ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Civil servants 'lack security awareness'

Tom Espiner ZDNet.co.uk

Published: 01 Feb 2007 14:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A leading government advisor has heavily criticised low levels of awareness of security threats within the public sector.

Lieutenant General Sir Edmund Burton, a key advisor to the Cabinet Office on information assurance issues, said that with the exception of the police, defence and intelligence communities, public servants have little grasp of information security threats. "What keeps me awake at night is that, with some notable exceptions, across government there's too little awareness of the scale and breadth of the risk facing us at the moment," said Burton.

This systemic problem extends across all government departments, and is endemic at board level. Ignorance of information security threats at board level is actually more of a threat than the threats themselves, according to Burton. "No-one knows the scale of the risk. We need to energise boards. The technical risks are nothing compared with ignorance at board level," he said in a panel discussion at a British Computer Society (BCS) security event on Tuesday.

A senior member of the Cabinet Office's Central Sponsor for Information Assurance (CSIA), whose remit is partly to oversee the effective transmission of data threat information between public sector organisations, admitted that the problem did begin at board level, and that the situation would improve once a younger generation of civil servants reached seniority. "Senior civil servants will eventually be succeeded by people who grasp technology issues," the CSIA member told ZDNet UK. "People in that generation of senior civil servants are less adept at technology than people who've grown up with it."

The lack of risk awareness extends to information risk in governance, policy formulation and civil service culture. There is also a lack of awareness of technical countermeasures, system infrastructure, threats and vulnerabilties, how to improve skills and competencies, and how to perform risk analyses, according to the CSIA figure.

Steps are being taken within the government to address the perceived lack of security risk awareness. There is a network of "senior information risk owners", which liaises with the government CIO and CTO councils to refresh information assurance strategy.

But there is still a lot of work to be done, according to Burton. "In the area of information assurance they really need to understand and manage the information risk between organisations. [The problem] is hugely complex — the scale is large, and the complexities are new," Burton told ZDNet UK. "It's time for decisive leadership and partnering between the public and private sectors [to tackle the problem]."

The government recently announced two sets of controversial database plans — plans to form the database for the ID Cards National Identity Register from three existing databases, and plans to relax data-sharing laws so government departments can share information more easily.

Phil Booth, national co-ordinator for the "No2ID" anti-ID cards campaign, said that ordinary civil servants not having a grasp of security issues should "terrify" people. "That civil servants can't even assess security threats beggars belief. They are proposing major new pieces of the critical national infrastructure. To say they don't understand security should terrify anyone whose details are going to be on the system," Booth told ZDNet UK.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
9 out of 11 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Server Team Leader

As well as a competitive salary, Morrisons offer a range of benefits including stakeholder pension, life assurance, annual profit share and staff ...

Head of Information

The hospitals are some of the most technologically advanced in the country, with state of the art medical and diagnostic equipment ensuring that ...

Scrum QA / Senior Test Analyst - Leading Financial institution

Candidates MUST have: Demonstrable experience and knowledge of Quality Assurance testing methods, test automation, agile and scrum QTP, WinRunner / ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments