This is a request for information that relates to the organisation’s contracts around ICT contract(s) for Server Hardware Maintenance, Server Virtualisation Licenses and Maintenance and Storage Area Network (SAN) Maintenance/Support, which may include:
● Server Hardware Maintenance- contracts relating to the support and maintenance of the organisation’s physical servers.
● Virtualisation Maintenance/Support/ Licensing (VMware, Solaris, Unix, Linux, Windows Server)
● Storage Area Network Maintenance/Support (EMC, NetApp etc)
For each of the type of contract described above, please can you provide me with the following data. If there is more than one contract, please split the information for each separate supplier this includes annual spend
1. Contract Title: Please provide me with the contract title.
2. Type of Contracts (ABOVE): Please can you provide me with one or more contract types the contract relate to: Server Hardware, Virtualisation, SAN (Storage Area Network)
3. Existing/Current Supplier: Please provide me with the supplier’s name for each contract.
4. Brand: Please state the brand of hardware or software
5. Operating System / Software (Platform): (Windows, Linux, Unix, vSphere, AIX, Solaris etc.) Please state the operating system used by the organisation.
6. Annual Average Spend: Please provide me with the most recent annual spend for this contract?
7. Contract Duration: (Please can you also include notes if the contract includes any contract
8. Contract Expiry Date: Please can you provide me with the date of when the contract expires.
9. Contract Review Date: (An approximate date of when the organisation is planning to review this particular contract.)
10. Purchase of Servers: Could you please provide me with the month and year in which most/bulk of servers were purchased.
11. Number of Physical Server: Please can you provide me with the number of physical servers.
12. Number of Virtual Servers: Please can you provide me with the number of Virtual servers’ servers.
13. Brief Contract Description: I require a brief description of the service provided under this contract. Please do not just put maintenance. I need at least a sentence.
14. Contract Owner: (The person from within the organisation that is responsible for reviewing and renewing this particular contract. Please include their full name, job title, direct contact number and direct email address.)
If this service is part of a managed contract, please can you send me the contract information for this managed service including Hardware Brand, Number of Users, Operating System, and contact details of the internal contact responsible for this contract
Information provided for the answer:
Thank you for your request dated 12th October 2022.
Public Health Wales does not confirm or deny that we hold the information you have requested as we do not release details regarding our information security arrangements and we therefore engage the following exemption under the Freedom of Information Act 2000.
Section 38(2) – Health and Safety of the Act – which states that:
38(1) Information is exempt information if its disclosure under this Act would, or would be likely to –
(a) endanger the physical or mental health of any individual, or
(b) endanger the safety of any individual.
(2) The duty to confirm or deny does not arise if, or to the extent that, compliance with section 1(1)(a) would, or would be likely to, have either of the effects mentioned in subsection (1).
Public Interest Test
Public interest considerations in favour of releasing the information.
There is a general public interest in openness and transparency in public sector bodies which can help to maintain public trust.
Information relating to Public Health Wales protective security measures in relation to its systems are clearly matters of public interest and we recognise that there is a legitimate interest in knowing that security measures are in place and where they are focused.
Public interest considerations in favour of refusing to release the information.
Public Health Wales has a duty to protect the public and individuals, and to provide a safe and effective public health service. The release of information under FOIA is ‘release to the world’ and I feel that releasing this information into the public domain would not be in the public interest.
Public Health Wales protective security measures that exist are there to protect our systems which are used to directly assist with the provision of patient care. It has been established that any groups who may be planning cyber-attacks are known to conduct extensive research into the opposition they might face and the release of any information which is held about the security of our systems, no matter how innocuous such requests may appear, may enhance the capability of cyber terrorists and hackers to carry out such attacks.
Releasing any information held could enable hackers and cyber criminals to gain knowledge about Public Health Wales capabilities and IT security measures, and this could enable them to plan attacks where they perceive a lower level of security resource exists. This exposes our IT systems to greater risk and therefore it also follows that risk to our systems will also constitute a risk to both public and staff of Public Health Wales as our systems are used to provide patient care.
Balance of Public Interest Test
Public Health Wales concedes that there is a very real interest in the public knowing that it has adequate levels of protection in place for its IT systems to ensure that we limit any potential for risk befalling the systems on which we heavily rely upon to complete our day to day business and for running the organisation.
However Public Health Wales believes that ensuring the safety of our systems is paramount and on the balance of the information provided above Public Health Wales believes that there would be a clear causative link between releasing the requested information which could then expose Public Health Wales to the risk of crime which could subsequently endanger or cause harm to our patients. Public Health Wales believes that confirming or denying the information requested is held could expose Public Health Wales sites to hackers and cyber criminals this in turn could lead to Public Health Wales being unable to deliver and provide patient care thereby resulting in a real risk of potential harm to our patients and staff and endanger individuals who are depend upon our IT systems for the care they require.
Public Health Wales therefore believes that the public interest in releasing this information outweighs any arguments for disclosure and so we will neither confirm nor deny that we hold the information requested.
If you are unhappy with the service you have received in relation to your request and wish to make a complaint or request a review of the decision, you should write to the Corporate Complaints Manager, Public Health Wales NHS Trust, 3, Number 2, Capital Quarter, Tyndall Street, Cardiff, CF10 4BZ.
If you are not content with the outcome of your complaint or review, you may apply directly to the Information Commissioner for a decision. Generally, the ICO cannot make a decision unless you have exhausted the complaints procedure provided by the Trust. The Information Commissioner can be contacted at:
Information Commissioner for Wales
Telephone: 029 2067 8400