Search results for ‘legislation as code’
-
3. Integrate security and privacy proportionate to risk from the outset
Found in Standards & guidance / Digital Service Design Standard / Current principles / 3. Integrate security and privacy proportionate to risk from the outset
Consider the user and business context when applying access and security classifications.
Evaluate security risk and privacy obligations and apply the necessary treatments at source.
Identify the data and information the digital service will be providing or storing and address the security level, legal responsibilities, privacy issues and risks associated with the service (consulting with experts where appropriate).
Try to make the appropriate consideration of privacy and security an ongoing par… -
Catalogue approved services
Found in Standards & guidance / Technology and architecture / Cloud services / Cloud plans / Shadow cloud / Manage shadow cloud in your organisation / Catalogue approved services
Set up or update your organisation’s catalogue of approved public cloud services.
-
GEA-NZ dimension: Strategy, investment and policy
Found in Standards & guidance / Technology and architecture / Enterprise architecture / GEA-NZ framework / Dimensions of the GEA-NZ framework / GEA-NZ dimension: Strategy, investment and policy
Government strategy, investment prioritisation and policy evolution are drivers of change in the public sector, along with continuous change driven by customers and the environment.
-
Legally binding agreements
Found in Standards & guidance / Information sharing standard / Legally binding agreements
Learn about legally binding agreements and existing or planned contracts when implementing the information sharing standard.
-
Run a workshop with stakeholders
Found in Standards & guidance / Privacy, security and risk / Risk management / Risk assessments for government organisations / Identify the risks / Run a workshop with stakeholders
Running a workshop with the key stakeholders of the information system allows you to more accurately identify its risks.
-
Security
Found in Standards & guidance / Privacy, security and risk / Security
All government-held information requires appropriate protection. Government agencies must consider the nature and value of the information they’re managing and the measures needed to protect it.
-
Security and GenAI
Found in Standards & guidance / Technology and architecture / Artificial intelligence (AI) / Responsible AI Guidance for the Public Service: GenAI / GenAI foundations / Security
Learn about the key security risks of introducing GenAI to your organisation. Develop a list of considerations to ensure GenAI software undergoes basic security measures.
-
Digital Investment Office
Found in Standards & guidance / Governance / Digital investment / Digital Investment Office
The Digital Investment Office supports the Government Chief Digital Officer and works with the Treasury and other public sector system leaders to achieve government-wide strategies and outcomes for digital investment.
-
Why DPUP has a Transparency and Choice Guideline
Found in Standards & guidance / Privacy, security and risk / Privacy / Data Protection and Use Policy (DPUP) / Read the DPUP Guidelines / Transparency and Choice Guideline / Why DPUP has a Transparency and Choice Guideline
Help people understand why and how providing personal information can help them or people in similar circumstances, if providing some information is optional, and their rights to access or request changes.