My Department implements a multi layered defence-in-depth security strategy which is achieved through the effective combination of People, Processes, and Technology to support the implementation of appropriate security measures and provisions. This defence-in-depth security strategy includes the implementation of an extensive Information Security Management System (ISMS) comprising of many security policies and controls, which is aligned and certified to the industry security standard ISO 27001:2022 to address risks from cyber security attacks. These security controls ensure that a consistent and effective approach is adhered to in the management of cyber security threats and incidents.
For operational and security reasons, my Department has been advised by the National Cyber Security Centre not to disclose details of systems and processes which could in any way compromise the Department's cybersecurity efforts. In particular, it is not considered appropriate to disclose any information which might assist criminals to identify potential vulnerabilities in cybersecurity arrangements in my Department or the bodies under its aegis. Therefore, it is not possible to provide the particular information requested by the Deputy on spend or any information in relation to cyber security tools and services or operational security matters.