Select audience

Choose the option that best describes your role.

Information Security Policy

1. Purpose and Alignment 

1.1 Purpose

This policy defines the principles, governance, and mandatory controls for managing information security risk in alignment with NIST Cybersecurity Framework. It covers the scope and activities of the Information Security Team, and colleagues’ responsibilities, considering our tolerance for Information Security risk, and our legislative obligations.

1.2 Policy Objectives

1.2.1 The objective of this policy is to protect the Bank from cyber and information security threats by implementing effective controls, managing risk proactively and ensuring rapid response to potential incidents. It aims to safeguard the confidentiality, integrity and availability of information assets while promoting compliance with applicable legal and regulatory requirements. This includes:

  • Security Operations Management – Security tooling, log aggregation, detection engineering, threat hunting & intelligence, security event triage & analysis, and cyber incident response.
  • Posture Management – Security architecture and engineering, vulnerability management, penetration testing & red teaming, supplier risk management & due diligence, employee cyber security awareness & training
  • Protecting the Confidentiality of our data by ensuring it is only accessed by authorised individuals and by preventing unauthorised disclosure.
  • Protecting the Integrity of our data by preventing it from being altered by unauthorised individuals.
  • Ensuring the Availability of our data and systems by implementing controls to protect against disruptions through redundancy, failover systems, and backup and recovery processes.
  • Preventing non-repudiation by ensuring actions on information systems can be traced to the responsible party through access controls, logging, monitoring, and auditing.
  • Ensuring the Bank is compliant with our Legal and Regulatory obligations as outlined in section 1.4.
  • Maintaining the Bank’s Information Security Standards – see section 7 – and assess our systems against these.
  • Continuously improving our systems and processes through service requests, changes, service improvement projects, and by supporting the Bank’s strategic projects.

1.3 Alignment to Risk Appetite

This policy forms part of the Bank’s Risk Management Framework (RMF) and sits under the Level One Risk Category, Operational and Resilience Risk. It aligns to the Level Two Risk Category, Information Security (Incl. Cyber), which is defined as:

The risk that the Bank fails to protect the confidentiality, integrity, or availability of its digital enterprise

The Bank’s risk appetite level in relation to Information Security (Incl. Cyber) is Low.

The Bank is obliged to abide by all applicable UK law. The principal legislation to which this policy, and its associated policies and procedures relate, includes;

  • Computer Misuse Act 1990 – this act prohibits the unauthorised access, use or modification of computer systems and data. Misuse of Bank systems may result in the criminal prosecution of the individual under this act.
  • UK General Data Protection Regulation and Data Protection Act 2018 – require personal data to be processed securely and protected against unauthorised or unlawful processing and against accidental loss, destruction or damage – this policy and its related standards ensure this.
  • Human Rights Act 1998 – the Bank must ensure that monitoring, investigatory and incident response activity is carried out lawfully and in a way that is necessary and proportionate, including in respect of privacy rights.
  • Investigatory Powers Act 2016 and the Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulation 2018 - lawful interception of communications. The Bank may monitor communications and where required or permitted by law, the Bank may disclose relevant information to the authorities or other third parties - such as our cyber insurers - to protect our network security, satisfy legal obligations or manage a cybersecurity incident.
  • risk and incident management, incident reporting, and authority compliance requirements. We comply through our Incident Response processes. Colleagues are responsible for reporting incidents and should be aware of their local processes and the Bank's wider Incident Response Process.

In addition to meeting its legal obligations, the Bank as an Arm’s Length Body (ALB) is required to meet the Government Functional Standards (GFS) where applicable. Obligations relating to Government Functional Standard (GFS007) – Security are contained and prescribed through this policy and associated standards. We provide cyber resilience assurance to Government via the GovAssure programme.

2. Scope, Roles and Responsibilities

2.1 This Policy applies to all the Bank’s entities, operations and subsidiaries, and all Colleagues (see Appendix 3 for definition).

  • Colleague behaviours in the use of IT systems are covered in the Information Technology Acceptable Use Policy.
  • For detailed procedures on secure system and data usage, please refer to the IT Acceptable Use Policy.pdf.

2.2 The Information Security Team is responsible, and the Head of Information Security is accountable for:

  1. Defining and operationalising the cyber security strategy aligning with Bank's objectives
  2. Owning and maintaining the security frameworks, policies, standards and procedures
  3. Identifying and assessing security risks, managing exceptions and mitigations
  4. Providing security architecture guidance and design assurance
  5. Operating core security capabilities to proactively protect the digital landscape
  6. Managing cyber incidents and supporting other incident response activities
  7. Delivering security consultation, training, and awareness
  8. Reporting security posture and measuring compliance with regulatory and government requirements

2.3 Service Owners - as agreed and documented in the IT Service Catalogue - are responsible, and their Managing Director is accountable, for taking corrective action where the systems underlying their services are outside of compliance as defined in the Vulnerability Management Framework (VMF).

2.4 Appendix B is a simplified RACI matrix outlining key responsibilities across the Bank for maintaining cyber security and protecting data. It supports role clarity by showing who is expected to act, oversee, or advise in common security scenarios.

3. Information Security Themes and Requirements

We recognise four level three risks under Information Security (Incl. Cyber), broadly risks related to:

  • People - Risk of inadequate Information Security awareness and training
  • Process - Risk of Inadequate Information Security processes and procedures
  • Technology - Cyber and Technology Risk
  • Governance - Risk of Inadequate Information Security Governance

These themes are reflected from the Board Risk appetite statement in the RMF, through this policy and down to the Risk and Control library. This section details colleague responsibilities and behaviours under these themes.

3.1 Risk of inadequate Information Security awareness and training

“There is a risk that our colleagues, contractors and suppliers weaken the security of the Bank with a lack of understanding of the controls, tools and processes in place. We train and educate Colleagues appropriately on how to respond to information security threats and incidents. We perform due diligence checks against suppliers, significant exposures, and Colleagues.”

  • Colleagues must complete:
  • all generic and targeted mandatory learning and development in line with the Learning & Development Policy. This includes mandatory and role specific AI training.
  • Any targeted training required due to the risk associated with the role – e.g. accounts payable staff are often targets, or behaviour – for example, serial phishing links clickers

3.1.1 Information Security will ensure the content of the Information Security learning modules are relevant, proportionate to our risk and up to date.

  • Our risk decisions will be informed and validated by using cyber awareness activities such as ransomware exercises, ethical phishing, smishing, whaling or, vishing.
  • Colleagues will take all necessary steps to prevent unauthorised access, including those set forth in the Banks AI Standards
  • Colleagues will consider whether conversations can be overheard, and by whom. They will take all reasonable steps to prevent unauthorised disclosure of sensitive information this way, whether working remotely or at the Bank’s premises.
  • Colleagues will only disclose the Bank’s information to third parties in the proper exercise of their contractual duties using the appropriate channels, and with the permission of any second party if relevant. Colleagues will only disclose Official Sensitive information on a need-to-know basis and only if the recipient is bound by an obligation of confidentiality in favour of the Bank, such as with Non-Disclosure agreements (NDA).
  • Colleagues will understand that any information they create or transmit using company systems may be monitored, where lawful and necessary, for security and compliance purposes.

3.1.2 Prior to contract initiation or renewal: contract owners will ensure cyber security due diligence checks are carried out against the supplier; line managers are responsible for validating that interim workers have appropriate information security training and competence.

3.2 Cyber and Technology Risk

“There is a risk that the Bank’s vulnerability management systems fail to detect and deter a cyber-attack (e.g. Ransomware). We proactively monitor our systems to identify and remediate system vulnerabilities to agreed timeframes aligned to business requirements. Controls are in place to prevent and mitigate current and emerging Cyber and Information Security threats.”

Access

3.2.1. System access is role-based and follows the principles of least privilege and need-to-know. A colleague should not access or attempt to access systems that are not necessary for the fulfilment of their duties or to which they have not been granted access.

3.2.2. Colleagues will only access - or provide access to - authorised physical locations. Physical access to the Bank’s premises will follow the principle of least privilege, with appropriate physical access control for secure areas such as data centres or logistics loading bays.

Posture Management – vulnerability management and standards’ compliance

3.2.3. The Information Security team will maintain a set of Information Security Standards (see Supporting Standards) which will be reviewed annually at the same time as this policy. New systems, systems critical to the operation of the Bank or high risk systems will be assessed against these standards annually by Information Security.

3.2.4. The Bank’s Commercial Operations will ensure Information Security standards are made available to suppliers with sufficient time for the supplier to provide a full and comprehensive response, and for this to be reviewed by Information Security.

3.2.5. Information Security will validate their compliance through their accreditation against relevant standards and by completing due diligence checks.

3.2.6. The Information Security Team will maintain and operate a Vulnerability Management Framework (VMF) to enable the Bank to effectively manage vulnerabilities in software, firmware, hardware or configuration.

  • This defines roles, responsibilities, and timescales across the vulnerability management lifecycle. It predominantly applies to roles with service responsibilities, including but not limited to IT.
  • The Governance and Resilience team will inform Service Owners of the status of system vulnerabilities together with the required remediation controls and timescales as defined in the VMF. They will also inform Service Owners and Risk Managers of elements which do not comply with the security standards and agree remediation timescales.
  • Service Owners are responsible for resolving vulnerabilities affecting their services within the timescales detailed in the VMF. Vulnerabilities can be resolved through software patching, configuration changes, hardware or firmware updates, or architectural process and policy changes. Service Owners will ensure all systems comply to the information security standards.
  • Information Security will validate the vulnerability level of our systems and services using vulnerability scanning, penetration tests, or other appropriate means.
  • Information Security will use the RMF to report breaches in VMF Service Level Agreements (SLA), or lack of compliance with the Information Security Standards. They will produce regular reports for ERC demonstrating the effectiveness of the VMF and critical and high-risk systems’ standards compliance.

3.2.7. Suppliers must meet the requirements of our security due diligence checks - or be granted a security risk exception - prior to contract commencement or renewal.

3.2.8. Risk ownership resides with business owners who accept risk within appetite, informed by Information Security. All exceptions to standards’ compliance must be recorded with documented risk acceptance by the accountable Service Owner (or delegated business owner). Information Security will assess and advise on the risk, propose compensating controls, and ensure exceptions are tracked and reviewed at least annually. If the exception results in a material risk, these will be recorded as a Risk under the RMF and managed through the RCSA procedure.

3.3 Risk of Inadequate Information Security Governance

“Our controls protect the confidentiality, integrity and availability of our information assets from threats and are benchmarked against external standards”

3.3.1. The Bank will meet applicable UK Government security requirements. Information Security will provide oversight and assurance, with recommended remediation actions where gaps are identified. The cyber Governance, Risk, and Compliance (GRC) function will validate whether this is so and provide path to green recommendations if required. Service owners are accountable for ensuring their services meet UK Government requirements. The Executive Committee representative of a function is ultimately accountable to the Board for the compliance of services run by their function.

3.3.2. The Bank will maintain Cyber Essentials Plus accreditation or equivalent, to be recertified annually.

  • The Bank will enable Threat Intelligence to proactively identify, assess, and address cyber threats, prioritising critical risks by identifying both active attacks and passive risks such as suspicious activity, indicators of compromise, known malware/ransomware or leaked credentials.

3.3.3. The Bank will align and benchmark our controls against the NIST Cybersecurity Framework, gaining independent assurance through Internal or External Audit or other assessments as required.

3.3.4. Information Security Standards will be reviewed annually and a gap analysis against key systems as identified by Business Impact Analysis completed and reported to Enterprise Risk Committee (ERC).

  • We will maintain awareness of relevant standards as they evolve, provide timely and accurate reporting to stakeholders, and drive any initiatives required to maintain standards alignment.

3.3.5. The Information Security team will provide technical guidance supporting effective control selection, operation, and validation, and the RCSA procedure and Risk Incidents to validate and improve controls.

  • Colleagues must take all reasonable action to verify controls are effective and appropriate, and report when they are not. 
  • Colleagues are expected to diligently utilise and maintain controls, taking necessary steps to ensure their effectiveness. This includes following relevant standards and procedures. Colleagues will propose control improvement actions, addition or removal as identified - particularly after incidents, control failures, or where the controls are not cost-effective.
  • Colleagues must not try to disable or bypass controls and will promptly report any incidents of control failure or attempted bypassing following the risk incident process

3.3.6. Asset and Data Management

All information assets must be inventoried, classified, and assigned an owner. Data must be classified at creation and protected through technical controls (e.g., access controls, encryption).

3.3.7. Identity and Access Management

Access is managed through a Joiner-Mover-Leaver process. Privileged access must be reviewed quarterly. Least privilege and need-to-know principles apply (see section 7 Definition of Terms).

3.3.8. Technology and Infrastructure Security

Systems must meet defined security configuration standards and be protected through layered security controls aligned to CIS benchmarks.

3.3.9. Operations Security

Security monitoring, logging, and vulnerability management must operate continuously. Logs must be retained and reviewed according to defined standards. Vulnerabilities must be remediated within risk-based timelines. Security exceptions will be required for anything exceeding defined SLAs.

3.3.10. Third Party Risk Management

Third-party information security risk must be managed throughout the supplier lifecycle. Suppliers must be risk-assessed before onboarding or renewal, with proportionate due diligence covering the data, systems, access, integrations, resilience dependencies, and services they support. Required security obligations, assurance evidence, and any risk exceptions must be agreed before services commence. Service Owners are accountable for supplier risk and must ensure ongoing monitoring of security performance, control compliance, incidents, material changes, and assurance findings through approved measures. On exit, access must be removed, Bank information returned or securely destroyed, integrations decommissioned, and residual risks recorded and managed.

3.3.11. Security Awareness

Security awareness training must be risk-based and measured through defined KPIs such as phishing resilience and training completion rates.

3.3.12. Compliance and Assurance

Compliance with this policy will be assessed through internal audit, independent assurance, and continuous monitoring. Metrics will be reported to governance forums.

3.4 Risk of Inadequate Information Security processes and procedures

“There is a risk that security processes do not operate as designed and leave the Bank's security vulnerable. We maintain an effective Cyber Incident Response capability. We validate policy and procedural effectiveness through regular exercises and ongoing testing and take corrective action where needed.”

  • Any suspected cyber incident must be reported immediately via an approved reporting channel (including the IT Service Desk and the Risk Incident Portal) and managed through a formal incident response framework. Severity classification and escalation paths must be defined. Examples include having entered credentials after following a link in a phishing email, entering restricted information into an AI tool, or if malicious software is suspected on a laptop.

3.4.1. Any data breach identified through cyber incident response will be escalated to the IT Major Incident Management (MIM) Team for escalation to the Bank’s wider Incident Response Team. The Bank will maintain an effective Security Operations Centre (SOC) and Cyber Incident Response Team (CIRT) with 24x7x365 cover.

  • Failure to report, log, or respond to a notification of a cyber incident may be subject to disciplinary or contractual procedures.

3.4.2. Information Security will maintain a Cyber Incident Response Plan (CIRP). This will be validated on each major incident, or at least annually using ‘stress test’ exercises.

  • The Cyber Incident Response Team (CIRT) Incident Manager will inform all relevant parties of the approved distribution list for each incident.
  • Information relating to an active CIRT incident is classed as Official Sensitive and strictly need-to-know. Do not disclose details of an active cyber incident or forward meeting invites outside of that distribution list.
  • The Information Security Team will actively work to mitigate the incident, including suspected compromised systems. Decision-making authority for disruptive action to core services will be agreed in advance with Executive Committee and documented as part of the Cyber Incident Response Plan (CIRP).
  • Bank device(s) may be required for further analysis and/or account(s) may be locked as part of cyber incident response. Devices and access will be restored as quickly as possible, but not before the incident containment and eradication.
  • Colleagues may be asked to provide accurate information in support of chain of custody documentation.

3.4.3. Incident management: The incident response framework must define severity classification and escalation paths, including decision authority for disruptive containment actions, communications governance, and evidence collection requirements.

3.4.4. IT will maintain hardened systems, both user-facing and back end. The security exposure of Bank systems will be ascertained externally through appropriate penetration tests, to be reviewed by Information Security, managed under the VMF, and with the results reported to Executive Risk Committee.

3.4.5. Logging and monitoring: Minimum logging requirements, retention, protection from tampering, and review activities must be defined in a supporting logging standard. Logs must support detection, investigation, and evidence collection.

4. Non-Compliance

All identified breaches of this policy must be reported via the Risk Incident Portal on the Bank’s Intranet. Breaches will be assessed by the Policy Owner to determine the further action required and may include disciplinary action in accordance with the Bank’s Disciplinary Policy.

5. Emergency and Safety Protocols for Colleagues

Policy Statement:

The Bank enforces strict controls to safeguard company systems and minimise harm from any forced or accidental actions. The safety and wellbeing of all employees is prioritised in situations involving physical threat, coercion, or emergencies, whether within the UK and internationally. All incidents must be reported at the earliest safe opportunity and will be jointly investigated by InfoSec and relevant stakeholders.

Colleague Guidance:

Preserve Life First - In case of immediate danger, colleagues must dial 999 (UK) or the relevant local emergency number and follow any instructions given by the aggressor to prevent escalation.

Corporate Emergency Contacts - Once in a safe location, colleagues must report the incident to their line manager and the IT Service Desk (ITSD) - 020 3880 1630 to receive guidance on further process.

International Assistance - Colleagues travelling abroad must be familiar with local emergency numbers and the nearest British Consulate or High Commission. Additionally, those travelling with corporate devices must pre-register their itinerary through the Bank’s Working Outside UK process.

6. Aligned Frameworks, Policies, Standards, and Procedures

6.1 Supporting Standards

  • Information Classification and Handling Standard
  • Information Security Standards (Approved Draft)
  • AI Standards

6.2 Aligned British Business Bank Standards

  • Data Governance Standard
  • Data Protection Rights Standard
  • IT Outsourcing
  • Records Retention Schedule
  • Risk and Control Self-Assessment Procedure
  • Code of Conduct

6.3 Aligned Frameworks

  • Risk Management Framework
  • Vulnerability Management Framework

6.4 Aligned Policies

  • Business Resilience Policy
  • Data Protection Policy
  • Information Technology Acceptable Use Policy
  • Data and Information Management Policy
  • Supplier Management Policy
  • Learning and Development Policy

6.5 Aligned Information Security Procedures

  • Cyber Incident Response Plan
  • Major Incident Management (MIM)

6.6 Aligned British Business Bank Procedures

  • Freedom of Information Procedure
  • Strategic Recovery and Incident Management Plan
  • System Delivery Lifecycle

7. Definition of Terms

7.1 CIRT (Cyber Incident Response Team)

The Bank’s CIRT is focused on incident response and management after a security incident has occurred. Our CIRT has an incident confidentiality clause; details of cyber incidents are strictly need-to-know. A CIRT is a specialised team that focuses on responding to and managing cybersecurity incidents and breaches. It is responsible for investigating and containing security incidents, coordinating the response efforts, and ensuring the organisation can recover from the incident effectively. The CIRT works closely with various stakeholders, such as IT teams, legal departments, and law enforcement, to gather evidence, perform forensic analysis, and implement necessary remediation measures. The CIRT also plays a role in incident reporting and communication, ensuring that the incident is appropriately addressed, and the necessary actions are taken to prevent future occurrences.

7.2 Least Privilege

A security principle that a system should restrict the access privileges of users (or processes acting on behalf of users) to the minimum necessary to accomplish assigned tasks.

7.3 Need to know

"Need to know" is a principle or concept that limits access to information or resources only to those individuals who require that specific information to perform their duties or tasks effectively.

7.4 Non-Disclosure Agreement

An NDA, or Non-Disclosure Agreement, is a legally binding contract between two or more parties that outlines confidential information they wish to share with each other. The purpose of an NDA is to protect sensitive or proprietary information from being disclosed to unauthorised individuals or parties.

7.5 Phishing

Phishing is a type of cyberattack and social engineering technique in which an attacker attempts to deceive individuals into divulging sensitive information, such as login credentials, passwords, financial details, or personal identification information. The term "phishing" is a play on the word "fishing," as the attacker "fishes" for victims by posing as a legitimate and trustworthy entity in electronic communications.

7.6 Posture Management

A group of proactive activities that together ensure our people and technology are hardened against attack. It includes, managing cyber awareness, proactive Threat Intelligence. Security Engineering, Vulnerability Management, and Penetration Testing of our services.

7.7 Red, Blue, and Purple Team Exercises

A Red Team evaluates, Blue Team defends, and Purple Team combines efforts to strengthen an organisation's cybersecurity defences.

Red Team:

A group of skilled security experts that mimic cyber attackers by attempting to breach defences and identify vulnerabilities. Their goal is to uncover weaknesses and improve overall security.

Blue Team:

Our internal defensive SOC responsible for monitoring and safeguarding our network and systems. The SOC are not informed that the exercise is taking place and during an exercise, they respond to the Red Team's attacks, detect breaches, and mitigate threats.

Purple Team:

A collaborative exercise that brings the Red and Blue Teams together. The objective is to facilitate knowledge sharing and enhance the overall cybersecurity capabilities. The teams work jointly to evaluate and improve defence strategies based on the Red Team's attack tactics and the Blue Team's response effectiveness.

7.8 Security Operations Management

Business as usual activities to keep us secure. These are mostly reactive and include Case /Alert Management, Reactive Threat Intelligence during cyber incident response, Threat Hunting following Threat Intelligence, Due Diligence Questionnaires, and servicing Colleague requests.

7.9 Service

An IT Service used by colleagues, delivery partners, or customers. Examples include the Bank’s Laptops, SharePoint, the Guarantees and Wholesale Portal, and PeopleXD.

7.10 Service Catalogue

A service catalogue is a structured listing of IT services provided by an organisation, making it easy for colleagues to access and understand available services and any associated service responsibilities. It includes service descriptions and levels, helping colleagues make informed decisions. A service catalogue can have different views, for example a view for service consumers might list available service and links to documentation. A view for those responsible for delivering or supporting the services might include roles and responsibilities, and links to technical documentation, related contracts, costs and renewal dates. The catalogue streamlines service delivery, enhances communication, and aids resource allocation, resulting in improved colleague satisfaction.

7.11 Smishing

Smishing (SMS phishing or SMSing) is a type of social engineering cyberattack that involves sending fraudulent text messages (SMS) to deceive and manipulate individuals into revealing sensitive information or performing certain actions. The term "smishing" is a combination of "SMS" (Short Message Service) and "phishing," which is the practice of attempting to obtain sensitive information, such as passwords, financial details, or personal identification, by masquerading as a trustworthy entity in electronic communications.

7.12 SOC (Security Operations Centre)

The Bank’s SOC is our first line of defence, focused on proactive monitoring, detection, and prevention of security incidents. A SOC is responsible for monitoring, detecting, and responding to security incidents within an organization's networks, systems, and applications. The SOC actively monitors and analyses security events and alerts in real-time. The SOC typically employs various security technologies and tools, such as SIEM (Security Information and Event Management) systems, intrusion detection systems, and vulnerability scanning tools. Its primary goal is to maintain the security and integrity of the organisation's infrastructure by identifying and mitigating threats promptly.

7.13 CDT (Cyber Defence Team)

The Cyber Defence team is our second line of defence, focused on investigating escalated security incidents, improving detection capabilities, and supporting proactive security posture across the bank.

In addition, the team is responsible for overseeing vulnerability management, coordinating threat intelligence activities, managing relevant incident responses and supporting security awareness initiatives to strengthen the bank’s overall cyber resilience.

7.14 System

A component or components making up a Service. Examples include storage, compute or networking infrastructure, servers, databases, and applications.

7.15 Vishing

The term "vishing" is a combination of "voice" and "phishing". It is a type of social engineering cyberattack that relies on voice communication, typically over the phone, to deceive and manipulate individuals into revealing sensitive information or performing certain actions.

7.16 Vulnerabilities

Vulnerabilities include exploitable or potentially exploitable weaknesses in software, hardware, and configuration, but also the processes underpinning operation of the Bank’s systems and services.

7.17 Whaling

A form of spear-phishing attack that targets senior leaders or high-ranking officials in government or large organisations. These attacks are highly customised and aim to deceive the target into disclosing sensitive information, authorising financial transactions, or clicking on malicious links that can compromise secure systems.

7.18 RACI matrix

RACI model is a framework used to clarify roles and responsibilities for any model. Responsible - who do the work to complete the task, Accountable - who is ultimately answerable for the task’s success, Consulted - whose input is sought before or during the task, Informed - who are kept up to date on progress or decisions. See appendix B.

Appendix A: Policy Scope Categories

The Bank has defined its use of the terms Employee and Colleague to include the following individuals:

Colleagues
 Employees
Non-executive directors (NEDs)ContractorsTempsProfessional ServicesPermanent Employees (Full or Part time)Fixed term contract employees (FTC)ApprenticesInternsSecondees – outSecondees – inBoard Members (executive directors)

Appendix B – Simplified Responsibility, Accountability, Consulted and Informed (RACI) matrix

The below table outlines key responsibilities across the Bank for maintaining cybersecurity and protecting data, mapped using a simplified RACI matrix (Responsible, Accountable, Consulted) model.

ActivityAll ColleaguesLine ManagersService OwnersIT Ops
Following day-to-day security practicesRA C
Using strong passwords and MFARA C
Reporting security incidents or phishingRA C
Protecting and classifying sensitive dataR RR
Manage access to services or systems  AR
Securing third-party and supplier integrations  ARead footnote text 1 C
Using approved collaboration/storage toolsRACR
Patching systems and applying updates  AR
Conducting vulnerability assessments   R/A
Implementing security controls  AR
Security policy governance and updates   R/A
End-user security training and awarenessRA C
Incident response and breach handlingR CA
BYOD and mobile security enforcementRR A
Ensure vendors meet security expectations  AC
Maintain and update security policies   R/A
Secure devices during remote workingRA R
  • Return to footnote location 1

    Vendors and third-party solution providers are responsible for implementing and maintaining appropriate security controls as specified within their contractual agreements. This includes timely communication of security incidents, provision of evidence for compliance with security requirements, supporting security assessments or audits as necessary, and prompt application of security patches and updates. Service Owners are responsible for ensuring that these responsibilities are clearly defined in contracts and actively monitored in collaboration with IT Operations to maintain compliance and safeguard service integrity.

Do you have a Freedom of Information Act (FOIA) request?

View our archive of previously answered Freedom of Information Act enquiries or use our contact us form to submit your own.