Guidance

DWP procurement: security policies and standards

These apply to DWP suppliers and contractors where explicitly stated in the security schedule of the contract.

Documents

Acceptable Use policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Artificial Intelligence security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Information Management policy

Information Security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Personnel Security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Physical Security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Cryptographic Key Management policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Email policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Forensic Readiness policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Microsoft Teams recording and transcription policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Privileged Users Security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Protective Monitoring Security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Remote Working Security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security Classification policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

SMS Text policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Social Media policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Technical Vulnerability Management policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

User Access Control policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Placeholder: Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard: Physical and Electronic Security (part 1)

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-001 (part 1): Access and Authentication Controls

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-001 (part 2): Privileged User Access Controls

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-002: Public Key Infrastructure & Key Management

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-003: Software Development

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-005: Database Management System

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-006: Security Boundaries

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-007: Use of Cryptography

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-008: Server Operating System

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-009: Hypervisor

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-010: Desktop Operating System

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-011: Containerisation

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-012: Protective Monitoring Standard

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-013: Firewall Security

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-014: Security Incident Management

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-015: Malware Protection

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-016: Remote Access

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-017: Mobile Device

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-018: Network Security Design

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-019: Wireless Network

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-022: Voice and Video Communications

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-023: Cloud Computing

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-025: Virtualisation

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-028: Microservices Architecture

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-029: Securely Serving Web Content

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security Standard SS-031: Domain Management

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security Standard SS-033: Security Patching

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security Standard SS-035: Backup and Recovery

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security Standard SS-036: Secure Sanitisation and Destruction

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Details

The Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers is under review. You should refer to Good Practice Guides 45 and 44 instead.

Note, the Department for Work and Pensions (DWP) is unable to reply to general enquiries or questions about these security standards and policies.

These security standards and policies apply to DWP suppliers and contractors only. They do not apply to other government departments, their agencies or arm’s length bodies.

They have been published to help inform DWP Invitations to Tender and other contracting processes.

DWP may choose in an Invitation to Tender or the bid process to reference the standards and policies published here. Questions about a specific standard or policy should be sent to the DWP team managing responses to bids. This team is the only DWP authorised responder on any question about a bid and a standard or policy.

A new or changed policy or standard does not mean a new requirement for any existing contract. DWP will notify contract holders or partners of any changes to a contract.

Suppliers and contractors should contact their DWP contract managers with any questions about:

  • varying contracts
  • changing the agreed delivery of contracted services
  • the applicability of a standard or policy for their contracts

Updates to this page

Published 9 April 2018

Last updated 1314 MarchApril 2025 + show href="#full-history">+ show all updates
    1. Published an updated version of Security standard SS-015: Malware Protection.

Sign up for emails or print this page