DWP procurement: security policies and standards
These apply to DWP suppliers and contractors where explicitly stated in the security schedule of the contract.
- From:
- Department for Work and Pensions
- Published
- 9 April 2018
- Last updated
-
5
AugustSeptember 2024 — See all updates
Documents
Acceptable Use policy
PDF, 155 KB, 10 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Information Management policy
https://www.gov.uk/government/publications/dwp-information-management-policies/dwp-information-management-policy
Information Security policy
PDF, 236 KB, 8 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Personnel Security policy
PDF, 171 KB, 5 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Physical Security policy
PDF, 227 KB, 4 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Cryptographic Key Management policy
PDF, 542 KB, 5 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Email policy
PDF, 176 KB, 7 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Forensic Readiness policy
PDF, 204 KB, 10 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Microsoft Teams recording and transcription policy
PDF, 151 KB, 4 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Privileged Users Security policy
PDF, 472 KB, 3 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Protective Monitoring Security policy
PDF, 174 KB, 5 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Remote Working Security policy
PDF, 72 KB, 3 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security Classification policy
PDF, 229217 KB, 11 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
SMS Text policy
PDF, 402 KB, 3 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Social Media policy
PDF, 401 KB, 4 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Technical Vulnerability Management policy
PDF, 127 KB, 11 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
User Access Control policy
PDF, 192 KB, 4 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Placeholder: Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers
PDF, 57.4 KB, 1 page
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard: Physical and Electronic Security (part 1)
PDF, 866 KB, 24 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-001 (part 1): Access and Authentication Controls
PDF, 405 KB, 27 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-001 (part 2): Privileged User Access Controls
PDF, 334 KB, 18 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-002: Public Key Infrastructure & Key Management
PDF, 350 KB, 22 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-003: Software Development
PDF, 426 KB, 28 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-005: Database Management System
PDF, 320 KB, 17 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-006: Security Boundaries
PDF, 340 KB, 25 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-007: Use of Cryptography
PDF, 325 KB, 24 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-008: Server Operating System
PDF, 380 KB, 22 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-009: Hypervisor
PDF, 325 KB, 18 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-010: Desktop Operating System
PDF, 370 KB, 21 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-011: Containerisation
PDF, 364 KB, 32 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-012: Protective Monitoring Standard
PDF, 299 KB, 24 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-013: Firewall Security
PDF, 466 KB, 26 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-014: Security Incident Management
PDF, 375 KB, 22 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-015: Malware Protection
PDF, 338 KB, 29 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-016: Remote Access
PDF, 316 KB, 19 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-017: Mobile Device
PDF, 310 KB, 15 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-018: Network Security Design
PDF, 502 KB, 48 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-019: Wireless Network
PDF, 392 KB, 24 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-022: Voice and Video Communications
PDF, 395 KB, 25 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-023: Cloud Computing
PDF, 804 KB, 36 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-025: Virtualisation
PDF, 346 KB, 17 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-028: Microservices Architecture
PDF, 347 KB, 15 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security standard SS-029: Securely Serving Web Content
PDF, 357 KB, 19 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security Standard SS-031: Domain Management
PDF, 325 KB, 15 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security Standard SS-033: Security Patching
PDF, 306 KB, 21 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security Standard SS-035: Backup and Recovery
PDF, 346 KB, 18 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Security Standard SS-036: Secure Sanitisation and Destruction
PDF, 376 KB, 30 pages
This file may not be suitable for users of assistive technology.
Request an accessible format.
Details
The Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers is under review. You should refer to Good Practice Guides 45 and 44 instead.
Note, the Department for Work and Pensions (DWP) is unable to reply to general enquiries or questions about these security standards and policies.
These security standards and policies apply to DWP suppliers and contractors only. They do not apply to other government departments, their agencies or arm’s length bodies.
They have been published to help inform DWP Invitations to Tender and other contracting processes.
DWP may choose in an Invitation to Tender or the bid process to reference the standards and policies published here. Questions about a specific standard or policy should be sent to the DWP team managing responses to bids. This team is the only DWP authorised responder on any question about a bid and a standard or policy.
A new or changed policy or standard does not mean a new requirement for any existing contract. DWP will notify contract holders or partners of any changes to a contract.
Suppliers and contractors should contact their DWP contract managers with any questions about:
- varying contracts
- changing the agreed delivery of contracted services
- the applicability of a standard or policy for their contracts
Updates to this page
Last updated 5
-
The Security Classification Policy has been updated.
-
DWP forensic readiness policy has been updated.
-
SS-033 - Security Patching has been updated.
-
Published an updated DWP Security Classification Policy. Under 'Compliance', added at paragraph (e) guidance on what to do where systems or applications do not allow for an automatic security classification to be applied. There have also been changes to paragraph numbering.
-
Updated DWP Security standard SS-011: Containerisation.
-
Published updated DWP Security Classification Policy.
-
The email policy has been updated to the latest version.
-
Acceptable Use policy updated to include amendments around use of public Vs Private AI and also amendments around use of Non-Corporate Communication Channels.
-
Replaced the User Access Control Policy. Updated guidance on password management to advise users must change their passwords on indication or suspicion of compromise.
-
Removed Security standard SS-030: Oracle Database Security because it is out of date. The guidance is now included in Security standard SS-005: Database Management Systems.
-
Updated Security standard SS-018: Network Security Design and removed out of date Security standard SS-027: Application Security Testing.
-
Updated DWP Security standard SS-013: Firewall Security, Security standard SS-023: Cloud Computing and Security standard SS-028: Microservices Architecture (version 2).
-
Published updated security standards: SS-001 (part 1): Access and Authentication Controls; SS-001 (part 2): Privileged User Access Controls; SS-014: Security Incident Management; SS-029: Securely Serving Web Content; SS-036: Secure Sanitisation and Destruction.
-
Updated the DWP Email policy.
-
Security Standard SS-035: Backup and Recovery attachment published in error, replaced with correct version.
-
Updated 'Security Standard SS-035: Backup and Recovery' attachment.
-
Added revised versions of Security standard SS-003: Software Development and SS-005: Database Management Systems.
-
Added Security standard SS-014: Security Incident Management.
-
Added revised version of Security Standard SS-033: Security Patching.
-
New 'Security Standard (SS-035): Backup and Recovery' added. Updated 'Security standard SS-008: Server Operating System'. Deleted 'Security standard SS-014: Security Incident Management' and 'Form: Security incident response team referral (for Security standard SS-014: Security Incident Management)'.
-
Updated Security standards SS-009 Hypervisor, SS-022: Voice and Video Communication and SS-025: Virtualisation (the new versions are labelled version 2.0 and dated 27/04/2023).
-
Updated the Technical Vulnerability Management policy.
-
Updated Security standard SS-002: Public Key Infrastructure & Key Management, SS-010: Desktop Operating System and SS-031: Domain Management.
-
Updated Security standards SS-017: Mobile Device and SS-019: Wireless Network.
-
Updated security standard SS-15: Malware protection.
-
Added a new version of the Remote Working Security policy. Updated paragraph 3.3 and 7.5 of the Acceptable Use policy.
-
Published a revised version of the DWP Acceptable Use Policy (the new version is still labelled version 3). Published a revised version of DWP Security standard SS-006: Security Boundaries (the new version is labelled version 2 and dated 16/01/2023), and a revised version of Security standard SS-016: Remote Access (the new version is labelled version 2 and dated 16/01/2023).
-
Published a revised version of DWP Security Standard SS-007: Use of Cryptography (the new version is labelled version 2.0, dated 07/12/2022) and DWP Security Standard SS-033: Security Patching (the new version is labelled version 2.0, dated 07/12/2022).
-
Published a revised version of the Security standard: Physical and Electronic Security (part 1) - the new version is labelled version 1.1, dated 16/11/2022.
-
Added the DWP policy for Protective Monitoring Security (version 1). This is for the use of DWP suppliers and contractors only.
-
Published a revised version of the Security Standard SS-012: Protective Monitoring Standard (the new version is labelled version 2.0, dated 11/10/2022). Also published a new standard - Security Standard SS-036: Secure Sanitisation and Destruction (this new standard is labelled version 1, dated 11/10/2022).
-
Published a revised version of the DWP Security Standard – Containerisation (SS-011) (the new version is labelled version 2.0, dated 22/08/2022).
-
Revised version of the DWP Microsoft Teams recording and transcription policy (the new version is labelled version 1.5, dated 22/09/22).
-
Revised version of DWP Physical Security Policy (new version is labelled version 2.1). Also published a new standard - Security standard: Physical and Electronic Security (part 1) (this new standard is labelled version 1).
-
Revised version of DWP Acceptable Use Policy (new version is labelled version 3).
-
Revised version of DWP Personnel Security Policy (new version is labelled version 2).
-
Revised version of Security Standard SS-031: Domain Management (new version is labelled version 1.2 and dated December 2021).
-
Added the DWP policy for Microsoft Teams Recording and Transcription. This is for DWP suppliers and contractors only.
-
Revised version of Social Media policy (new version is labelled version 2).
-
Added Personnel Security policy for DWP suppliers and contractors.
-
Revised version of Security Standard SS-033: Security Patching (new version is labelled version 1.3 and dated January 2021).
-
Revised version of Security Standard SS-033: Security Patching (now labelled version 1.2).
-
Revised version of Security standard SS-016: Remote Access (now labelled version 1.2). Typo correction in entry 10.3.2, from ‘Authority’ to ‘Contractor’.
-
Published revised version of Security incident response team referral form for Security standard SS-014. The revised form is dated 3 June 2020.
-
Added the following 10 DWP policies: Cryptographic Key Management Policy, Email Policy, Forensic Readiness Policy, Privileged Users Security Policy, Remote Working Security Policy, Security Classification Policy, SMS Text Policy, Social Media Policy, Technical Vulnerability Management Policy and User Access Control Policy.
-
Published updated versions of the DWP security standards. All are now dated March 2020, except standard SS-014 which is dated 4/3/2020. These have been revised to reflect changes in DWP processes, laws, and national and international security standards and practices.
-
Added DWP Security Standard SS-033: Security Patching.
-
Removed the Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers document. This document is currently under review.
-
Revised versions of the Acceptable Use (version 2.5) and Physical Security (version 2) policies.
-
Revised versions of 'Security Standard - Firewall Security (SS-013)' and 'Security Standard - Network Security Design (SS-018)'. Both are now dated 9 April 2019.
-
Added 'Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers' (version 1.7).
-
Published revised version of Security standard SS-003: Software Development (now version 1.1, dated 07/10/2018).
-
Published revised versions of Acceptable Use (version 2.5), Information Security (version 1) and Physical Security (version 1) policies.
-
Added 'Security standard SS-012: Protective Monitoring Standard'.
-
Added 'Security standard SS-001 (part 2): Privileged User Access Controls'.
-
First published.
Sign up for emails or print this page
Update history
2024-09-05 12:12
The Security Classification Policy has been updated.
2024-08-05 14:48
DWP forensic readiness policy has been updated.
2024-08-02 10:44
SS-033 – Security Patching has been updated.
2024-07-24 07:56
Published an updated DWP Security Classification Policy. Under ‘Compliance’, added at paragraph (e) guidance on what to do where systems or applications do not allow for an automatic security classification to be applied. There have also been changes to paragraph numbering.
2024-07-19 11:10
Updated DWP Security standard SS-011: Containerisation.
2024-03-07 07:50
Published updated DWP Security Classification Policy.
2024-02-07 13:36
The email policy has been updated to the latest version.
2024-02-05 10:41
Acceptable Use policy updated to include amendments around use of public Vs Private AI and also amendments around use of Non-Corporate Communication Channels.
2024-01-31 12:48
Replaced the User Access Control Policy. Updated guidance on password management to advise users must change their passwords on indication or suspicion of compromise.
2024-01-24 16:20
Removed Security standard SS-030: Oracle Database Security because it is out of date. The guidance is now included in Security standard SS-005: Database Management Systems.
2024-01-16 12:21
Updated Security standard SS-018: Network Security Design and removed out of date Security standard SS-027: Application Security Testing.
2023-12-12 16:54
Updated DWP Security standard SS-013: Firewall Security, Security standard SS-023: Cloud Computing and Security standard SS-028: Microservices Architecture (version 2).
2023-11-08 08:20
Published updated security standards: SS-001 (part 1): Access and Authentication Controls; SS-001 (part 2): Privileged User Access Controls; SS-014: Security Incident Management; SS-029: Securely Serving Web Content; SS-036: Secure Sanitisation and Destruction.
2023-09-05 08:24
Security Standard SS-035: Backup and Recovery attachment published in error, replaced with correct version.
2023-09-04 13:21
Updated ‘Security Standard SS-035: Backup and Recovery’ attachment.
2023-06-27 11:40
Added revised versions of Security standard SS-003: Software Development and SS-005: Database Management Systems.
2023-06-15 16:58
Added Security standard SS-014: Security Incident Management.
2023-06-12 12:35
Added revised version of Security Standard SS-033: Security Patching.
2023-06-07 11:43
New ‘Security Standard (SS-035): Backup and Recovery’ added.Updated ‘Security standard SS-008: Server Operating System’.Deleted ‘Security standard SS-014: Security Incident Management’ and ‘Form: Security incident response team referral (for Security standard SS-014: Security Incident Management)’.
2023-05-09 15:06
Updated Security standards SS-009 Hypervisor, SS-022: Voice and Video Communication andSS-025: Virtualisation (the new versions are labelled version 2.0 and dated 27/04/2023).
2023-04-27 13:19
Updated the Technical Vulnerability Management policy.
2023-04-12 11:24
Updated Security standard SS-002: Public Key Infrastructure & Key Management, SS-010: Desktop Operating System and SS-031: Domain Management.
2023-03-20 17:00
Updated Security standards SS-017: Mobile Device and SS-019: Wireless Network.
2023-02-22 14:24
Updated security standard SS-15: Malware protection.
2023-02-17 16:06
Added a new version of the Remote Working Security policy. Updated paragraph 3.3 and 7.5 of the Acceptable Use policy.
2023-01-30 10:12
Published a revised version of the DWP Acceptable Use Policy (the new version is still labelled version 3). Published a revised version of DWP Security standard SS-006: Security Boundaries (the new version is labelled version 2 and dated 16/01/2023), and a revised version of Security standard SS-016: Remote Access (the new version is labelled version 2 and dated 16/01/2023).
2022-12-16 09:03
Published a revised version of DWP Security Standard SS-007: Use of Cryptography (the new version is labelled version 2.0, dated 07/12/2022) and DWP Security Standard SS-033: Security Patching (the new version is labelled version 2.0, dated 07/12/2022).
2022-11-17 09:04
Published a revised version of the Security standard: Physical and Electronic Security (part 1) – the new version is labelled version 1.1, dated 16/11/2022.
2022-11-07 11:19
Added the DWP policy for Protective Monitoring Security (version 1). This is for the use of DWP suppliers and contractors only.
2022-10-21 09:54
Published a revised version of the Security Standard SS-012: Protective Monitoring Standard (the new version is labelled version 2.0, dated 11/10/2022). Also published a new standard – Security Standard SS-036: Secure Sanitisation and Destruction (this new standard is labelled version 1, dated 11/10/2022).
2022-10-17 10:12
Published a revised version of the DWP Security Standard – Containerisation (SS-011) (the new version is labelled version 2.0, dated 22/08/2022).
2022-09-23 14:15
Revised version of the DWP Microsoft Teams recording and transcription policy (the new version is labelled version 1.5, dated 22/09/22).
2022-05-09 13:56
Revised version of DWP Physical Security Policy (new version is labelled version 2.1). Also published a new standard – Security standard: Physical and Electronic Security (part 1) (this new standard is labelled version 1).
2022-04-28 11:34
Revised version of DWP Acceptable Use Policy (new version is labelled version 3).