- Asked by: Anas Sarwar, MSP for Glasgow, Scottish Labour
-
Date lodged: Friday, 19 May 2017
-
Current Status:
Answered by Derek Mackay on 5 June 2017
To ask the Scottish Government, further to the statement by the Cabinet Secretary for Health and Sport on 16 May 2017 (Official Report, c. 4), whether it will publish details of any action it has taken in response to warnings issued by the National Cyber Security Centre regarding the need to protect services from hackers.
Answer
The Scottish Government’s Cyber Security Operations Centre (C-SOC) monitors guidance and threat reports issued by the National Cyber Security Centre (NCSC) and takes appropriate action on relevant warnings. These actions include: taking relevant additional precautionary steps to protect Scottish Government systems and infrastructure; sharing threat information with other bodies; sharing relevant information back with NCSC.
- Asked by: Anas Sarwar, MSP for Glasgow, Scottish Labour
-
Date lodged: Friday, 19 May 2017
-
Current Status:
Answered by Derek Mackay on 5 June 2017
To ask the Scottish Government, further to the statement by the Cabinet Secretary for Health and Sport on 16 May 2017 (Official Report, c. 4), when it acted on the alert issued by Microsoft in March 2017; whether it will publish any warnings that it subsequently issued to departments and agencies for which it has responsibility, and which of those failed to respond.
Answer
The Scottish Government installs Microsoft updates across its core infrastructure as a minimum on a monthly basis. All Microsoft-based devices connected to the Scottish Government’s ICT network (SCOTS) before May’s Wannacrypt attack had this update applied.
The Scottish Government’s Information and Technology Services (iTECS) division does not have responsibility for alerting other departments and agencies to Microsoft security bulletins. These organisations will receive the alerts and updates direct from Microsoft.
- Asked by: Anas Sarwar, MSP for Glasgow, Scottish Labour
-
Date lodged: Friday, 19 May 2017
-
Current Status:
Answered by Derek Mackay on 5 June 2017
To ask the Scottish Government, further to the statement by the Cabinet Secretary for Health and Sport on 16 May 2017 (Official Report, c. 4), what contractual arrangements it put in place with Microsoft to provide customised support for Windows XP after Microsoft stopped issuing updates.
Answer
The Scottish Government’s ICT network (SCOTS) was migrated to Windows 7 in advance of Microsoft ending support for Windows XP, therefore no contractual arrangements were required for continued Windows XP support.
Information on arrangements put in place by public sector bodies not on SCOTS is not held centrally.
- Asked by: Anas Sarwar, MSP for Glasgow, Scottish Labour
-
Date lodged: Friday, 19 May 2017
-
Current Status:
Answered by Derek Mackay on 5 June 2017
To ask the Scottish Government, further to the statement by the Cabinet Secretary for Health and Sport on 16 May 2017 (Official Report, c. 4), whether it will list the departments and agencies for which it has responsibility that continue to use unsupported software systems.
Answer
Information related to support for Agency and NDPB systems not supported by the Scottish Government’s Information and Technology Services (iTECS) division is not held centrally.
- Asked by: Anas Sarwar, MSP for Glasgow, Scottish Labour
-
Date lodged: Friday, 19 May 2017
-
Current Status:
Answered by Shona Robison on 1 June 2017
To ask the Scottish Government, further to the statement by the Cabinet Secretary for Health and Sport on 16 May 2017 (Official Report, c. 4), what instructions the cabinet secretary issued prior to the recent cyber-attacks to (a) civil servants and (b) organisations and agencies for which she has responsibility, to improve resilience against such incidents.
Answer
Health boards all comply with the Scottish Government IT Security Framework and the Standards For Organisational Resilience. NHSScotland Chief Operating Officer issued a letter to Chief Executives of NHS boards on the 21 February 2017 asking that they confirm there are controls in place to mitigate the impact of any disruption to services
- Asked by: Anas Sarwar, MSP for Glasgow, Scottish Labour
-
Date lodged: Friday, 19 May 2017
-
Current Status:
Answered by Shona Robison on 1 June 2017
To ask the Scottish Government, further to the statement by the Cabinet Secretary for Health and Sport on 16 May 2017 (Official Report, c. 4), for what reason the NHS in Scotland was affected by the recent cyber-attacks when the NHS in Wales was not.
Answer
Boards are currently carrying out their own internal reviews of why they were affected by this attack and to understand further lessons that can be learnt to increase their security.
- Asked by: Anas Sarwar, MSP for Glasgow, Scottish Labour
-
Date lodged: Friday, 19 May 2017
-
Current Status:
Answered by Shona Robison on 1 June 2017
To ask the Scottish Government, further to the statement by the Cabinet Secretary for Health and Sport on 16 May 2017 (Official Report, c. 4), for what reason the NHS in Scotland still uses Windows XP.
Answer
There will be some devices across the NHS estate that require operating systems such as Windows XP. A managed risk approach within each board will be taken around the continuing use of old software such as Windows XP. A rolling programme of system (hardware and software) replacement is underway.
- Asked by: Anas Sarwar, MSP for Glasgow, Scottish Labour
-
Date lodged: Friday, 19 May 2017
-
Current Status:
Answered by Shona Robison on 1 June 2017
To ask the Scottish Government, further to the statement by the Cabinet Secretary for Health and Sport on 16 May 2017 (Official Report, c. 4), whether it is responsible for NHS Scotland not taking sufficient action to prevent the recent cyber-attacks.
Answer
NHS Scotland have a rolling programme of system replacement (hardware and software) along with robust policies and procedures which include local patching regimes at each board. The Scottish Government provides £100 million per annum to Health boards for IT investment and cyber security resilience. Health boards spend at least the same amount per annum however we know that in 2016-17 total spend was around £257 million.
- Asked by: Anas Sarwar, MSP for Glasgow, Scottish Labour
-
Date lodged: Friday, 19 May 2017
-
Current Status:
Answered by Shona Robison on 1 June 2017
To ask the Scottish Government, further to the statement by the Cabinet Secretary for Health and Sport on 16 May 2017 (Official Report, c. 4), for what reason it did not take pre-emptive action, similar to that taken in Wales, which might have prevented the recent cyber-attack affecting the NHS in Scotland.
Answer
Many Boards were unaffected or had small numbers of devices affected. In February 2017 letter was issued asking Boards to confirm their approach to back-up procedures for an attack such as we experienced.
- Asked by: Anas Sarwar, MSP for Glasgow, Scottish Labour
-
Date lodged: Monday, 22 May 2017
-
Current Status:
Taken in the Chamber on 25 May 2017
To ask the First Minister, in light of her expressing the view that the NHS pay cap is "unsustainable", whether the Scottish Government will provide details of the submission it made to the pay review body.
Answer
Taken in the Chamber on 25 May 2017