ministryofjustice / security-guidance

Security guidance from the MOJ Digital & Technology Cybersecurity team
https://ministryofjustice.github.io/security-guidance/
Other
22 stars 25 forks source link

Request Approval to publish 'Accessing MOJ IT Systems from abroad'. #95

Closed warmanaMOJ closed 4 years ago

warmanaMOJ commented 4 years ago

Hello @cybersquirrel

Please may I request approval to publish guidance on 'Accessing MOJ IT Systems from abroad'? A preview of the document can be seen here.

I have also updated the landing page to include the new topic as part of the Asset Management section here.

Thank you.

cybersquirrel commented 4 years ago

Hi @warmanaMOJ - thanks for readying this for publication. A couple of minor tweaks / suggestions:

warmanaMOJ commented 4 years ago

@cybersquirrel Thank you, I have updated the draft accordingly.

cybersquirrel commented 4 years ago

Thank you - and apologies for my tardiness in the re-review.

I think the content is now spot on.

The only bit I'm slightly unsure about is the part 1 / part 2 flow. It feels like the activity at the end of part 1 (item 2) feels like it could happen first, before you collect all the data?

The other point is the ordering of part 2 - shouldn't item (3) come first? I'm not really sure of this, but it feels like you should first check that your LM is ok with the concept, then you get guidance from us, then you get your SCS to agree with any risks we've flagged? But then part 5 feels like there's a potential to get rejected again - this is a touch circular!

Sorry for further questions.

Jon.

warmanaMOJ commented 4 years ago

@cybersquirrel Thank you, a revised draft including your comments is available here

NB This is a different link to the one used earlier in the conversation (above).

cybersquirrel commented 4 years ago

This looks spot on. Happy to approve publication.

warmanaMOJ commented 4 years ago

Thank you very much.