The Information Assurance Standard 6 (IAS 6) is legislation enacted by the British government in May 2009 as part of its Security Policy Framework (SPF). SPF is a response to government data breaches uncovered in the government's Data Handling Review.
IAS 6 requires all government agencies to submit reports of compliance to the U.K. Cabinet Office to prove that the methods they use to process and store sensitive personal information are secure. The original reporting deadline was 15 June, 2009.
IAS 6 is supported by Good Practice Guide 15, which is published by the U.K. Cabinet Office and the Communications-Electronics Security Group (CESG). CESG gives a more prescriptive explanation of not only the data that must be collected for the report, but also how to collect it.