Skip to content
site-logo

FEDIP Job Profiles

  • Home
  • About
  • All Job Roles
  • Submit Feedback
  • News
  • FAQs

SFIA Skills: Information assurance (INAS)

Policies (INAS) (Level 6)

Reviews and agrees internal policies and protocols governing the protection and use of person-identifiable information by the organisation’s staff, ensuring that these address the requirements of national policy, guidance and the law, and that their operation is monitored. Ensures they are in an understandable format and available to staff.

Caldicott Guardian/SIRO and DPO advice and support (INAS) (Level 6)

Provides highly complex and strategic advice and support to the board, the senior management team and Senior Information Risk Owners. Provides support to the DPO.

Strategy (INAS) (Level Seven)

Accountable for establishing and managing information assurance strategy and policies in accordance with the ISO/IEC 27000 series of standards and/or other external and internal guidance relevant to own organisation.

Influencing partners (INAS) (Level Seven)

Influences key partner organisations to maintain information assurance policies and practices in line with those of own organisation.

Implementation and processes (INAS) (Level Seven)

Ensures that the organisation implements processes to take forward the information assurance strategy and policies, and improve information security maturity.

Data privacy and information security culture (INAS) (Level Seven)

Obtains organisational commitment to data information security at the highest level. Establishes a culture where data and information security is the responsibility of every employee.

Business plans (INAS) (Level Seven)

Has significant input to development of business plans, ensuring that information assurance is integrated into business strategy and policies.

Advice and guidance (INAS) (Level Seven)

Leads and guides provision of information assurance requirements across all the organisation’s information and information systems.

Strategy (INAS) (Level Six)

Develops strategies for information assurance, as part of corporate IT governance, including guidelines for information and network users and alignment to standard security frameworks. Defines target thresholds for information assurance maturity and oversees activities to achieve these.

Performance measures (INAS) (Level Six)

Identifies and develops metrics and measures for information assurance such as key risk indicators (KRIs) and key performance indicators (KPIs). Determines appropriate and practical performance measures, to ensure that information assurance priorities set by the business can be effectively monitored.

Influencing partners (INAS) (Level Six)

Influences internal and external partners, including the supply chain, to ensure compliance with the organisation’s information security requirements.

Implementation and processes (INAS) (Level Six)

Contributes to the development, implementation and monitoring of organisational policies and processes intended to maintain the availability, integrity and confidentiality of the organisation’s information assets.

Data privacy and information security culture (INAS) (Level Six)

Champions organisational commitment to data privacy and information security. Promotes and supports a culture where data privacy and information security are the responsibility of every employee. Identifies opportunities for improving the security culture and takes responsibility for actioning these.

Business continuity and resilience (INAS) (Level Six)

In the context of business continuity, assesses protection, detection and reaction capabilities, to determine whether they are sufficient to support restoration of information systems in a secure manner.

Architectural principles (INAS) (Level Six)

Ensures architectural principles are applied during design to reduce risk, and advances assurance standards through ensuring rigorous security testing.

Advice and guidance (INAS) (Level Six)

Guides, encourages, leads and develops colleagues, in the disciplines of Information assurance. Supports employees to understand their role in the security of data and information.

Risk assessment (INAS) (Level Five)

Carries out risk assessments of complex information systems and infrastructure components control effectiveness. Contributes to classification of data types held and audits of information systems. Contributes to data breach planning.

Policies (INAS) (Level Five)

Interprets security and assurance policies and contributes to development of policies, standards and guidelines that comply with these, to enable effective assessment of risks to information availability, integrity, authentication and confidentiality.

Performance measures (INAS) (Level Five)

Ensures effective reporting of information assurance metrics. Undertakes activities pertaining to improvements in information security maturity.

Influencing partners (INAS) (Level Five)

Influences internal and external partners, including the supply chain, to ensure compliance with the organisation’s information security requirements.

Implementation and processes (INAS) (Level Five)

Implements effective information security processes to support the organisation’s information assurance strategy and policies.

Data privacy and information security culture (INAS) (Level Five)

Champions organisational commitment to data privacy and information security. Promotes and supports a culture where data privacy and information security are the responsibility of every employee. Identifies opportunities for improving the security culture and delivers awareness training where appropriate.

Business continuity and resilience (INAS) (Level Five)

In the context of business continuity, supports the assessment of the protection, detection, and reaction capabilities, to determine whether they are sufficient to support restoration of information systems in a secure manner.

Advice and guidance (INAS) (Level Five)

Advises information and network users on information assurance architecture and strategies to manage identified risk, and promotes awareness of policies and procedures. Acts to ensure that they are aware of obligations such as protecting the secrecy of passwords and accounts access details.

Risk assessment (INAS) (Level Four)

Carries out risk assessment as directed, using standard processes for identifying potential risks to information systems and infrastructure components.

Policies (INAS) (Level Four)

Contributes to the development of, and implements, security and assurance policies relating to assessment of risks to information availability, integrity, authentication and confidentiality.

Performance measures (INAS) (Level Four)

Produces information assurance management reports.

Influencing partners (INAS) (Level Four)

Influences internal and external partners to ensure compliance with the organisation’s information security requirements.

Implementation and processes (INAS) (Level Four)

Contributes to the effective implementation of information security processes to support the organisation’s information assurance strategy and policies.

Data privacy and information security culture (INAS) (Level Four)

Champions organisational commitment to data privacy and information security in their areas of influence. Promotes and supports a culture where data privacy and information security are the responsibility of every employee. Delivers awareness training to improve the security culture.

Advice and guidance (INAS) (Level Four)

Provides advice and guidance to support and encourage adherence to information security principles.

Best practice (INAS)(Level 6)

Assesses legal and best practice issues, and promotes awareness of national and international laws, including those relating to confidentiality, privacy and copyright.

Job Families

  • IT Operations (47)
    • Application Operations Engineer (6)
    • End User Computing Engineer (5)
    • Infrastructure Operations Engineer (5)
    • Infrastructure Engineer (5)
    • Service Transition Manager (4)
    • Service Desk Manager (4)
    • IT Service Manager (4)
    • Command and Control Centre Manager (4)
    • Change and Release Manager (3)
    • Business Relationship Manager (3)
    • Incident Manager (2)
    • Problem Manager (2)
  • User Centred Design (37)
    • User Researcher (6)
    • Service Designer (6)
    • Interaction Designer (6)
    • Graphic Designer (6)
    • Content Designer (6)
    • Accessibility Specialist (4)
    • Technical Writer (2)
    • Content Strategist (1)
  • Architecture (27)
    • Solutions Architect (5)
    • Technical Architect (5)
    • Business Architect (4)
    • Enterprise Architect (4)
    • Network Architect (3)
    • Data Architect (3)
    • Security Architect (3)
  • Data (25)
    • Data Engineer (5)
    • Data Analyst (5)
    • Analytics Engineer (4)
    • Data Scientist (4)
    • Data Governance Manager (3)
    • Machine Learning Engineer (2)
    • Data Ethicist (2)
  • Software Development (24)
    • Software Developer (9)
    • Development Operations Engineer​​ (9)
    • Frontend ​Developer​ (6)
  • Product and Delivery (21)
    • Business Analyst (6)
    • Product Manager (5)
    • Delivery Manager (4)
    • Digital Portfolio Manager (4)
    • Service Owner (1)
    • Programme Delivery Manager (1)
  • Patient Services (18)
    • Clinical Coder (7)
    • Records and Information Manager​​ (4)
    • Patient Access​ Manager​ (4)
    • Data Quality​ Officer​ (3)
  • Quality Assurance Testing (10)
    • Quality Assurance Testing (QAT) Analyst (4)
    • Test Engineer (4)
    • Test Manager (2)
  • Cyber Security (10)
    • Cyber Security Specialist (Governance Risk and Compliance) (4)
    • Cyber Security Specialist (Operations) (4)
    • Cyber Security Analyst (2)
  • Digital Leadership Roles (9)
    • Chief Technology Officer (1)
    • Chief Information Officer (1)
    • Chief Audit Officer (1)
    • CxIO (1)
    • Chief Information Security Officer (1)
    • Chief Analytics Officer (1)
    • Caldicott Guardian (1)
    • Chief Data Officer (1)
    • Chief Pharmacy Information Officer (1)
  • Knowledge, Library and Information Management (8)
    • Knowledge Manager (5)
    • Library Manager (2)
    • Information Manager (1)
  • Digital Education Services (6)
    • Digital Education Specialist (2)
    • Digital Education Manager (2)
    • Digital Education Administration (1)
    • Digital Education Trainer​ (1)
  • Information Governance (6)
    • Information Governance Officers​ (3)
    • Information Governance Manager​​s (2)
    • Data Protection Officer​​ (1)
  • Clinical Informatics (3)
    • Clinical Informatician​ (2)
    • Clinical Safety Officer (1)
FEDIP logo

The Federation for Informatics Professionals in Health and Care

Registered in England and Wales No. 10639143

email: info@fedip.org

Copyright © 2026 All Rights Reserved FEDIP | Use of cookies | Legal notices
Registered in England and Wales No. 10639143

website by Sarah Scriven