Master Governance Presentation
KwaZulu‑Natal Department of Health

SCM‑NUMSICT Governance & System Assurance Standards

A slide-by-slide walkthrough of the SCM‑NUMS master governance binder — prepared for the KZN Health ICT Governance Committee in line with PHSDSBC Resolution 1 of 2022, POPIA, PFMA and Treasury Regulations 16A.

Document IDKZN/ICT/SCM-NUMS/2026/001
Version1
Date Issued23 September 2026
Project ManagerMr Themba Sikosana
ClassificationInternal · Confidential
ComplianceKZN ICT · POPIA · PFMA
SCM-NUMS clinical care team
Digitised nurse uniform workflow across 11 KZN districts
SCM‑NUMS Supply Chain Management Nurse Uniform Management System
Slide 1 of 25 Use → to navigate
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
SCM‑NUMS Presentation
Section 1–21
Agenda

What this presentation coversEnd‑to‑end governance walkthrough

This deck walks through every section of the SCM‑NUMS master governance binder — from the project charter to final sign‑off — so the Committee understands what was delivered, why each control exists, and how the system will operate in production.

1

Project Charter & Business Case

Purpose, scope, objectives, milestones and success criteria. Pages 3–5

2

Business & User Requirements

Business problems, stakeholder groups, URS / FRS / NFR and password policy. Pages 5–9

3

System Architecture

Four‑layer architecture, database schema, technology stack. Pages 10–12

4

Roles, RBAC & Risk

Position hierarchy, supervision rules, access matrix, risk register. Pages 13–18

5

Security & Data Management

POPIA compliance, data classification, retention, breach response. Pages 19–21

6

Testing, UAT & Traceability

RTM coverage, test phases, UAT scenarios and sign‑off. Pages 21–24

7

Change Management

CH‑001 to CH‑005 records, CCB composition, emergency change process. Page 24–27

8

Backup, DR & Incident

Scripts, Task Scheduler XML, DR scenarios, incident framework. Page 27–31

9

User Manual & Training

SOPs, training plan, attendance and assessment. Page 31–34

10

Go‑Live, PIR & Sign‑Off

Readiness checklist, cut‑over, post‑implementation review, audit evidence. Page 35–38

KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Executive Summary
Pages 3–5
Why SCM‑NUMS exists

A unified platform fornurse uniform management

SCM‑NUMS replaces fragmented, manual, paper‑based uniform ordering with one integrated, secure, web‑based platform — serving 32,000+ nurses across 11 KZN health districts and 700+ facilities.

Digitised nurse uniform process
Digitised nurse uniform process — end-to-end through SCM‑NUMS
32k+
Nurses Served
11
Districts
700+
Facilities
Project Status: Development largely complete. Testing underway. Go‑live scheduled mid‑October 2026.

Core Objective

Deliver a transparent, auditable, role‑based platform for nurse registration, uniform ordering, supervisor approval, distribution tracking and financial reporting.

KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Project Charter — Identification
Page 3
Project Registration

Project identityand ownership framework

AttributeDetail
Project NameSCM‑NUMS · Nurse Uniform Management System
Project IDKZN-ICT-2026-01
DepartmentKwaZulu‑Natal Department of Health
DivisionSCM & ICT Division
SponsorHead of Department: KZN Health
Project ManagerMr Themba Sikosana (PM · Technical Lead)
Start → End26 May 2026 → 15 October 2026
StatusImplementation Ongoing

Budget Framework

Mr TG Sikosana remuneration — maximum overtime allowed for the project duration. Zero licensing cost; system is maintainable by the in‑house ICT team.

Delivery Window

Formally established on 26 May 2026 and completed on 15 October 2026, delivering all planned objectives within scope and budget.

KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Challenges & Value
Page 4
Before & After

Challenges addressedand business value delivered

Challenges Before SCM‑NUMS

  • Inefficient manual processes: paper‑based ordering slow and error‑prone.
  • Email‑based requests: difficult to track, prioritise or audit.
  • Lack of visibility: no real‑time view of ordering or expenditure.
  • Audit difficulties: audit evidence hard to produce.
  • Fraud risk: no traceability created mismanagement opportunities.
  • Inconsistent practices: no standardisation across districts and facilities.

Business Value Delivered

  • Fully digitised ordering process
  • Complete audit trail for every transaction
  • Role‑based access control across 5 roles
  • Real‑time financial and operational dashboards
  • Full compliance with PHSDSBC Resolution 1 of 2022
  • Zero licensing cost and maintainable by own ICT team
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Project Scope
Page 4
Scope Boundaries

In scope vsout of scope

In Scope

  • Users: 32,000+ nurses across 11 districts
  • Facilities: 700+ health facilities
  • Online ordering: visual catalogue with size selection
  • Approval workflow: position hierarchy (Levels 1–12)
  • RBAC: five distinct user roles
  • Audit trail: complete logging of all transactions
  • Financial reporting: district, facility, province‑wide
  • Integration: HR database for Persal validation

Out of Scope

  • Physical uniform manufacturing
  • Procurement of raw materials
  • Logistics fleet management
  • Physical distribution logistics
  • External system integrations beyond HR
Deliberate scoping keeps this release focused — every out‑of‑scope item is on the future roadmap.
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Objectives & Milestones
Page 4–5
Progress

Objectives anddelivery milestones

Objectives

ObjectiveStatus
Digitise ordering processIn Progress
RBAC with 5 rolesAchieved
Real‑time order visibilityAchieved
Complete audit trailAchieved
PHSDSBC complianceAchieved
HR integrationAchieved
99.5% uptimeMonitoring

Milestones

PhaseDateStatus
BRS & URS Approval26 May 2026Complete
Architecture & Schema15 Jun 2026Complete
Core Modules1 Aug 2026In Progress
Internal & Security Tests15 Aug 2026In Progress
Facility TestingEnd Sep 2026Planned
5 Pilot FacilitiesEarly Oct 2026Planned
Province‑Wide Go‑LiveMid Oct 2026Planned
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Business Requirements
Page 5–6
Business Requirements

Business problemsand process change

SCM-NUMS catalogue
Manual and email‑based ordering replaced by a controlled digital catalogue

Old Process (Manual)

  • Paper forms distributed to facilities
  • Requests received by email
  • No central register
  • Physical approval signatures
  • Paper‑based order tracking
  • Manual report generation

New Process (Digital)

  • Online registration and ordering
  • Automated data validation
  • Digital approval workflow
  • Real‑time status tracking
  • Automated reporting with export
Business Value: Operational efficiency, improved financial accountability, enhanced audit readiness across the KZN health system.
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Business Requirements Register
Page 6
Requirements Register

Key businessrequirements

IDRequirementPriorityBusiness Driver
BR‑01Nurses register using Persal numberHighIdentity verification
BR‑02Supervisors approve/reject ordersHighAccountability
BR‑03All transactions logged with audit trailHighAudit readiness
BR‑04RBAC with role‑based accessHighSecurity
BR‑05Financial and operational reportsMediumManagement oversight
BR‑06HR database integration for validationHighData accuracy
BR‑07Centralised uniform catalogueMediumConsistency
BR‑08Support for 32,000+ usersHighScalability
All business requirements were reviewed and approved by the Uniform Management Steering Committee.
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
URS / FRS / NFR
Page 7–8
User & System Requirements

Functional requirementsby role and by function

User Requirements

IDUser TypePriority
UR‑01Nurse — register, order, view historyHigh
UR‑02Supervisor — approve, activate, re‑openHigh
UR‑03Stores Officer — inventory, issue, reportsMedium
UR‑04Head Office — oversight, configHigh
UR‑05Auditor — logs, compliance, read‑onlyMedium

Functional Requirements

IDFunctionModule
FR‑01Registrationcheck_name.php
FR‑02Authenticationlogin.php
FR‑03RBACconfig.php
FR‑04Catalogue CRUDsettings.php
FR‑05Order Placementorder.php
FR‑06Approval Workflowapprove_order.php
FR‑07Audit Loggingadmin_audit_log
FR‑08Reportingfinancials.php
FR‑09Activationactivate_user.php
FR‑10Order Editingedit_order.php
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
NFR & Password Policy
Page 8–9
Quality Attributes

Non‑functional requirementsand password complexity

SCM-NUMS in a facility
Nurses interacting with SCM‑NUMS in a live facility environment

Security (NFR‑02)

  • bcrypt hashing with salt
  • 30‑min session timeout
  • HTTPS (SSL/TLS) encryption
  • CSRF tokens on all forms
  • Prepared statements (PDO)
  • XSS prevention via output encoding
  • Lockout after 5 failed logins

Password Complexity

  • Minimum 6 characters
  • At least one uppercase (A–Z)
  • At least one lowercase (a–z)
  • At least one number (0–9)
  • At least one special character
  • bcrypt hashing with salt
Where enforced: Both client (check_name.php live checklist) and server (PHP regex) mirror each other — registration is blocked if any rule fails.
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
System Architecture
Page 10–11
Architecture

Four‑layersystem architecture

SCM-NUMS deployment
SCM‑NUMS deployment across KZN Health infrastructure

Layer 1 — Presentation

Technologies: HTML5, CSS3, JavaScript, jQuery, Font Awesome.

Components: Nurse Portal, Supervisor Dashboard, Admin Console, Auditor Interface.

Layer 2 — Application

Technologies: PHP 8.2, Apache 2.4, Composer.

Modules: Authentication, Orders, Approvals, Catalogue, Reports, Audit.

Layer 3 — Data

Technologies: MariaDB 10.4+, PDO, SQL.

Tables: 14 core tables including nurses_users, uniform_orders, order_items.

Layer 4 — Infrastructure

OS: Windows 10 Enterprise (22H2).

Hosting: SITA — State Information Technology Agency.

KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Database Design
Page 11
Data Model

Core databasetables

TableDescriptionKey Fields
nursesHR master data (read‑only)persal_number, surname, district, facility
nurses_usersSystem user accountspersal_number, email, password, is_active, position_id
uniform_ordersOrder headersuser_id, status, total_amount, approved_by
uniform_catalogueUniform itemscategory, item_name, price, sizes
order_itemsOrder line itemsorder_id, uniform_id, size, quantity, price
admin_usersSystem administratorsusername, password, role, district, status
admin_audit_logAdmin action audit trailadmin_id, action, description, ip_address
nurses_activity_logNurse activity audit trailuser_id, action, description, ip_address
supervisor_approvalsSupervisor approval recordssupervisor_id, nurse_id, action, rejection_reason
positionsNursing position hierarchyposition_name, level, is_supervisor, scope
order_cyclesOrdering periodsstart_date, end_date, is_active
user_order_limitsPer‑cycle order trackinguser_id, cycle_id, has_ordered
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Position Hierarchy
Page 13
Roles & Hierarchy

Twelve nursing positionsand supervision rules

IDPositionLevelScope
1Enrolled Nursing Auxiliary1
2Staff Nurse (Enrolled)2
3Professional Nurse (General)3
4Professional Nurse (Specialty)4
5Clinical Nurse Practitioner5
6Operational Manager (General)6Department
7Operational Manager (Specialty/PHC)6Department
8Assistant Nurse Manager7Facility
9Deputy Manager (Nursing)8Facility
10Manager (Nursing) / Matron9Facility
11Director / Chief Director Nursing10Facility
12Facility CEO11Facility (Ultimate)

Supervision Rules

  • Position 6: SAME FACILITY AND SAME DEPARTMENT.
  • Positions 7–12: ALL nurses in the SAME FACILITY.
  • CEO: Ultimate authority for the facility.
  • Self‑Supervision: Not permitted.
  • Higher Level Rule: Supervisor must be higher than supervisee.
Principle of Least Privilege: Users are granted only the permissions necessary for their role.
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Access Matrix
Page 14–15
RBAC

Function‑by‑roleaccess matrix

FunctionNurseSupervisorStoresHead OfficeAuditor
Register / LoginLogin only
Place / Edit Order
View Supervisee Orders
Activate / Approve
Manage Catalogue / Stores
View Province Reports
View Audit Logs
System Config / Manage Admins

Nurse

Register, place orders, view own history, edit pending orders.

Supervisor

Approve/reject supervisee orders, activate accounts, re‑open approved orders.

Stores Officer

Manage inventory, issue uniforms, generate stores reports, read audit logs.

Head Office

Highest access. Configure system, manage users province‑wide.

Auditor

Read‑only access to all data, audit logs and compliance reports.

KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Risk Register
Page 16–18
Risk Management

Active risk registerand mitigations

IDRiskLIMitigationStatus
R‑01Unauthorised access to PIILowHighRBAC, bcrypt, SSL/TLS, lockoutMitigated
R‑02Downtime during peak usageMedHighHA infra, load balancing, redundancyMitigated
R‑03Data loss (hardware/corruption)LowHighDaily backups, off‑site DR, restore testsMitigated
R‑04POPIA non‑complianceLowHighPIA, data classification, RBAC, reviewsMitigated
R‑05User resistance to digital systemMedMedTraining, manuals, phased rollout, helpdeskOngoing
R‑06HR integration failureLowMedAPI testing, fallback, UAT, error handlingMitigated
R‑07Cybersecurity attackLowHighPDO, sanitisation, WAF, pen testsMitigated
R‑08Performance degradation at scaleMedMedQuery tuning, caching, load testingMitigated
R‑09Weak user passwordsLowHighComplexity policy, bcrypt, lockoutMitigated
R‑10Silent backup failureLowHighError logging, exit codes, weekly verifyMitigated
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Security & Privacy
Page 19–20
Security & Privacy

Security controls andPOPIA compliance

Security Controls

  • bcrypt hashing with salt
  • Session‑based authentication, 30‑min timeout
  • RBAC with least privilege
  • SSL/TLS encryption in transit
  • PDO prepared statements, CSRF, XSS prevention
  • Comprehensive audit logging
  • Account lockout after 5 failed logins

POPIA — 8 Conditions

  • 1. Accountability
  • 2. Processing Limitation
  • 3. Purpose Specification
  • 4. Further Processing Limitation
  • 5. Information Quality
  • 6. Openness
  • 7. Security Safeguards
  • 8. Data Subject Participation

All Compliant

Layer 1

Network

HTTPS, firewall, IDS, secure config.

Layer 2

Application

bcrypt, RBAC, input validation, CSRF/XSS.

Layer 3

Data

Encryption at rest, secure connections, classification.

Layer 4

Audit

Comprehensive logging, IP tracking, incident monitoring.

KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Data Management
Page 21
Data Governance

Data classification,ownership and retention

Classification

Data TypeClass
Personal InformationCONFIDENTIAL
CredentialsCONFIDENTIAL
Order InformationINTERNAL
Audit LogsCONFIDENTIAL
System ConfigurationINTERNAL
Financial ReportsINTERNAL

Retention Schedule

Data TypeRetention
User Records (Active)Indefinite
User Records (Inactive)5 yrs → delete at 10 yrs
Order RecordsIndefinite
Audit LogsIndefinite
Reports5 years
Backups30d daily / 12m monthly

Data Owner

KwaZulu‑Natal Department of Health.

Data Steward

Supply Chain Management Division.

Technical Custodian

ICT Division.

KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
RTM & Testing
Page 21–22
Traceability & Testing

Requirements traceabilityand test coverage

Business Reqs

8

100% mapped to test cases

User Reqs

5

100% mapped to test cases

Functional Reqs

11

100% mapped to test cases

Test Cases

86

UAT cases planned

Test Phases

PhaseStatus
1. Unit TestingIn Progress
2. Integration TestingIn Progress
3. Functional TestingIn Progress
4. Security TestingIn Progress
5. Performance TestingPlanned
6. Facility TestingPlanned
7. UATPlanned

UAT Participants

RoleNumber
Nurses10
Supervisors5
Stores Officers3
Head Office2
Auditors2
86 UAT test cases covering registration, ordering, approvals, catalogue, reporting, audit and RBAC.
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Change Management
Page 24–27
Change Control

Change managementrecords to date

IDDateDescriptionImpactDeployed
CH‑00115 Jun 2026Remove document upload functionalityLow
CH‑00215 Jun 2026Approvals/activations by immediate supervisorMedium
CH‑00328 Jul 2026Remove price from UI; keep adminMedium
CH‑00428 Jul 2026No price limits; only quantity limitsMedium
CH‑00528 Jul 2026Admin portal finance only; “orders” → “requisitions”Medium

Change Control Board

  • Chair: Mr Mtshali
  • Technical Lead · PM: Mr Themba Sikosana
  • Business Rep: Mr Mkhize
  • Security Rep: ICT Security
  • Audit Rep: Internal Audit

Emergency Change Process

  • Criteria: critical system issues
  • Approval: CIO or delegate
  • Rapid testing before deployment
  • Documented within 24 hours
  • Reviewed at next CCB meeting
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Backup & DR
Page 27–31
Resilience

Backup, recovery anddisaster recovery

4h
RTO — Recovery Time Objective
1h
RPO — Recovery Point Objective
30d
Daily Backup Retention
12m
Monthly Backup Retention

Backup Schedule

TypeFrequencyStorage
Full DB BackupDaily 17:00E:\Backup + pharmacyportal VM
IncrementalHourly after 17:00E:\Backup\incremental
Remote Off‑siteDaily 17:30\\pharmacoportal\e\backup
VM BackupPeriodicInfrastructure storage
VerificationWeekly Sun 03:00nurses_db_test

DR Scenarios

ScenarioRTORPO
Database Corruption< 2h< 1h
Hardware Failure< 3h< 1h
Complete Site Disaster< 4h< 1h
Ransomware Attack< 3h< 1h
Accidental Data Deletion< 1h< 1h
Silent Backup Failure< 2h< 24h
Automation: Three batch scripts (full, incremental, remote copy) registered under a single Task Scheduler XML — SCM-NUMS Backup Suite.
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Incident Management
Page 31–32
Incident Management

Incident prioritiesand escalation

Priority Levels

PriorityDescriptionResponseResolution
P1System down, data loss, breach15 min2 hours
P2Major functionality affected30 min4 hours
P3Non‑critical functionality2 hours24 hours
P4Minor issues / enhancements24 hours5 days

Escalation Path

LevelOwner
Level 1Helpdesk Support
Level 2Mr Themba Sikosana & SCM Team
Level 3ICT Manager
Level 4CIO
Level 5Head of Department
Incident register: No incidents have occurred to date. Procedures and templates are in place and ready.
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
User Manual & Training
Page 32–34
Enablement

User manual andtraining programme

User Manual — Core Procedures

  • 16.3 — Register as a Nurse
  • 16.4 — Log In
  • 16.5 — Place a Uniform Requisition
  • 16.6 — Activate a Nurse Account
  • 16.7 — Approve or Reject a Requisition
  • 16.8 — Re‑open an Approved Requisition
  • 16.9 — Manage the Catalogue
  • 16.10 — Manage Inventory & Issue Uniforms

Training Target Audience

CategoryTotal Users
Nurses32,000+
Supervisors450
Stores Officers22
Head Office Staff15
Auditors8
Total32,500+

Train‑the‑Trainer

Head Office — district trainers enabled first.

District Training

Two rounds across all 11 districts covering nurses, supervisors and stores.

Specialist Sessions

Auditor, supervisor refresher, helpdesk and admin advanced training.

KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Go‑Live, PIR, Audit & Sign‑Off
Page 35–38
Closing

Go‑live readiness,audit evidence and sign‑off

Go‑Live Readiness

  • Business readiness ✓
  • Security readiness ✓
  • Data readiness ✓
  • ICT readiness ✓
  • Operational readiness — planned
  • User readiness — planned

Post‑Implementation

  • Requisition time < 10 days
  • User satisfaction > 80%
  • Uptime > 99.5%
  • 100% audit log completeness
  • 100% training completion
  • Incident resolution < 24h
  • Backup success rate 100%

Audit Evidence

  • RBAC matrix ✓ Available
  • Audit‑log reports — in progress
  • Change records ✓ Available
  • Test scripts — in progress
  • UAT sign‑off — planned
  • DR runbook ✓ Available
  • Password complexity evidence ✓
Sign‑Off: Project Manager · Technical Lead — Mr Themba Sikosana · Business Owner — Director: Supply Chain Management · Change Control Board Chair — Mr Mtshali · Internal Audit — Chief Audit Executive.
KZN DoH
KwaZulu‑Natal Department of Health
ICT Governance & System Assurance
Closing
Thank You
Closing

Thank youQuestions & Discussion

This closes the SCM‑NUMS presentation. The full governance binder is available in index.php and the templates in templates.php.

Document References

Document ID: KZN/ICT/SCM-NUMS/2026/001
Version: 1
Date Issued: 23 September 2026
Project Manager · Technical Lead: Mr Themba Sikosana
Classification: Internal · Confidential
Compliance: KZN ICT · POPIA · PFMA

SCM-NUMS clinical team
SCM‑NUMS · Digitised nurse uniform workflow across 11 KZN districts
1 / 25
Document