Skip to content

Commit 279453a

Browse files
authored
Emma 2i requested changes:
- add and change link to sandbox environments - Change 'lead in line' for details component in step 9 - replace(s) from device(s) - rephrase bullets in step 9 'Prove you have developed your integration securely' to statements instead of questions
1 parent a0ca955 commit 279453a

File tree

2 files changed

+17
-17
lines changed

2 files changed

+17
-17
lines changed

docs/pages/get-started/get-started.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,4 +29,4 @@ We'll contact you within 10 working days to find out more about what your servic
2929

3030
Due to our current service capacity and features, you may have to wait before you can continue onboarding. We’re working hard to increase the scale of our service.
3131

32-
[Learn how to onboard with NHS Notify]({% link pages/get-started/onboard-with-notify.md %})
32+
[Learn how to onboard with NHS Notify]({% link pages/get-started/onboard-with-notify.md %}).

docs/pages/get-started/onboard-with-notify.md

Lines changed: 16 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ You can use NHS Notify if your programme or service:
3434

3535
You'll need to integrate with [NHS Notify API]({% link pages/using-nhs-notify/api.md %}) or [NHS Notify MESH]({% link pages/using-nhs-notify/mesh.md %}) to send messages. You may need a developer or a technical team to do this.
3636

37-
If you want to try NHS Notify API, use our sandbox environments.
37+
[Try NHS Notify API by using our sandbox environments](https://god.gw.postman.com/run-collection/28740466-ec078d1e-d4d7-4460-92b9-7d79d51f967a?action=collection%2Ffork&source=rip_markdown&collection-url=entityId%3D28740466-ec078d1e-d4d7-4460-92b9-7d79d51f967a%26entityType%3Dcollection%26workspaceId%3D3664098f-4f8b-4edf-874d-ed33e1eea8ed).
3838

3939
## 1. Register your interest
4040

@@ -164,39 +164,39 @@ This stage covers the technical requirements your service or organisations needs
164164
You will need to:
165165

166166
{% include components/details.html
167-
heading='Show that it meets NHS Notify’s technical conformance requirements'
168-
text='Your service will need to accept that it is responsible for:
167+
heading='Show you can meet NHS Notify’s technical conformance requirements'
168+
text='Your organisation or service will need to accept that it's responsible for:
169169

170170
- using the correct processes to identify the recipients of messages you plan to send
171171
- authoring and proofing the content of messages
172172
- managing the volume of messages it sends so it does not exceed any previously agreed amounts
173173

174-
You will also need to confirm that you have successfully completed integration testing with NHS Notify.'
174+
You also need to confirm that you have successfully completed integration testing with NHS Notify.'
175175
%}
176176

177177
{% include components/details.html
178178
heading='Prove you have developed your integration securely'
179-
text='Your service should be designed, developed and deployed in a way that minimises and mitigates threats to its security.
179+
text='Your organisation or service should be designed, developed and deployed in a way that minimises and mitigates threats to its security.
180180

181181
Overall, you will need to evidence that your organisation or service:
182182

183183
- has a System Level Security Policy (SLSP) in place
184184
- aligns with NCSC Secure development and deployment guidance
185185
- adheres to the 10 data security standards – Security Self Assessment
186186

187-
To prove that your service has developed securely, we ask for information and evidence around the following topics.
187+
To prove that your integration has been developed securely, we ask for information and evidence on the following topics.
188188

189189
### People
190190

191-
Do the staff and people operating your organisation or service:
191+
The staff and people operating your organisation or service need to:
192192

193193
- commit to handle information respectfully and safely, according to the Caldicott Principles
194194
- understand their responsibilities under the National Data Guardian’s Data Security Standards
195195
- complete appropriate annual data security training and pass mandatory tests provided through the DSPT
196196

197197
### Processes
198198

199-
Does your organisation or service:
199+
Your organisation or service must:
200200

201201
- ensure personal confidential information is only accessible by required staff and is attributable to individuals
202202
- complete annual reviews to prevent instances where data security is compromised
@@ -205,27 +205,27 @@ Does your organisation or service:
205205

206206
### Technology
207207

208-
Does your organisation or service have proof that:
208+
Your organisation or service must:
209209

210-
- it only uses supported operating systems, software or browsers within its IT estate
211-
- a strategy is in place to protect IT systems from cyber threats
212-
- processes and procedures are in place to deal with security incidents resultant of cyber attacks
213-
- any third party IT suppliers are contractually accountable for protecting personal confidential data that they process and meet National Data Guardian’s Data Security Standards
210+
- only use supported operating systems, software or browsers within its IT estate
211+
- have a strategy is in place to protect IT systems from cyber threats
212+
- have processes and procedures are in place to deal with security incidents resultant of cyber attacks
213+
- prove third party IT suppliers are contractually accountable for protecting personal confidential data that they process and meet National Data Guardian’s Data Security Standards
214214

215215
### Data in transit protection
216216

217-
Does your organisation or service confirm that data in transit is:
217+
Your organisation or service must confirm that data in transit is:
218218

219219
- encrypted by default, including sensitive data in transit
220-
- protected between your end-user device(s) and your service
220+
- protected between your end-user devices and your service
221221
- protected between internal components within the service
222222
- protected where exposed to other external service, for example, via an API
223223

224224
### Identity and authentication
225225

226226
Access to service interfaces should be constrained to authenticated and authorised individuals.
227227

228-
Does your organisation or service confirm that:
228+
Your organisation or service must confirm that:
229229

230230
- access to internal and external interfaces is authenticated
231231
- it has processes to manage the lifecycle of service credentials

0 commit comments

Comments
 (0)