Related Stories

  • Flattery will get you everywhere - social engineering and information security
    The widespread availability of personal information, along with employees being exposed to more data than they need to know, is making it easier for hackers to bypass the ‘human firewall’ of information security. SA Mathieson reports on the rising threat of social engineering
  • US standards drive Canadian information security
    An absence of legislation and the presence of the laissez-faire attitude has resulted in Canada being rather lax when it comes to information security compliance. Robin Arnfield looks at how US standards are driving the Canadian information security marketplace
  • A breach a day will keep the patients away - information security in the health sector
    The NHS web is made up of different management structures, different information security needs, and different budgets. Cath Everett looks for a medicine that will cure information security worries across the healthcare board
  • Educating children on data protection
    The use of biometrics and CCTV in school classrooms - installed to protect pupils - may just as easily put them at risk of other dangers. What, then, can be done to prepare our children for the big wide world of data protection? Rob Stringer reports…
  • Keeping sensitive information secure when staff is leaving
    Career loyalty is an endangered creature. Unlike our predecessors, today’s workforce is unlikely to stay committed to a job for five years, let alone their entire lives. But with such a fluid stream of employees keeping human resources busy, and countless eyes being cast over company data, Rob Stringer investigates how sensitive information can stay faithful to its organisation, even if its staff don’t...

News

Council staff breach security of National ID database

26 February 2009

The Department of Work and Pensions (DWP) have admitted that 33 public sector workers across 30 local authorities have accessed the Customer Information System (CIS) “without business justification”.

CIS will assist in shaping the biometric-based national ID card programme, currently containing biographical information on the majority of UK citizens, including benefit recipients, pensioners and anyone holding a national insurance number. Since July 2008, CIS has also provided access to HMRC tax credit data.

The breaches, dating back to 2006, were discovered via routine checks, but it’s unknown whether the breaches were made through malicious intent or misuse.

The ‘Housing benefit and council tax benefit general information bulletin’ from
15 January issued by the DWP said that the organisation “will support your [local authority] to ensure appropriate disciplinary or prosecution action is taken, and may consider prosecuting directly under social security legislation.”

In spite of the breaches, the DPW remains positive about their standards, stating that, "The small number of breaches shows that the CIS security system is working and is protected by several different audit and monitoring controls, which actively manage and report attempts at unauthorised or inappropriate access."

“These latest breaches highlight the general inexperience of local authorities when dealing with large amounts of sensitive data,” commented Ken Munro, director at IT security specialist, Secure Test.

“Central government understands protective marking of sensitive data, and vets staff appropriately, while many local authorities are found wanting in this area. Access to data such as this must be purely on a need to know basis, and should be carefully logged and reviewed on a regular basis.

“It is an incredibly difficult process to work out why one operator should or shouldn’t be viewing a particular record. Far better to vet the individuals concerned, so there is a far greater degree of assurance that they won’t be tempted.”

He added that “In cases like this, legislation can act as a deterrent but it’s not prevention.”

Susan Hall, partner and ICT specialist at law firm Cobbetts, remarked that “Surely this must be the final nail in the coffin for the government’s national ID card programme. If council staff are able to snoop at our records so easily and undetected for so long, then how can an even larger and more complex database be safe? Indeed - who guards the guards?

“It has been reported that ‘routine checks’ unearthed these cases” Hall continued, “but, if there are breaches dating back to 2006, then they are not proving very effective. Such negligence reinforces the need for custodial sentences for breaches of the Data Protection Act.”




 

 

This article is featured in:
Compliance and Policy Data Loss Encryption Identity and Access Management Public Sector

 

Comment on this article

You must be registered and logged in to leave a comment about this article.