We use some essential cookies to make our website work. We’d like to set additional cookies so we can remember your preferences and understand how you use our site.
You can manage your preferences and cookie settings at any time by clicking on “Customise Cookies” below. For more information on how we use cookies, please see our Cookies notice.
Your cookie preferences have been saved. You can update your cookie settings at any time on the cookies page.
Your cookie preferences have been saved. You can update your cookie settings at any time on the cookies page.
Sorry, there was a technical problem. Please try again.
This site is a beta, which means it's a work in progress and we'll be adding more to it over the next few weeks. Your feedback helps us make things better, so please let us know what you think.
Freedom of Information (FOI) Act request ref: 01/FOI/24/006825/Z
Version Date: 28/11/2024
The ICT Department and the Professional Standards Department have provided the following information.
1 What auditing systems are currently in place for your existing SaaS solutions?
Each SaaS solution is separate and has it’s own auditing requirements commensurate with the value of the data held.
2 Is your preference that audit logs from new solutions plugin to your organisations existing auditing solutions? And if so what solutions are you using?
Each system has its own individual auditing solution.
3 What are the key compliance requirements for your SaaS applications from an auditing perspective?
Audit requirements for applications are based on the value of the data held rather than the hosting platform used.
4 Do you require any specific audit logs or reports from your SaaS solutions?
No.
5 How do you handle audit trails for your SaaS solutions?
Each SaaS solution is separate and has it’s own auditing requirements commensurate with the value of the data held.
6 What are the technical requirements or standards for integrating a new SaaS solution with your existing auditing systems?
No current requirement for integration of SaaS audit logging with existing auditing / SIEM solution, but if there was the technical requirement would be to use industry standard mechanisms such as SYSLOG>.
7 Are there any specific security or data protection features that you require in a SaaS solution to comply with your auditing requirements?
No, each SaaS solution has it’s own auditing requirements commensurate with the value of the data held.