About Defence

Defence Security and Assurance Services - Defence Industry/List X

Defence Security & Assurance Services (DSAS), Defence Industry IT Accreditation.

Until January 2007 the accreditation of Defence Industry IT systems was originally undertaken by the Security Services under the List-X process. Since then, Defence Security and Assurance Services (DSAS) expanded to include the accreditation of Defence Industry and now work with over 150 defence partners.

Our key responsibilities are:

  • the formal Accreditation of Defence Industry IT Systems which store, process or forward HMG (MOD) information
  • to provide general Information Assurance advice
  • and provide guidance in line with the Data Protection Act 1998 to adequately safeguard MOD personal data held in industry

Accreditation is defined in HMG Information Assurance Standard No 2 (IAS2) as "...an independent assessment that an information system meets its IA requirements and that the residual risks, in the context of the business requirement, are acceptable to the business".

Information Assurance is delivered through the assessment of information in relation to:-

  • Confidentiality - The property that information is not made available or disclosed to unauthorised individuals, entities, or processes
  • Integrity - The property of safeguarding the accuracy and completeness of assets. This may include the ability to prove an action or event has taken place, such that it cannot be repudiated later
  • Availability - The property of being accessible and usable upon demand by an authorised entity

The process involves the formal assessment of residual risk to the information culminating in the creation and approval of a Risk Management and Accreditation Document Set (RMADS) as described in IAS2.

Systems should be developed based on the guidance and good practice offered by CESG, the UK's National Technical Authority for Information Assurance. CESG produce Information Assurance Standards, Memoranda, Manuals and Security Procedures which underpin the Security Policy Framework (SPF) based upon identified threats and vulnerabilities across a range of technologies.

The DSAS Industry Team have an Accreditation responsibility for all systems storing, processing or forwarding information at CONFIDENTIAL and above (List-X) and all those systems at RESTRICTED which connect to other Government Networks.

Where Defence Equipment and Support (DE&S) and Industry Security Services (ISS) provide the physical assurances to the List-X process by assessing the Global and Local Security Environments (GSE and LSE), we are responsible for the security of the data within the Electronic Security Environment (ESE).

Despite having a defined scope of responsibility, we will always offer guidance and support to Defence Industry in relation to Information Security and Assurance on all IT systems storing HMG (MOD) information.

If you wish to know more about our services, please contact us using the links to the right.






Contact details

DSAS

Rm F310, Bldg 351

RAF Brampton

Huntingdon

Cambs

PE28 2EA


DSAS Point of Contact: 01480 425381
Contact us by email
(This email is for unclassified mail only)

Page rated 11 times
This page has an average rating of 4/5