong> <strong>Programme</strong>, all users must be assured thatall reasonable steps have been taken to safeguard their data.Mandatory Requirements:• all providers should have a back up system;• the strategies for managing risk must include an annual security review by an externalindependent body to comply with industry standard;• the annual security review should test both the application itself and the security <strong>of</strong>the data (including hosting, back-up, etc.);• detail relating to the robustness <strong>of</strong> the e-portfolio and the security controls employedmust be made available to all e-portfolio users; this would include the extent andmethods <strong>of</strong> the annual security review itself, but not its detailed results (whichtheoretically could compromise security);• only foundation doctors may download their own data. Downloads <strong>of</strong> non aggregateddata is not permitted.<strong>The</strong> UK <strong>Foundation</strong> <strong>Programme</strong>: <strong>Reference</strong> <strong>Guide</strong>70

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!