Establishment of IT Controls for GPG13 Compliance

The provision of an effective framework of Protective Monitoring within Her Majesty's Government's (HMG’s) Information and Communication Technology (ICT) systems is an essential element of HMG’s information security risk strategy. CESG’s Good Practice Guide 13 (GPG13) Protective Monitoring framework has been developed to guide public sector organizations on how to monitor exactly what is going on within their ICT infrastructure in a consistent and effective manner. GPG13 is mandatory for all central and local government, fire, police, health or education authorities.

Protective Monitoring is essentially a set of business processes and support technology that have to be put into place to monitor how ICT systems are used and to assure visibility and accountability for use of HMG’s ICT facilities.