Understanding if your project should be included
All DfE projects and services that go through Cabinet Office spend control process must follow Secure by Design. This includes:
- all new or significant changes to digital service and technology infrastructure
- projects built within the Department for Education (DfE) or procured through suppliers
- if your service is one of the top 75 services recognised by Government Digital Service (GDS)
The DfE services recognised as part of the top 75 include:
- Find an apprenticeship
- Find school and college performance
- Get information about schools
- Get into teaching
- Use the National Careers Service
Your team will need someone who can support you in your Secure by Design evaluation. For example, delivery managers or technical developers.
Spend controls approval
You need spend approval before committing to any digital or technology spend which is above the spend control thresholds.
Projects identified as high risk are included in Secure by Design.
The spend controls approval process is supported by Get approval to spend service.
Through the service business cases undergo a process to determine their risk and importance rating. These are:
- High (H)
- Medium (M)
- Low (L)
We expect most business cases will fall within the scope of Secure by Design.
Additional criteria
If you are developing a service that must meet the service standard. You can check if you need to meet the Service Standard or get an assessment.