NHS DSP toolkit is an abbreviation for the ‘NHS Data Security and Protection Toolkit’. An online self-assessment tool that allows organisations to measure their performance against the National Data Guardian’s 10 data security standards.
Get Your 'Vulnerability Management Template' FREE!
Your Vulnerability Management Template Includes:
Secure your organisation today by completing the form for your Vulnerability Management Template.
Download the, 'How to secure Microsoft Office Desktop Deployments Technical Guide' - FREE
Complete the form to download your free technical guide and secure your organisation today.
Download the Cyber Essentials Template Policy Pack - FREE
Complete the form to download your FREE Cyber Essentials Template Pack today, including:
Download the Microsoft 365 Security Guide - FREE
Complete the form to download your FREE Microsoft 365 Security Guide today, including:
Sign up on the form and receive the guide instantly.
NHS DSP toolkit is an abbreviation for the ‘NHS Data Security and Protection Toolkit’. An online self-assessment tool that allows organisations to measure their performance against the National Data Guardian’s 10 data security standards.
The 10 standards are:
Firstly, you need to register your organisation. After registration, you will then create your organisations’ profile.
When creating your profile look to the elements marked as ‘Mandatory’. These will vary depending on how your organisation is categorised, so take extra care when selecting this option. The example registration page shown is taken from the profile creation process.
There are essentially 3 levels within the NHS DSP Toolkit, these are ‘Approaching Standards’, ‘Standards Met,’ and 'Standards Exceeded'.
The level of 'Standards Exceeded' should be the target for all organisations when certifying against the NHS Data Security and Protection Toolkit. It is reserved for those that achieve 'Standards Met' and hold a current Cyber Essentials PLUS certification.
NHSmail is the national secure collaboration service for health and social care in England. As a minimum, an organisation will need to have ‘Approaching Standards’ to access NHSmail.
Let’s take a bit of a closer look into one of the 10 Standards, specifically Standard 9, IT Protections.
The Independent Assessment Framework, for this standard states:
“A strategy is in place for protecting IT systems from cyber threats which is based on a proven cyber security framework such as Cyber Essentials. This is reviewed at least annually.”
Within this standard are several assertions. These are:
Assertion 1 - All networking components have had their default passwords changed.
Assertion 2 - A penetration test has been scoped and undertaken.
Assertion 3 - Systems which handle sensitive information or key operational services shall be protected from exploitation of known vulnerabilities.
Assertion 4 - You have demonstrable confidence in the effectiveness of the security of your technology, people, and processes relevant to essential services.
Assertion 5 - You have a data security improvement plan with agreed implementation dates.
Assertion 6 - You securely configure the network and information systems that support the delivery of essential services.
One of the main motivations for the standard's creation was to ensure that the NHS's supply chains are as secure as possible. To this end the standard asks:
“Do your organisation’s IT system suppliers have cyber security certification?”
The detail supporting the question lets us know that the following are ways your IT suppliers can demonstrate this:
· Having a Cyber Essentials certificate
· Have an ISO27001 certificate
A Cyber Essentials certificate comes at 2 levels - Cyber Essentials and Cyber Essentials Plus.
There have been some changes to the Cyber Essentials standard in 2022. To help with the changes we have recorded a brief webinar covering everything you need to know.
The page also contains other useful information related to Cyber Essentials, including our Cyber Essentials Readiness Quiz. The quiz is a self-assessed Gap Analysis to give you an idea of how ready your organisation is for Cyber Essentials certification.
View both here: Cyber Essentials
You should have submitted an assessment by the deadline of 30 June.
Don’t worry about having all your information to hand the first time you submit DSPT. You can skip back and forth as you work through the portal.
All of your responses in the portal will be saved so you can come back and continue later. There is also no specific order you need to follow when completing your submission, just as long as it’s completed in full. You can even involve as many people as you need to make sure it's right.
If you require assistance with any component of the DSP toolkit, please contact us.
Precursor Security is a Cyber Essentials certification body and a CREST registered company. We can assist with a variety of toolkit components, such as proof of penetration testing and vulnerability scanning.
Choose Precursor Security for penetration testing excellence—where industry-leading expertise, CREST accreditation, and a client-focused approach converge to fortify your digital defences with precision and reliability.
We have a CREST accredited Security Operations Centre and all of our penetration testers are CREST certified.
We are accredited to the highest of standards including CREST, ISO27001, ISO9001 and Cyber Essentials Plus.
Our experts have a combined experience of over 30 years delivering security operations to sectors such as healthcare, financial services, aerospace and more.
It’s important to know what you’re getting, what’s not included and what else is available. This starts with understanding a SOC and it’s critical functions. CREST has recently published a guide to the critical functions of a SOC which aligns with the CREST SOC standard.
Enter your details here and to get the complete guide instantly sent to your inbox.
Choose Precursor Security for penetration testing excellence—where industry-leading expertise, CREST accreditation, and a client-focused approach converge to fortify your digital defences with precision and reliability.
We have a CREST accredited Security Operations Centre and all of our penetration testers are CREST certified.
We are accredited to the highest of standards including CREST, ISO27001, ISO9001 and Cyber Essentials Plus.
Our experts have a combined experience of over 30 years delivering security operations to sectors such as healthcare, financial services, aerospace and more.
Precursor Security
Welcome to Precursor Security, where the forefront of cybersecurity and penetration testing expertise meets unmatched dedication and innovation. We are the architects of robust digital defences, committed to safeguarding the online realm.