Civil servants to get data breach training

Cabinet Office review calls for government departments to get their information handling skills up to date.

The review of information security in government published yesterday by Cabinet secretary Gus O'Donnell will introducing annual training for civil servants handling sensitive data.

The measures have emerged as part of plans outlined in the review to set up a new framework that is designed to improve the rules, responsibilities and scrutiny of data handling after a series of high-profile public sector data breaches, including the loss of sensitive personal details of 25 million UK citizens by Her Majesty's Revenue and Customs late last year.

The report said: "There will be mandatory training for those with access to protected personal information or involved in managing it, alongside new action to make clear that any failure to apply protective measures is a serious matter potentially leading to dismissal."

Other measures in the new framework include minimum encryption requirements, more rigorous IT systems testing, standardised data security roles in departments to establish clear levels of responsibility and data spot checks by that will be carried out by the Information Commissioner.

The Cabinet Office review was carried out at the same time as the Poynter Review into the missing HMRC discs and the parallel Burton Review into the loss of Ministry of Defence laptops earlier this year.

Both were damning in their assessment of a systemic lack of regard or responsibility for data security handling procedures in the government departments.

Featured Resources

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Evaluate your order-to-cash process

15 recommended metrics to benchmark your O2C operations

Download now

AI 360: Hold, fold, or double down?

How AI can benefit your business

Download now

Getting started with Azure Red Hat OpenShift

A developer’s guide to improving application building and deployment capabilities

Download now

Recommended

How LogPoint uses MITRE ATT&CK
Whitepaper

How LogPoint uses MITRE ATT&CK

15 Jan 2021
Weekly threat roundup: Microsoft Defender, Adobe, Mimecast
vulnerability

Weekly threat roundup: Microsoft Defender, Adobe, Mimecast

14 Jan 2021
Mimecast admits hackers accessed users’ Microsoft accounts
Security

Mimecast admits hackers accessed users’ Microsoft accounts

13 Jan 2021
What is public key infrastructure (PKI)?
Security

What is public key infrastructure (PKI)?

12 Jan 2021

Most Popular

IT retailer faces €10.4m GDPR fine for employee surveillance
General Data Protection Regulation (GDPR)

IT retailer faces €10.4m GDPR fine for employee surveillance

18 Jan 2021
Citrix buys Slack competitor Wrike in record $2.25bn deal
collaboration

Citrix buys Slack competitor Wrike in record $2.25bn deal

19 Jan 2021
Should IT departments call time on WhatsApp?
communications

Should IT departments call time on WhatsApp?

15 Jan 2021