Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 Data Management Planning for Secure Services (DMP-SS) † Tito Castillo,


Similar presentations
Grey Literature, Institutional Repositories and the Organisational Context Simon Lambert, Brian Matthews & Catherine Jones Business & Information Technology.

Module N° 4 – ICAO SSP framework
April 2010 MRC Data Sharing Policy Peter Dukes Policy Lead – Data Sharing & Preservation.
Useful tools for ESRC Research Centres
The PREMIS Data Dictionary Michael Day Digital Curation Centre UKOLN, University of Bath JORUM, JISC and DCC.
VCC3 Proposal Organisation of the tasks Sophie David, Jean-Luc Minel 28 th -29 th August 2012, Dublin.
ISMS implementation and certification process overview
Privacy Impact Assessment Future Directions TRICARE Management Activity HEALTH AFFAIRS 2009 Data Protection Seminar TMA Privacy Office.
EMS Checklist (ISO model)
Dr Lami Kaya ISO Information Security Management System (ISMS) Certification Overview Dr Lami Kaya
APA CONFERENCE, FRASCATI 6 November 2012 Data management planning at the DCC Martin Donnelly Digital Curation Centre University of Edinburgh.
MANAGING YOUR DATA WELL …………………………………………
Statistical Metadata Driven eForms Oleg Volguine Assistant Director Technology Services Division Australian Bureau of Statistics.
Environmental Management Systems Refresher
Developing a Risk-Based Information Security Program
[Organisation’s Title] Environmental Management System
Massachusetts Digital Government Summit October 19, 2009 IT Management Frameworks An Overview of ISO 27001:2005.
S&I Framework Testing HL7 V2 Lab Results Interface and RI Pilot Robert Snelick National Institute of Standards and Technology June 23 rd, 2011 Contact:
RMS – a collaborative approach Presentation Lyn Dare & Stephen Larmour Authorisation & Audit Comcare.
Managing your research data: University support for researchers Sally Rumsey The Bodleian Libraries University of Oxford Mary Harssch
ASQA Update – where are we now? 5 April 2013 Presenter: Tessa Bachmayer.
Developments in Data Discovery at ICPSR George Alter Director, ICPSR University of Michigan.
Repository audit and risk profiles: trust through transparency
By Eileen Clegg Digital Preservation at Columbia in the Old Days (2009)
School of Computing, Dublin Institute of Technology.
Environmental Management Systems Refresher
Co-funded by the European Union under FP7-ICT Alliance Permanent Access to the Records of Science in Europe Network Co-ordinated by #APARSEN.
First Practice - Information Security Management System Implementation and ISO Certification.
The Trusted Digital Repositories Checklist Government Records and Archives Aspects Dr Stephen Ellis Assistant Director – General Government.
OHSAS 18001: Occupational health and safety management systems - Specification Karen Lawrence.
Good practice in Research Data Management Module 6: Tools, training and support.
Data Archiving and Networked Services DANS is an institute of KNAW en NWO Trusted Digital Archives and the Data Seal of Approval Peter Doorn Data Archiving.
2008 New York - Member Forum Council for Responsible Jewellery Practices, Ltd. Overview of CRJP.
Chapter 3 資訊安全管理系統. 4.1 General Requirements Develop, implement, maintain and continually improve a documented ISMS Process based on PDCA.
ETICS2 All Hands Meeting VEGA GmbH INFSOM-RI Uwe Mueller-Wilm Palermo, Oct ETICS Service Management Framework Business Objectives and “Best.
© 2013 Cambridge Technical CommunicatorsSlide 1 ISO/IEC Standard for Information Security Management Systems.
CERTIFICATION In the Electronics Recycling Industry © 2007 IAER Web Site - -
SERPent Project Secure Epidemiology Research Platform January – October 2010 Virtual Research Environment Rapid Innovation Project Funded.
1 Schema Registries Steven Hughes, Lou Reich, Dan Crichton NASA 21 October 2015.
Because good research needs good data Funded by: Digital Curation for Researchers, 28th February 2013 The Shifting Research Data Management Policy Landscape.
Adaptive Processes Consulting Pvt. Ltd. An ISO 9001:2000 Certified Company This document is the property of and proprietary to.
Seamus Ross Director, HATII & ERPANET Associate Director of DCC Services Funders: Service Definition & Delivery Digital Curation Centre a centre of expertise.
Information Security 14 October 2005 IT Security Unit Ministry of IT & Telecommunications.
Secure Epidemiology Research Platform (SERPent) Kick Start Meeting - April 15 th, 2010 Pascal Heus
Samantha Schreiner University of Illinois at Urbana- Champaign BA 559 – Professor Michael Shaw December 15 th, 2008 A Survey of IT Governance Through COBIT,
COBIT®. COBIT® - Control Objectives for Information and related Technology. C OBI T was initially created by the Information Systems Audit & Control Foundation.
ISMS Implementation Workshop Adaptive Processes Consulting Pvt. Ltd.
SAM-101 Standards and Evaluation. SAM-102 On security evaluations Users of secure systems need assurance that products they use are secure Users can:
Working Group 4 Data and metadata lifecycle management  1. Policies and infrastructure for data and metadata changes  2. Supporting file and data formats.
Alex Ezrakhovich Process Approach for an Integrated Management System Change driven.
Improving performance, reducing risk Dr Apostolos Noulis, Lead Assessor, Business Development Mgr Thessaloniki, 02 June 2014 ISO Energy Management.
Active Data Management Plans (ADMP) - Helen Glaves British Geological Survey.
Department of Computer Science Introduction to Information Security Chapter 8 ISO/IEC Semester 1.
What is ISO Certification? Information is a valuable asset that can make or break your business. When properly managed it allows you to operate.
 Planning an audit of cost statements, records and other related documents is considered necessary to ensure achievement of audit objectives with available.
Digital Repository Certification Schema A Pathway for Implementing the GEO Data Sharing and Data Management Principles Robert R. Downs, PhD Sr. Digital.
GS-R-3 vs. ISO 9001:2008 Requirements - 4
What Is ISO ISO 27001, titled "Information Security Management - Specification With Guidance for Use", is the replacement for BS It is intended.
Preparing a Trustworthy Domain Repository for ISO Certification
aspects of archive system design
Developing Criteria to Establish Trusted Digital Repositories
CFI John R Evans Leaders Fund Digital Data Management
Research Data Management
HingX Project Overview
The MRC Research Data Gateway
Metadata The metadata contains
Exchanging Data Management Plans with DDI
What is IT audit? An examination of how IT systems where implemented to ensure that they meet the organization’s business needs without compromising.
Presentation transcript:

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 Data Management Planning for Secure Services (DMP-SS) † Tito Castillo, † Stelios Alexandrakis, † Anthony Thomas, † Michael Waters, *Phil Curran, *Kevin Garwood † UCL Institute of Child Health *MRC Unit for Lifelong Health and Ageing

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 DMP-SS Data Management Planning for Secure Services The Digital Curation Centre has developed DMPOnline to assist researchers with the design of structured and standardised data management plans. Data management planning involves consideration and application of effective information security. Question: Can we harness aspects of DMPOnline to assist with the establishment of a formal Information Security Management System (ISMS)?

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 Summary The project seeks to develop an Information Security Management System (ISMS) ISO-27001:2005 ISMS designed to operate with a local registry of data management plans Health and social science surveys are standardising on DDI as the method for metadata representation Local DMP registry will extend DDI top accommodate the DMPOnline checklist.

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 Information Security Management Systems International standard for information security ISO-27001:2005 Describes requirements (i.e. what you ‘shall’ do) Independently audited Associated code of practice ISO-27002:2005 Provides guidance (i.e. what you ‘should’ do) An ISMS is dynamic

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 Objectives  Extend DMPOnline checklist through a formal object model for data management planning  Create a local DMP repository service by extension of the DDI 3.x standard to accommodate elements of the DMP object model.  Develop suitable web-services from the local DMP repository to allow for search and retrieval of data management plans contained within the repository  Develop the necessary functional components for an ISO compliant ISMS  asset and risk registers  controls and assurance records  document management system

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 DMP-SS Project Data Management Planning for Secure Services

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 DMPOnline Checklist The DMPOnline checklist provides a taxonomy of questions relating to the planned use of data assets within a research project

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 ISO controls taxonomy The standard proposes a taxonomy of controls and associated assurance mechanisms that may be applied by an organisation to reduce the risk to specified information assets.

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 Information Security Management System (ISMS) Development PLAN Management Support Define ISMS Scope Create Asset Register Risk Assessment Risk Treatment Plan Statement of Applicability DO ISMS Implementation Programme Create ISMS ISMS CHECK Compliance Review Stage 1 Audit Stage 2 Audit ISO Certification ACT Corrective Action Corrective Action Procedure

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 Data Management Plan Information Security Management System Relationship between DMP and ISMS

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 What is DDI? Data Documentation Initiative (DDI) – XML metadata specification – Describes the study, datasets, supporting docs & other external resources – DDI Alliance DDI version – focus is on the archive / preservation / dissemination – Has been around since – Widely used and tools available DDI version – Encompasses the entire survey life cycle – Initial version released in – Early adoption stage and tools in development

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 DDI ‘life-cycle’ standard Metadata descriptors of data management process. ….. from conceptualisation through to archival.

Meeting Disciplinary Challenges in Research Data Management Planning – March 23 rd 2012 Project Workpackages 1.Adaptation of DMP Online DCC develop web service API 2.DDI Repository development Metadata Technology develop formal model of DMP and extend DDI repository 3.Risk assessment tool development ICH develop ISMS (database and document management system) 4.Stakeholder Engagement Pilot studies 5.Reporting