Advertisement
Promo

Security threats Toolkit

Civil servants 'lack security awareness'

Tom Espiner ZDNet.co.uk

Published: 01 Feb 2007 14:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A leading government advisor has heavily criticised low levels of awareness of security threats within the public sector.

Lieutenant General Sir Edmund Burton, a key advisor to the Cabinet Office on information assurance issues, said that with the exception of the police, defence and intelligence communities, public servants have little grasp of information security threats. "What keeps me awake at night is that, with some notable exceptions, across government there's too little awareness of the scale and breadth of the risk facing us at the moment," said Burton.

This systemic problem extends across all government departments, and is endemic at board level. Ignorance of information security threats at board level is actually more of a threat than the threats themselves, according to Burton. "No-one knows the scale of the risk. We need to energise boards. The technical risks are nothing compared with ignorance at board level," he said in a panel discussion at a British Computer Society (BCS) security event on Tuesday.

A senior member of the Cabinet Office's Central Sponsor for Information Assurance (CSIA), whose remit is partly to oversee the effective transmission of data threat information between public sector organisations, admitted that the problem did begin at board level, and that the situation would improve once a younger generation of civil servants reached seniority. "Senior civil servants will eventually be succeeded by people who grasp technology issues," the CSIA member told ZDNet UK. "People in that generation of senior civil servants are less adept at technology than people who've grown up with it."

The lack of risk awareness extends to information risk in governance, policy formulation and civil service culture. There is also a lack of awareness of technical countermeasures, system infrastructure, threats and vulnerabilties, how to improve skills and competencies, and how to perform risk analyses, according to the CSIA figure.

Steps are being taken within the government to address the perceived lack of security risk awareness. There is a network of "senior information risk owners", which liaises with the government CIO and CTO councils to refresh information assurance strategy.

But there is still a lot of work to be done, according to Burton. "In the area of information assurance they really need to understand and manage the information risk between organisations. [The problem] is hugely complex — the scale is large, and the complexities are new," Burton told ZDNet UK. "It's time for decisive leadership and partnering between the public and private sectors [to tackle the problem]."

The government recently announced two sets of controversial database plans — plans to form the database for the ID Cards National Identity Register from three existing databases, and plans to relax data-sharing laws so government departments can share information more easily.

Phil Booth, national co-ordinator for the "No2ID" anti-ID cards campaign, said that ordinary civil servants not having a grasp of security issues should "terrify" people. "That civil servants can't even assess security threats beggars belief. They are proposing major new pieces of the critical national infrastructure. To say they don't understand security should terrify anyone whose details are going to be on the system," Booth told ZDNet UK.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
9 out of 11 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Watchdog reveals illegal sale of phone...

The Information Commissioner's Office is preparing a prosecution file against a mobile operator's employees who allegedly sold on thousands of customers' details to a competitor. The... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters