How MHCLG uses your CAF assurance report and improvement plan
Your assurer will share your completed CAF assurance report and improvement plan with MHCLG. We use this information to understand cyber security risks across local government and identify where councils may need support.
Following the independent assurance review, your assurer will share your completed assurance report and improvement and implementation plan with MHCLG.
What you need to do
You do not need to take any action. Your assurer will let you know when they have submitted the documents.
How MHCLG will use your information
We use the information in your CAF assurance report and improvement plan to understand cyber security risks across the sector and identify where councils may need more support. This will help us meet the ambitions of the Government Cyber Security Strategy 2022 to 2030.
Councils that complete CAF assessments and submit them to MHCLG will be in a better position to access future support.
MHCLG will not publish individual council information, but we will share insights about sector-wide cyber security risks with councils.
Read the MHCLG personal information charter and privacy notice to find out how we collect, use and store personal information.
How long MHCLG will keep your information
We will keep your information on our systems for 7 years. After that, we will delete it.
Only authorised central government staff who need the information to understand cyber security risks across local government will have access.
We will review the information stored annually to:
- check whether we still need it
- delete any information we no longer need
- make sure only the relevant people have access