Question to the Home Office:
To ask the Secretary of State for the Home Department, with reference to the policy paper entitled Transforming for a digital future: 2022 to 2025 roadmap for digital and data, updated on 29 February 2024, what steps his Department has taken to mitigate the risks of red-rated legacy IT systems.
The Central Digital and Data Office (CDDO), in the Cabinet Office, has established a programme to support departments managing legacy IT. CDDO has agreed a framework to identify ‘red-rated’ systems, indicating high levels of risk surrounding certain assets within the IT estate. Departments have committed to have remediation plans in place for these systems by next year (2025). It is not appropriate to release sensitive information held about specific red-rated systems or more detailed plans for remediation within the Home Department’s IT estate, as this information could indicate which systems are at risk, and may highlight potential security vulnerabilities.