DSPT: the two assertions that fail most often
Across the toolkits we help complete, the same two assertions trip people up. Fix training completion and leaver offboarding and most of the rest follows.
The Data Security and Protection Toolkit looks large from the outside, and organisations often brace for a marathon. In practice the same two assertions cause most of the grief, and neither is technical. They are training completion and leaver offboarding: proving that your people have actually done their data-security training, and proving that when someone leaves, their access to everything goes with them.
Training fails not because it was not delivered but because it cannot be evidenced. ‘We covered it in a team meeting’ is not a record. What the toolkit wants is a name, a date, and completion for everyone in scope, including part-timers, the bank staff and the person who started last week. If you cannot produce that list on demand, the assertion is unmet however good the actual training was.
Leaver offboarding fails because it is nobody's single job. Someone leaves, HR knows, the rota knows, but the shared inbox, the clinical system, the building fob and the parent app each depend on a different person remembering. Weeks later an active login belongs to someone who no longer works there. That is the finding auditors reach for, because a live account with no owner is the classic route in.
Fix these two properly and the toolkit stops feeling like a wall. Keep a simple training register you update as people join, and a one-page leaver checklist that lists every system to switch off and who owns switching it off. Both are admin, not IT projects, and both turn a shaky assertion into one you can evidence in a minute.
- ✓Keep a training register: every person in scope, with a completion date.
- ✓Write a one-page leaver checklist listing every system and account to disable.
- ✓Assign a single owner to run the leaver checklist on someone's last day.
- ✓Audit current accounts now and close any that belong to people who have left.
- Data Security and Protection Toolkit: guidance GOV.UK ↗
- Managing user accounts and access NATIONAL CYBER SECURITY CENTRE ↗
- Staff training records and accountability INFORMATION COMMISSIONER'S OFFICE ↗
Links open each publisher’s live coverage of this topic.