Skip to content

policy

Terminology

Term Meaning / Application
Must This term is used to state a mandatory requirement of this policy
Should This term is used to state a recommended requirement of this policy
May This term is used to state an optional requirement of this policy

Purpose

The purpose of this policy is...

Scope

SCOPE

Responsibility

RESPONSIBILITIES

Responsible Accountable Consulted Informed (RACI) matrix

Tasks ROLE ROLE2 ROLE3
TASK R A C

Other responsible owners

Exceptions

Exceptions to this policy are likely to occur. Request for exceptions may include XXXXX.

Exception requests must be made in writing to the team mailbox (XXXX@education.gov.uk) and must contain:

  • the reason for the request
  • risk to the department of not following the policy
  • specific mitigations that will not be implemented
  • technical and other difficulties in applying patches
  • date of review

The team should also try and obtain confirmation from the Senior Responsible Officer (SRO) and Service Owner that the has been approved and has been added to the Services Risk Register (where maintained).

Policy

Policy section

Revision history and decision records

Revision table

Date of change Author Review Date Version
YYYY-MM-DD FULL_NAME YYYY-MM-DD (+1 year) v0.1

Approved by

Name Title Date Version
FULL_NAME TITLE YYYY-MM-DD v0.1

Policy updates and decision record

Decision Reason for decision Author (Job title) Date
DECISION REASON AUTHOR (JOB_TITLE) YYYY-MM-DD

Appendix A: Glossary

Term Meaning in this context
TERM MEANING

Appendix B: Centre for Internet Security (CIS) safeguards mapping