Question to the Department for Environment, Food and Rural Affairs:
To ask the Secretary of State for Environment, Food and Rural Affairs, with reference to the policy paper entitled Transforming for a digital future: 2022 to 2025 roadmap for digital and data, updated on 29 February 2024, what steps his Department has taken to mitigate the risks of red-rated legacy IT systems.
The Central Digital and Data Office (CDDO), in the Cabinet Office, has established a programme to support departments managing legacy IT. CDDO has agreed a frame-work to identify ‘red-rated’ systems, indicating high levels of risk surrounding certain assets within the IT estate. Departments have committed to have remediation plans in place for these systems by next year (2025).
It is not appropriate to release sensitive information held about specific red-rated systems or more detailed plans for remediation within Defra’s IT estate, as this information could indicate which systems are at risk and may highlight potential security vulnerabilities.