Advertisement
Promo

Security threats Toolkit

Learning from UN's security failure

Leader ZDNet.co.uk

Published: 14 Jan 2009 17:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment
Learning from UN's security failure

Those who prefer convenience to security may find they end up with neither.

This is the fate of the United Nations Galileo logistical system, which has failed an internal audit. As Galileo is responsible for the international disposition of $2bn (£1.4bn) worth of material, including aid, medical and military supplies, there is no overstating the importance of the report's conclusions: network links were insecure, no mechanisms existed to detect security breaches, and authentication information was devastatingly unsafe.

To add to the fun, backup systems were co-located with the main systems, with frightening implications for business continuity. A determined, informed opponent could have done a great deal of damage at little risk. With IT skills and equipment now widely available even in the remotest of theatres, the UN has placed itself at considerable risk — a risk to which it was seemingly blind.

How did this happen? The headline reason was that there was nobody in charge — but, like most headline reasons, that begs the question of why.

The UN is constantly, pathologically underfunded. Decisions were therefore made on contingency, in a spirit of making do. Communications bandwidth too narrow for encrypted traffic? Send it in clear — problem solved, for now.

It isn't hard to understand the psychology behind such actions: making stuff work means no explanations to the boss, no struggle for extra resources, no difficult decisions to close down important services on which large parts of the organisation depend. It's also not difficult to see what can go wrong as a result.

In these difficult times, we must be careful not to succumb to the same pressures. When an organisation is in survival mode, resources are being husbanded and everyone's working flat out, it takes a particular strength of spirit to say "no, not good enough" to something that's apparently working well. It's also hard work to justify more spending with no direct effect on revenues, and to demonstrate that something that seems optional is in fact essential.

Yet this responsibility cannot be abdicated. It is hard enough for an organisation to recover from a serious security breach at the best of times. These are not the best of times. Argued from the context of minimising risk, the value of doing it right is clear. Make sure you're equipped to win that argument — and that, unlike the UN, you have all your bases covered.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
15 out of 18 people found this useful


Full Talkback thread

1 comment

  1. Super Civil Service 1000215420

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters