Guidance

DWP procurement: security policies and standards

These apply to DWP suppliers and contractors where explicitly stated in the security schedule of the contract.

Documents

Acceptable Use policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Information Management policy

Information Security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Personnel Security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Physical Security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Cryptographic Key Management policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Email policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Forensic Readiness policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Microsoft Teams recording and transcription policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Privileged Users Security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Protective Monitoring Security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Remote Working Security policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security Classification policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

SMS Text policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Social Media policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Technical Vulnerability Management policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

User Access Control policy

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Placeholder: Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard: Physical and Electronic Security (part 1)

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-001 (part 1): Access and Authentication Controls

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-001 (part 2): Privileged User Access Controls

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-002: Public Key Infrastructure & Key Management

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-003: Software Development

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-005: Database Management System

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-006: Security Boundaries

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-007: Use of Cryptography

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-008: Server Operating System

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-009: Hypervisor

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-010: Desktop Operating System

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-011: Containerisation

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-012: Protective Monitoring Standard

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-013: Firewall Security

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-014: Security Incident Management

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-015: Malware Protection

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-016: Remote Access

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-017: Mobile Device

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-018: Network Security Design

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-019: Wireless Network

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-022: Voice and Video Communications

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-023: Cloud Computing

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-025: Virtualisation

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-028: Microservices Architecture

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security standard SS-029: Securely Serving Web Content

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security Standard SS-031: Domain Management

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security Standard SS-033: Security Patching

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security Standard SS-035: Backup and Recovery

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Security Standard SS-036: Secure Sanitisation and Destruction

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email accessible.formats@dwp.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Details

The Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers is under review. You should refer to Good Practice Guides 45 and 44 instead.

Note, the Department for Work and Pensions (DWP) is unable to reply to general enquiries or questions about these security standards and policies.

These security standards and policies apply to DWP suppliers and contractors only. They do not apply to other government departments, their agencies or arm’s length bodies.

They have been published to help inform DWP Invitations to Tender and other contracting processes.

DWP may choose in an Invitation to Tender or the bid process to reference the standards and policies published here. Questions about a specific standard or policy should be sent to the DWP team managing responses to bids. This team is the only DWP authorised responder on any question about a bid and a standard or policy.

A new or changed policy or standard does not mean a new requirement for any existing contract. DWP will notify contract holders or partners of any changes to a contract.

Suppliers and contractors should contact their DWP contract managers with any questions about:

  • varying contracts
  • changing the agreed delivery of contracted services
  • the applicability of a standard or policy for their contracts
Published 9 April 2018
Last updated 7 March 2024 + show all updates
  1. Published updated DWP Security Classification Policy.

  2. The email policy has been updated to the latest version.

  3. Acceptable Use policy updated to include amendments around use of public Vs Private AI and also amendments around use of Non-Corporate Communication Channels.

  4. Replaced the User Access Control Policy. Updated guidance on password management to advise users must change their passwords on indication or suspicion of compromise.

  5. Removed Security standard SS-030: Oracle Database Security because it is out of date. The guidance is now included in Security standard SS-005: Database Management Systems.

  6. Updated Security standard SS-018: Network Security Design and removed out of date Security standard SS-027: Application Security Testing.

  7. Updated DWP Security standard SS-013: Firewall Security, Security standard SS-023: Cloud Computing and Security standard SS-028: Microservices Architecture (version 2).

  8. Published updated security standards: SS-001 (part 1): Access and Authentication Controls; SS-001 (part 2): Privileged User Access Controls; SS-014: Security Incident Management; SS-029: Securely Serving Web Content; SS-036: Secure Sanitisation and Destruction.

  9. Updated the DWP Email policy.

  10. Security Standard SS-035: Backup and Recovery attachment published in error, replaced with correct version.

  11. Updated 'Security Standard SS-035: Backup and Recovery' attachment.

  12. Added revised versions of Security standard SS-003: Software Development and SS-005: Database Management Systems.

  13. Added Security standard SS-014: Security Incident Management.

  14. Added revised version of Security Standard SS-033: Security Patching.

  15. New 'Security Standard (SS-035): Backup and Recovery' added. Updated 'Security standard SS-008: Server Operating System'. Deleted 'Security standard SS-014: Security Incident Management' and 'Form: Security incident response team referral (for Security standard SS-014: Security Incident Management)'.

  16. Updated Security standards SS-009 Hypervisor, SS-022: Voice and Video Communication and SS-025: Virtualisation (the new versions are labelled version 2.0 and dated 27/04/2023).

  17. Updated the Technical Vulnerability Management policy.

  18. Updated Security standard SS-002: Public Key Infrastructure & Key Management, SS-010: Desktop Operating System and SS-031: Domain Management.

  19. Updated Security standards SS-017: Mobile Device and SS-019: Wireless Network.

  20. Updated security standard SS-15: Malware protection.

  21. Added a new version of the Remote Working Security policy. Updated paragraph 3.3 and 7.5 of the Acceptable Use policy.

  22. Published a revised version of the DWP Acceptable Use Policy (the new version is still labelled version 3). Published a revised version of DWP Security standard SS-006: Security Boundaries (the new version is labelled version 2 and dated 16/01/2023), and a revised version of Security standard SS-016: Remote Access (the new version is labelled version 2 and dated 16/01/2023).

  23. Published a revised version of DWP Security Standard SS-007: Use of Cryptography (the new version is labelled version 2.0, dated 07/12/2022) and DWP Security Standard SS-033: Security Patching (the new version is labelled version 2.0, dated 07/12/2022).

  24. Published a revised version of the Security standard: Physical and Electronic Security (part 1) - the new version is labelled version 1.1, dated 16/11/2022.

  25. Added the DWP policy for Protective Monitoring Security (version 1). This is for the use of DWP suppliers and contractors only.

  26. Published a revised version of the Security Standard SS-012: Protective Monitoring Standard (the new version is labelled version 2.0, dated 11/10/2022). Also published a new standard - Security Standard SS-036: Secure Sanitisation and Destruction (this new standard is labelled version 1, dated 11/10/2022).

  27. Published a revised version of the DWP Security Standard – Containerisation (SS-011) (the new version is labelled version 2.0, dated 22/08/2022).

  28. Revised version of the DWP Microsoft Teams recording and transcription policy (the new version is labelled version 1.5, dated 22/09/22).

  29. Revised version of DWP Physical Security Policy (new version is labelled version 2.1). Also published a new standard - Security standard: Physical and Electronic Security (part 1) (this new standard is labelled version 1).

  30. Revised version of DWP Acceptable Use Policy (new version is labelled version 3).

  31. Revised version of DWP Personnel Security Policy (new version is labelled version 2).

  32. Revised version of Security Standard SS-031: Domain Management (new version is labelled version 1.2 and dated December 2021).

  33. Added the DWP policy for Microsoft Teams Recording and Transcription. This is for DWP suppliers and contractors only.

  34. Revised version of Social Media policy (new version is labelled version 2).

  35. Added Personnel Security policy for DWP suppliers and contractors.

  36. Revised version of Security Standard SS-033: Security Patching (new version is labelled version 1.3 and dated January 2021).

  37. Revised version of Security Standard SS-033: Security Patching (now labelled version 1.2).

  38. Revised version of Security standard SS-016: Remote Access (now labelled version 1.2). Typo correction in entry 10.3.2, from ‘Authority’ to ‘Contractor’.

  39. Published revised version of Security incident response team referral form for Security standard SS-014. The revised form is dated 3 June 2020.

  40. Added the following 10 DWP policies: Cryptographic Key Management Policy, Email Policy, Forensic Readiness Policy, Privileged Users Security Policy, Remote Working Security Policy, Security Classification Policy, SMS Text Policy, Social Media Policy, Technical Vulnerability Management Policy and User Access Control Policy.

  41. Published updated versions of the DWP security standards. All are now dated March 2020, except standard SS-014 which is dated 4/3/2020. These have been revised to reflect changes in DWP processes, laws, and national and international security standards and practices.

  42. Added DWP Security Standard SS-033: Security Patching.

  43. Removed the Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers document. This document is currently under review.

  44. Revised versions of the Acceptable Use (version 2.5) and Physical Security (version 2) policies.

  45. Revised versions of 'Security Standard - Firewall Security (SS-013)' and 'Security Standard - Network Security Design (SS-018)'. Both are now dated 9 April 2019.

  46. Added 'Common Standards for Identity Verification and Authentication (CSIVA) of DWP customers' (version 1.7).

  47. Published revised version of Security standard SS-003: Software Development (now version 1.1, dated 07/10/2018).

  48. Published revised versions of Acceptable Use (version 2.5), Information Security (version 1) and Physical Security (version 1) policies.

  49. Added 'Security standard SS-012: Protective Monitoring Standard'.

  50. Added 'Security standard SS-001 (part 2): Privileged User Access Controls'.

  51. First published.