Skygate Technology
fade bar Case study 2
The client:
When this project began the client was setting up a new type of private GP scheme. Their aim being to supplement the GP service available through the NHS, offering people a quick and reliable service. At hospitals where the scheme is available the client provides a private GP service from 8am to 8pm, seven days a week.

Project requirement:
The client's proposed infrastructure comprised a collection of local surgeries, each of which would be equipped with a PC. The PC would be used as a thin client communicating with a central hosting location over a private network.

The central location would provide the only connection to the Internet. Initially all connections would be initiated from the inside. Requests originating on the public Internet would not be allowed onto the private network. Internet requests initiated from the inside will include mail, web access, and various services specifically for medical purposes.

Skygate's involvement was split into three phases.

Phase 1:
  • Development of a threat model.
  • Detailed analysis of proposed system architecture.
  • Participation in full day event with client's suppliers.
  • Presentation of security analysis to client and suppliers.
  • Audit of implemented system (including ongoing dialogue with client/suppliers during implementation phase).
  • Vulnerability and/or penetration tests.
  • Final review at end of implementation.
Phase 2:
  • Full security policy definition.
  • Accreditation for BS7799.
Phase 3:
  • Ongoing consultancy for changes or future enhancements.
  • Ongoing testing of security of client's systems.
Due to budgetry constraints phases 2 and 3 have yet to be started.