David Miliband
Miliband: Government will work at improving security

Reports reveal poor security practices behind data losses

Data handling review spells out what the government must do to regain the public’s confidence

Written by Tom Young

Poor public sector information security practices were highlighted last week by four separate reports into data handling.

Two of the reports focused on the failures that led to the loss of 25 million child benefit records by HM Revenue and Customs (HMRC), while another examined the loss of a Ministry of Defence (MoD) laptop, which contained unencrypted personal records for more than 600,000 people.

Advertisement

A fourth report, the data handling review, looked more widely at data handling practices across government, and made a number of recommendations for improving security.

Improving information security practices were highlighted as a key move. The review announced that a series of mandatory minimum measures will be put in place.

All information that is portable will be encrypted, including laptops and discs, and greater controls will be put on the moving of information. Departments will be obliged to have their networks tested by ethical hackers on a regular basis.

Civil servants who deal with personal data will undergo annual training, and the government will introduce privacy impact assessments (PIAs) that will monitor the effect of government initiatives on citizens’ privacy.

Data security roles in departments are to be more clearly defined to ensure clear lines of responsibility for protecting information ­ something that was lacking in the HMRC breach.

Departments will report on their performance in these areas to the National Audit Office. They will also be subject to spot checks from the Information Commissioner’s Office (ICO) as part of an effort to improve the transparency of procedures.

“Effective public services depend on information about the people they serve. But to command public confidence, that information needs to be safely stored and protected,” said Cabinet Office minister Ed Miliband.

“The government is determined to take the necessary steps to improve data security. The measures outlined today are an important part of that process.”

Despite the high-profile losses, the Cabinet Office is keen to emphasise that data sharing is crucial to its technology strategy.

Each week, the police and courts make 4,500 enquiries to online driver’s databases ­- for example, the Vosa-operated electronic record of data held by MOT garages which, combined with the insurance industry system enables 10 million people to renew their car tax online through the Driver and Vehicle Licensing Agency (DVLA) -­ while HMRC saw three million self-assessment tax forms filed online in 2006/2007.

The ICO will play an important role in overseeing the increasing amounts of public information being handled. Equipped with new powers to fine and spot check, the office finally has some of the powers it has demanded.

Information Commissioner Richard Thomas welcomed the Cabinet Office moves to improve security. “This material should help chief executives across the whole of the public, private and not-for-profit sectors achieve better compliance with the Data Protection Act and keep people’s details more secure,” he said.

The number of data loss reports since the HMRC breach suggests that incidents will still occur, even when the danger is highlighted. But putting in place the safeguards laid out in the review will be key to reducing the number of occurrences, according to Graham Titterington, principal analyst at Ovum.

“Security training is the most important measure ­ most of these incidents are down to human failure,” he said.

While encrypting data is a relatively simple process, managing the keys that unlock that data is not.

“Encrypting across departments will mean large, complex key management syste ms, and these are quite a challenge to put in,” said Titterington.

“Despite this, it’s realistic to expect most departments to have the recommended measures in place within a year.”

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Online shopping

E-retailers urged to prepare for Christmas

Credit crunch sending shoppers online for cheaper presents   More...

Mobile phone

Emerging markets drive mobile growth

Mobile penetration rates expected to reach 95 per cent by...  More...

Digital information

Poor data classification costing companies dear

Millions wasted on searching through clutter, says analyst   More...

Primary Navigation