Plugging public sector data leaks
By Stephen Pritchard,
COMMENT: News that a full 132 local authorities have lost citizens' data over the last three years will surprise few security experts, and few CIOs.
Central and local government in the UK has progressively tightened policies around data security, improved access controls, and invested in data loss prevention technologies. Since the loss of the records of 25 million people by HMRC in 2007, controls over how data is stored and shared have become more rigorous. But as the latest research, compiled by Big Brother Watch, shows there is still a long way to go.
It is increasingly hard to avoid the conclusion that the issue is less one of technology, than of attitudes.
Nearly a third of councils lost data, Big Brother Watch found, and only 55 out of 1,035 incidents were reported to the Information Commissioner's Office. The privacy group had to resort to Freedom of Information requests to obtain the information, which in itself says a lot about a lack of transparency around the issue, in some public sector circles.
And it is increasingly hard to avoid the conclusion that the issue is less one of technology, than of attitudes. Although it is by no means the case everywhere, a significant minority of public sector staff appear to have a less than responsible attitude to the personal data they hold.
Nor do managers seem to be enforcing existing data security rules withy much rigour; according to Big Brother Watch, just nine of the one-thousand-plus data breaches resulted in a member of staff losing their job. In some authorities, copying personal identifiable data onto insecure or personal devices, including laptops and USB drives, seems to be tolerated at the very least.
Tim Patrick-Smith, CTO of IT services provider Getronics, describes a scenario where CIOs are "playing catch up" with staff who increasingly use consumer devices at work, and who need to balance flexibility with security policies. But he also suggests that a change in approach to data security – with the data, rather than devices, being secured -- may be the only practical way to solve the problem.
Another answer could lie in a new EU data protection framework, expected as early as January 2012, which may force organisations to report data breaches. This would follow a similar model already operating in California.
"A statutory duty to report a data security breach should help focus the collective mind of management boards on the importance of clear corporate governance and controls over the safeguarding of personal information," suggests Sally Annereau, a data protection analyst, at law firm Taylor Wessing.
But if councils do not act, and act soon, citizens will become increasingly wary of handing over all but essential data to local government. If that happens, it will make it harder to roll out e-government services. And that will cost everyone more in the long run.
Stephen Pritchard is a contributing editor at IT PRO.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Public Sector News
ACTA legality set for EU court scrutiny
The European Court of Justice is being asked to look into the legality of the controversial parts of ACTA.
advertisement
Most popular
- Olympics Wi-Fi will be ?an unmitigated disaster?
- Will the FBI close down your online business this March?
- Ubuntu vs. Windows 7 on the business desktop
- Brit Facebook hacker jailed
- Motorola claims Apple files EU patent complaint
- Google scores 90,000 Apps seats at Roche
- Google removes another 37 rogue apps from Android Market
- GoToMyPC for iOS review
- Rolling out iPads in the enterprise
- Transparency? What transparency?





Chris Mayers, chief security architect, Citrix
The news that 132 councils have lost personal data over 1000 times in just three years shows that the discipline of Information Assurance is still needed. Today, public sector bodies are all too aware of the potential risks to their sensitive data. Now that reporting of such incidents is mandatory elsewhere within government, there is every incentive to ensure compliance. As a result, IT security needs to be focused on understanding business need and making the right choices. Information Assurance remains the ideal approach, since it is risk-based and allows organisations significant flexibility in deciding how security requirements are met. For example, with the explosion of consumer devices coming into the workplace, different employees have different IT needs. As a result, IT needs to be able to enable different classes – or risk levels – of data to be handled securely, but with a solution that won’t unduly restrict access, or productivity. When budgets are constrained, this will be achieved through spending money on technology that is proportionate to the risk involved, and tiering access accordingly. Ultimately, applying Information Assurance not only helps organisations to follow the security rules, but also extracts real business value while providing flexibility as IT security continues to evolve.
By JamesStevenson_Citrix on Monday Nov 28