
NHS Data Security and Protection Toolkit Standard v7
Since September 2024, DSPT V7 NHS has adopted a more flexible, outcomes-based approach aligned with the principles of the Cyber Assessment Framework (CAF) developed by the National Cyber Security Center (NCSC).
The CAF is structured around four overarching security objectives, each supported by a set of cybersecurity principles:
01
What is DSPT?
The DSP Toolkit Standard is a National Health Service standard. All organisations that have access to NHS patient data and systems must use the DSP Toolkit to provide assurance that they are practising good data security and that personal information is handled correctly. Such organisations are required to carry out self-assessments of their compliance against the assertions and evidence contained within the DSP Toolkit.
02
More Details...
New changes: DSPT V7 and CAF​
​
The CAF is structured around four overarching security objectives, each supported by a set of cybersecurity principles:
Objective A: Managing Security Risk focuses on governance, risk management, asset management, and supply chain security at the organisational level.
Objective B: Protecting against Cyber Attacks zeroes in on policies, processes, access control, data security, system security, resilient networks, and systems, ensuring robust defences at the system level.
Objective C: Detecting Cyber Security Events outlines the necessity for security monitoring and proactive security event discovery, emphasising system-specific vigilance.
Objective D: Minimising the Impact of Cyber Security Incidents addresses incident response, recovery planning, and lessons learned, targeting organisational resilience.
Organisations will be required to assess themselves via two profiles - baseline and enhanced - depending on their relative cyber risk exposure. ITFORDENTAL can help you wish the assessment and complete required work to become DSPT v7 compliant.
03
How can we help?
Our highly exerienced technical professionals will visit the practice and prepare information which are requried to submit for the toolkit. We can also submit the toolkit on your behalf.
​
With the help of NHS Digital, GDC and ICO resources we have prepared set of documents that are mandatory requriements and must be maintained by a dental practice.
​
We can assist the practice in setting up for GDPR once which can later be matainted by the team locally or we can continue to help.