Way wayyyy OT - guess the subject.....

Nov 20, 2007 64 Replies

I don't agree it was as you say the monkey on the floor.

It simply shouldn't be technically permitted to download all this stuff from the main computer on to a CD. Not by anyone, not a monkey. Not the top man, not the PM.

What we don't know is how often these sort of downloads are done, who authorises them, what protection is there to prevent unauthorised downloads etc. etc..

But the reason these companies have all this data in the first place is because the government has insisted on it in the name of preventing money laundering etc. You can't run a bank account, engage a solicitor, scratch you ar** or anything without giving someone a copy of one of you vital documents.

The reason the head honcho was booted out was because the correct policies were not followed by the monkey on the floor, if the correct policy had been followed and the CD had been lost, he would not have had to step down! Stupid I know, but that's the rules. I suspect he "was resigned" to try and head off a furore. Chances are he was quite happy to take the payoff and retire.

I'd totally agree that the way such data is treated is IMHO cavalier and I've always boggled at the idea of it being regarded as "safe" to just put sensitive information into two envelopes and send it in the post without any encryption at all. When I was first required to do this, I queried if it was correct as the data was sensitive and I would never send such stuff when working in the commercial sector without proper encryption (and I don't mean passwords on word files or zip files).

However, the head honcho booted out over this had nothing to do with this daft policy, it's government-wide and similar is done overseas. I think it's daft meself.

There's a lot of issues with policy not keeping up with technology, I can't give examples but I've worked on projects where I have tests to perform that were written 6 years previously and when I spot a major problem that's not in the spec, then it's regarded as "out of scope" and I'm not even allowed to put it in the report. Not all are like that, just some where the test requirements have been written with too much precision by someone who doesn't do the technical side of security.

Surely, even under the data protection act, they have the duty to apply the strictest confidentiality to just one individuals personal details. When the data covers the details of 25 million then it must be afforded the even higher caveat of secret and handled accordingly. Also, under the data protection act, is there not a non-disclosure to any other parties/individuals clause? Surely the government department is guilty of breach of the act of parliament?! The NAO specifically instructed HMRC not to send all of the details - on three occasions - probably all too aware that both departments would be swimming in murky water if, as has unfortunately but almost inevitably happened, the data got lost or somehow leaked. Meanwhile, Brown is rather conveniently swanning around on some foreign junket and "eyebrows" Darling is hiding in a bunker somewhere....

Steve

Under the DPA they have to take "appropriate precautions", i.e. they have to show that they are trying and are following proper procedures, in this case proper procedures permits the sending of unencrypted data in the post so the DPA isn't an issue other than the person doing the posting deciding to use a courier rather than the post office (which makes no difference other than violating procedure).

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required