TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
News Archive

Facebook Generation

by Msecadm4921

Of a trio of official reports in government security lapses, the one about the Revenue and Customs lost discs (holding 25m people’s details about child benefit) got the most publicity. Arguably, however, more intriguing for the security person was the Burton Review – the report by Sir Edmund Burton into the January loss of a laptop from Birmingham. It appears that the ministry has yet to get to grips with securing the likes of PDAs and memory sticks, that hold (far more) data than old-fashioned paper.

Sir Edmund flagged up the โ€˜Facebook Generationโ€™. As he wrote of the Ministry of Defence (MoD): "The department recruits from, and exists within, a culture where the rapid and often uninhibited exchange of information is the norm. At work, this behaviour must be tempered by common sense and sound judgement, informed by data protection practice, and the particular concerns of MoD work. However, returning to strict information control of the type applied to paper documentation of 15 or more years ago is not considered practical in the modern working and cultural environment … One consequence of embracing this new data-sharing culture has been a decline in overall departmental security practice. The evidence for this is mainly anecdotal, but a considerable number of senior officials concurred on this point. They shared a concern that the younger generation of MoD staff are not inculcated with the same culture of protecting information as their counterparts from previous generation."<br>Let’s put it another way: staff whose careers dated from the Cold War took it for granted that information was only given on a ‘need to know’ basis. A new generation that has grown up since the Cold War sees nothing wrong or odd about putting personal, even intimate, things about themselves on social networking websites, such as Facebook. To return to Sir Edmund: he said ‘it is impractical to return to a strict โ€˜need to knowโ€™ culture. However, recent incidents suggest that unmanaged โ€˜need to shareโ€™ practices lead to unacceptable vulnerabilities’. This challenge – of getting the balance between necessary security and the freedom of information that ‘the Facebook generation’ takes for granted – is not just for the MoD but for all organisations, Sir Edmund suggested. ‘During the Cold War, awareness of real security was ingrained in individuals and organisations. Audit, inspection, and compliance regimes were rigorously underpinned by codes of discipline. These well developed processes and procedures have not been translated, effectively, into the information age. Furthermore, there seems to be a lack of awareness that, in the information age, the behaviour of each individual is a significant factor in the risks faced by the parent organisation. Achieving such awareness and appropriate codes of personal and corporate conduct, with effective governance, represents an urgent, high priority task for leadership teams across the UK: in central and local government, across the private sector, academe and throughout the education community.’ <br> <br>The report found that a ‘culture of formal, rigorous Information Risk management and security of personal data has yet to be embedded’. As Sir Edmund put it: &quot;MoD has, traditionally, placed a high priority on classifying and protecting documents and information that present a security risk to defence capabilities. However, the same degree of rigour and corresponding level of resource has not yet been applied to the protection of information and data held on electronic devices.&quot; <br><br>His review followed the theft (on January 9) of a Royal Navy (RN) recruiterโ€™s laptop, not encrypted, which contained unencrypted personal records for more than 600,000 recruits and potential recruits. – stolen from a parked car in Edgbaston. In the small print, it turned out the loss was more like 1m, because also about 400,000 next of kin and referee records were on the database. As for the details of the theft that prompted the review; the (junior) officer involved in the loss of the laptop has been the subject of ‘administrative action’. The stolen laptop was one of ‘a small population of 51 laptops’, which hold a large database incorporating over 600,000 personal records. &quot;Investigations revealed that a total of four of these laptops have been stolen since 2004 (all from parked cars). Only the recent theft appears to have led to disciplinary proceedings. Although the security instructions for the safe-keeping of laptops were clear in prohibiting them from being left in unattended vehicles, they did not dictate that the data must be encrypted. &quot; The review called this ‘a failure of supervision’: &quot;It is likely that the Department was in breach of several principles set out in the Data Protection Act…&quot; <br>The review found also that the standard of reporting of losses laptops, PDAs and USB storage devices was ‘inconsistent and unsatisfactory’, despite a policy to record such thefts. The reviewers spoke to 70 MoD and services people; and besides, to gauge commercial good practice, unnamed ‘senior private sector managers charged with the management of information risk and personal data security’. <br><br>The report spoke on three concepts – security (‘physical, personnel, procedural and technical measures and regulations in place’), data protection, and Information Risk Management (‘the policy, principles and culture ‘).<br> <br>MoD owns an estimated 35,000 laptops, of which some 12,000 are unencrypted. The review noted that MoD is in the process of ensuring that all but 2,000 of the entire laptop fleet will be equipped with full-disk encryption.; and these remaining 2,000 laptops will be taken out of service. Lost or stolen MOD-owned laptops numbered 130 in 2007. Out of a total laptop population of 35,000, this represents a loss rate of about 0.4 per cent: &quot;A comparable figure for industry and the wider population is an annual loss/theft rate of between 1 and 2pc.&quot; <br> <br>The review recomendations included: the MoD to audit its total personal data holdings; to instigate a full census of non-laptop removable media device holdings; the MoD to produce clear policy on sharing personal data with third parties, including changes to standard contractual clauses as required; and a coherent, Joint Service and Civil Service, awareness campaign ‘to highlight the importance of information and data as a key operational and business asset’. The review summed up: &quot;MOD, as with all organisations which hold and process large amounts of personal data, will always be at risk of future losses, perhaps significant ones. In that context the Department must improve its recording procedures, learn from the experience of recent losses, and do all this with the full knowledge that such incidents cause significant operational and reputational damage.’ <br>Protection of personal data is not simply a matter of the security and risk management procedures applied to its handling, according to the report. &quot;As a general principle, the more information an organisation holds, the harder it will be to protect it. The evidence suggests that the Department holds a very considerable amount of personal data (some 60 million personal records, much of it duplicated), without a clear business case for doing so on such a scale.&quot; Hence Sir Edmund’s call for an audit.<br><br>Background<br><br>Sir Edmund Burton, who is chairman of the Information Assurance Advisory Council and supports the Cabinet Office in the implementation of the Government’s information assurance strategy, was invited to conduct a full investigation into the circumstances that led to the loss of the data in January 2008 and consider the broader MoD approach to data protection.<br><br>The Ministry of Defence has accepted all of Sir Edmund’s 51 recommendations and has prepared a comprehensive action plan to implement them. Published alongside the report, the action plan has drawn on the broader findings of the Cabinet&#160;Secretary’s Review of Data Handling Procedures in Government, whose final report has also been published today.<br><br>Permanent Under Secretary, Bill Jeffrey said: &quot;We deeply regret the losses of personal data. We have identified weaknesses within parts of the MoD that led to this situation and I am confident that we are taking the necessary steps to address them. I am absolutely determined to make sure that we learn the lessons arising from the loss of this data and that we should do everything possible to make sure that this type of thing does not happen again.&quot;<br><br>Read the full report via this BBC news link: <br><br>http://news.bbc.co.uk/1/hi/uk_politics/7473818.stm