Public sector IT & e-Government news, job vacancies, public sector tenders from PublicTechnology.net
Advertise on our sites  |  About us  |  Contact us RSS news feeds
Free news email alerts from Publictechnology.net: Sign up here
Feb 09, 2010 - 02:49 PM
Join & login to submit articles
Want to join?  or  Login
Central Government
HMRC's lost Child Benefit data: Don't blame a junior clerk…


 Tag:  Central Government    Print article: Printer friendly page    Email article: Send this story to a friend       This was published: 22 Nov 2007 - 07:00 am   

Peapod Consulting, a GSS company, described the news that 25 million people’s personal details have gone ‘missing’ from HM Revenue and Customs (HMRC) as inevitable. Just yesterday, Peapod voiced its concern following the news last week from the Information Commisioner’s Office that nine out of ten adults worry that organisations are failing to keep their personal information secure. For them, this news couldn’t have come at a worse time.


Robin Hollington, Director of Consulting for Peapod (UK) Ltd, has been working in the IT Security arena for over 10 years. During this time he has provided indispensable advice to organisations on how to protect sensitive data, from personal customer records to sensitive business plans and confidential financial results. Additionally, Peapod has been carrying out security reviews as bespoke consulting assignments for more than five years to check organisations’ defences are impenetrable.

Robin made the following initial statement : “It’s pointless everyone pointing fingers now and placing the blame on a junior clerk, so let’s not jump on the bandwagon and throw mud at HMRC for the sake of it. They have a massive duty of care, which has been breached, but then so do lots of people. Whilst it is not acceptable to be losing data of this nature, HMRC are not the only large organisation to lose client data as there have been other high profile losses – like Nationwide Building Society and TKMaxx. How many companies’ back up tapes have been stolen from the back of vans that are never made public?

“Despite the potentially devastating short term implications of the incident, the real cost of the breach will be the long term damage done to the implicit trust with which Britons have been prepared to hand over their personally identifiable data and bank details. When the CDs eventually turn up, who is to say whether they have, or haven’t, been copied? The opportunistic thief can then wait one, two, three or even ten years to exploit the data – long after this incident is forgotten. This is a long term, potentially never ending problem and what is needed now is vigilance by everyone for any unusual account activity. But then, we’ve been doing this already, haven’t we?

“For the government a more demonstrable response is required. It needs to act swiftly or it can consider its headline national identity card policy and the NHS Patient Record initiatives dead in the water. It could even find itself paying the ultimate price at the next elections as an increasing sceptical public seeks a safer pair of hands in which to place the reins of power. That said it will not fix the problems overnight. No organisation of this size does. We know there are relatively simple solutions to the problem, technically. However the issue is normally with people and procedures.

"Information leakage from within and low-tech unauthorised disclosures are two major causes for concern, as are lack of management awareness, staff education relating to the use of removable media, working outside of the secure office environment etc., the list goes on. Although professional security experts have been advocating cohesive physical, information and technical security controls for many years, the holistic view is still all too often rejected and the culture of "someone else's problem" is very much prevalent. Government Departments often mandate suppliers are certified to ISO 27001 (the best practice Standard for Information Security), this is a wake up call to practice what they preach. Adoption of the standard need not be a costly exercise.

“I’m sure HMRC has policies in place that should have prevented this crisis in confidence but if these policies are not communicated to every member of staff, or are enforced, then they are not worth the time they took to write. Additionally, there are simple, cost effective solutions available that could have force encrypted this data as soon as it was passed outside the secure environment, in this instance downloaded to a CD.

“The lessons on offer in the wake of this disaster are clear, and show absolutely that all entities, public and private, in possession of personally identifiable data about UK residents must regard this unfortunate occurrence as a massive accelerant in their endeavours to ensure the sustainability of the confidentiality, integrity and availability of their critical information assets.

“Information security assurance can no longer be dismissed by business leaders as an afterthought, but must be treated as a cornerstone of any organisational strategy by any enterprise serious about remaining in business as a going concern in the 21st century.

“By adopting a sound organisational security policy that is effectively communicated to every member of staff, ensuring compliance is embedded in operational processes, implementing a regular audit programme and insisting on technical compliance testing of your internal and internet facing IT infrastructure, as well as testing staff are adhering to these processes and policies - all aspects covered by the ISO 27001 standard - you stand the best chance of minimising the likelihood of a security breach."

Related links to this article:
HM Revenue and Customs

Related articles:
HMRC's lost Child Benefit data:The Chancellor's statement in full
HMRC's lost Child Benefit data: IPCC to investigate
HMRC's lost Child Benefit data: Conservatives slam Government
HMRC's lost Child Benefit data: Lib Dems attack Treasury incompetence
HMRC's lost Child Benefit data: SNP derides Chancellor’s credibility
HMRC's lost Child Benefit data: Gartner identifies new problems




Finalists announced in the 2007 e-Government National Awards
81 finalists (detailed at this link) have been chosen from among the record 527 nominations received in this year's e-Government National Awards 2007. 11 Awards categories will recognise this year's "best of the best" strategies, achievements, teams and individuals in UK public sector web, ICT & e-Government services. The judging panel was headed by Government Chief Information Officer John Suffolk (based at Cabinet Office).

The winners will be announced and presented with their e-Government National Awards on 22nd January 2008 at a black-tie dinner at the Dorchester Hotel in London. Finalists may book tickets at this link

Platinum sponsor is KPMG.
Also a sponsor is O2
.

The Awards are supported by the Government Chief Information Officer (Cabinet Office), the Office of Government Commerce, the Society of Information Technology Management (Socitm), and SOLACE (Society of Local Authority Chief Executives and Senior Managers).
Posted by: Editor 



Other latest articles on the subject of Central Government

· Mandelson looks to Germany for lessons in tech innovation   (5 Feb 2010 )
· ICT can make travel greener   (29 Jan 2010 )
· Impact of cuts on technology to be examined   (25 Jan 2010 )
· National ID cards available to London youth   (25 Jan 2010 )
· Gartner: The future is bright but it’s a long haul ahead for public sector CIOs   (19 Jan 2010 )
· e-Borders coverage levels revealed   (19 Jan 2010 )
· Challenges to Effective Collaboration in US Intelligence Community   (18 Jan 2010 )
· HMG breaks its own 10 day payment pledge to SMEs   (18 Jan 2010 )
· Salesforce.com pledges more dollars to Haiti relief agency appeal   (18 Jan 2010 )
· Cameron on energy: the UK is vulnerable   (18 Jan 2010 )

>>>More articles on Central Government>>>

L A T E S T   J O B S

My TechTenders.net Account:

My Website login
My Subscription login
Subscribe to TechTenders.net


My PublicTechnology.net contributer Account:

PublicTechnology.net Account
PublicTechnology Emails
About:

About us
Contact us
Terms & conditions of use
Privacy policy
RSS feeds: Publictechnology

Copyright:

Copyright Public Technology Ltd 2003-2009. Crown copyright material used under click use licence C02W0007583. Parliamentary material used under click use licence P2005000039, & reproduced with the permission of the Controller of HMSO on behalf of Parliament. EU tender information published under license from the European Commission.

This web site automatically and continually monitors, collects and publishes latest breakings news from a large number of sources. Copyright of content / material may belong to the original source.
Advertise to our audiences:

Advertising options
Directory listings
Advertise Jobs
Advertise Tenders
Promote Events
Sponsor the Awards
Publish press releases
Promote products or services
The Public Technology
digital information network:


Public Technology is the UK's foremost news & information provider for the public sector & its suppliers.

It comprises:
Techtenders.net
PublicTechnology.net
Jobs.PublicTechnology.net
Public Technology email alerts
PublicPolitics.net
PublicPages.net
WhitehallPages.net
EducationPages.net
EUmonitor.net
PublicTenders.net
NHStenders.net
e-Government National Awards