Policy
Information Security Policy
The Information Security Policy for the Gambling Commission.
3 - Individual responsibilities
3.1. All colleagues
3.2. All individual users of Gambling Commission information systems and those handling or having access to Commission information outside of those systems shall be responsible for:
- complying with all relevant information management and security policies, practices and procedures including any external accountability
- report information security incidents via the defined and approved channels.
3.3. Senior Information Risk Owner (SIRO) The SIRO at the Commission is the Chief Technology Officer who is ultimately responsible for Information Security Standards and Incident Response.
3.4. Information Asset Owner (IAO) The IAOs are owners for allocated Information Assets that are recorded in our Information Asset Register (IAR) and directly relate to the functions and activities that IAOs oversee.
3.5. Data Protection Officer (DPO) The DPO at the Commission is the Head of Governance and is ultimately responsible for all data processing activities.
Previous section2. Purpose and scope - Information Security Policy Next section
4. Information Security objectives - Information Security Policy
Last updated: 24 April 2025
Show updates to this content
No changes to show.