You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- add and change link to sandbox environments
- Change 'lead in line' for details component in step 9
- replace(s) from device(s)
- rephrase bullets in step 9 'Prove you have developed your integration securely' to statements instead of questions
Copy file name to clipboardExpand all lines: docs/pages/get-started/get-started.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -29,4 +29,4 @@ We'll contact you within 10 working days to find out more about what your servic
29
29
30
30
Due to our current service capacity and features, you may have to wait before you can continue onboarding. We’re working hard to increase the scale of our service.
31
31
32
-
[Learn how to onboard with NHS Notify]({% link pages/get-started/onboard-with-notify.md %})
32
+
[Learn how to onboard with NHS Notify]({% link pages/get-started/onboard-with-notify.md %}).
Copy file name to clipboardExpand all lines: docs/pages/get-started/onboard-with-notify.md
+16-16Lines changed: 16 additions & 16 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -34,7 +34,7 @@ You can use NHS Notify if your programme or service:
34
34
35
35
You'll need to integrate with [NHS Notify API]({% link pages/using-nhs-notify/api.md %}) or [NHS Notify MESH]({% link pages/using-nhs-notify/mesh.md %}) to send messages. You may need a developer or a technical team to do this.
36
36
37
-
If you want to try NHS Notify API, use our sandbox environments.
37
+
[Try NHS Notify API by using our sandbox environments](https://god.gw.postman.com/run-collection/28740466-ec078d1e-d4d7-4460-92b9-7d79d51f967a?action=collection%2Ffork&source=rip_markdown&collection-url=entityId%3D28740466-ec078d1e-d4d7-4460-92b9-7d79d51f967a%26entityType%3Dcollection%26workspaceId%3D3664098f-4f8b-4edf-874d-ed33e1eea8ed).
38
38
39
39
## 1. Register your interest
40
40
@@ -164,39 +164,39 @@ This stage covers the technical requirements your service or organisations needs
164
164
You will need to:
165
165
166
166
{% include components/details.html
167
-
heading='Show that it meets NHS Notify’s technical conformance requirements'
168
-
text='Your service will need to accept that it is responsible for:
167
+
heading='Show you can meet NHS Notify’s technical conformance requirements'
168
+
text='Your organisation or service will need to accept that it's responsible for:
169
169
170
170
- using the correct processes to identify the recipients of messages you plan to send
171
171
- authoring and proofing the content of messages
172
172
- managing the volume of messages it sends so it does not exceed any previously agreed amounts
173
173
174
-
You will also need to confirm that you have successfully completed integration testing with NHS Notify.'
174
+
You also need to confirm that you have successfully completed integration testing with NHS Notify.'
175
175
%}
176
176
177
177
{% include components/details.html
178
178
heading='Prove you have developed your integration securely'
179
-
text='Your service should be designed, developed and deployed in a way that minimises and mitigates threats to its security.
179
+
text='Your organisation or service should be designed, developed and deployed in a way that minimises and mitigates threats to its security.
180
180
181
181
Overall, you will need to evidence that your organisation or service:
182
182
183
183
- has a System Level Security Policy (SLSP) in place
184
184
- aligns with NCSC Secure development and deployment guidance
185
185
- adheres to the 10 data security standards – Security Self Assessment
186
186
187
-
To prove that your service has developed securely, we ask for information and evidence around the following topics.
187
+
To prove that your integration has been developed securely, we ask for information and evidence on the following topics.
188
188
189
189
### People
190
190
191
-
Do the staff and people operating your organisation or service:
191
+
The staff and people operating your organisation or service need to:
192
192
193
193
- commit to handle information respectfully and safely, according to the Caldicott Principles
194
194
- understand their responsibilities under the National Data Guardian’s Data Security Standards
195
195
- complete appropriate annual data security training and pass mandatory tests provided through the DSPT
196
196
197
197
### Processes
198
198
199
-
Does your organisation or service:
199
+
Your organisation or service must:
200
200
201
201
- ensure personal confidential information is only accessible by required staff and is attributable to individuals
202
202
- complete annual reviews to prevent instances where data security is compromised
@@ -205,27 +205,27 @@ Does your organisation or service:
205
205
206
206
### Technology
207
207
208
-
Does your organisation or service have proof that:
208
+
Your organisation or service must:
209
209
210
-
-it only uses supported operating systems, software or browsers within its IT estate
211
-
- a strategy is in place to protect IT systems from cyber threats
212
-
- processes and procedures are in place to deal with security incidents resultant of cyber attacks
213
-
-any third party IT suppliers are contractually accountable for protecting personal confidential data that they process and meet National Data Guardian’s Data Security Standards
210
+
- only use supported operating systems, software or browsers within its IT estate
211
+
-have a strategy is in place to protect IT systems from cyber threats
212
+
-have processes and procedures are in place to deal with security incidents resultant of cyber attacks
213
+
-prove third party IT suppliers are contractually accountable for protecting personal confidential data that they process and meet National Data Guardian’s Data Security Standards
214
214
215
215
### Data in transit protection
216
216
217
-
Does your organisation or service confirm that data in transit is:
217
+
Your organisation or service must confirm that data in transit is:
218
218
219
219
- encrypted by default, including sensitive data in transit
220
-
- protected between your end-user device(s) and your service
220
+
- protected between your end-user devices and your service
221
221
- protected between internal components within the service
222
222
- protected where exposed to other external service, for example, via an API
223
223
224
224
### Identity and authentication
225
225
226
226
Access to service interfaces should be constrained to authenticated and authorised individuals.
227
227
228
-
Does your organisation or service confirm that:
228
+
Your organisation or service must confirm that:
229
229
230
230
- access to internal and external interfaces is authenticated
231
231
- it has processes to manage the lifecycle of service credentials
0 commit comments