Information Security Recent UK experiences
Paul J Jackson Information Security and Legal Services Division ONS
Information Security Recent UK experiences Paul J Jackson - - PowerPoint PPT Presentation
Information Security Recent UK experiences Paul J Jackson Information Security and Legal Services Division ONS Timeline 18 October 2007 25m records sent to National Audit Office On 2 unencrypted CDs Sent in standard internal
Information Security Recent UK experiences
Paul J Jackson Information Security and Legal Services Division ONS
20 November 2007 (+27 days)
QuickTime™ and a decompressor are needed to see this picture.
ONS figures for data in transit for 2007 to this date:
CD
recipient
Interim review of HMRC requires:
(i.e. - shutdown)
Assurance Strategy
citizens, businesses and government use and enjoy the full benefits of information systems with confidence
a/assets/nia_strategy.pdf
Power of Information Report 2007
to improve Digital Participation”
http://www.cabinetoffice.gov.uk/reports/power_of_information.aspx
The Coleman Report 2008
“Government must do more to deliver confidence in its information infrastructure”
http://www.computerweekly.com/blogs/stuart_king /Coleman%20Report.pdf
QuickTime™ and a decompressor are needed to see this picture.
2008
“a digital switchover for public services”
http://www.culture.gov.uk/images/publications/di gitalbritain-finalreport-jun09
Government Chief Information Officer
Government Security Policy Framework 70+ mandatory requirements :
1. Governance, Risk Management and Compliance 2. Protective Marking and Asset Control 3. Personnel Security 4. Information Security and Assurance 5. Physical Security 6. Counter-Terrorism 7. Business Continuity http://www.cabinetoffice.gov.uk/spf.aspx
Statistics and Registration Service Act 2007
Statistics
data
Freedom of Information Act Data Protection Act Human Rights Act Common law of confidentiality Computer Misuse Act
Judicial Review of public administration The Information Commissioner The Financial Services Authority The Information Tribunal Select Committees of Parliament UK Statistics Authority
Owen Pengelly Head, Information Security & Assurance Cabinet Office
Information is an asset and a liability
approach
UK Knowledge and Information Management Profession:
Senior Information Risk Officer
information
assessment process
the statement of internal control.
Information Asset Owner
leaves - and why
provides assurance to SIRO
Departmental Security Officer
SIRO
framework
Information Technology Security Officer
systems
…plus 65 others…
…plus many others…
QuickTime™ and a decompressor are needed to see this picture.
Began on 20th November 2007… …and by definition will never end
Data Sharing Committee Chair - Head of Sources Members - selected experts Meets 1/4ly Micro-data Release Panel Chair - HoP Statistics Members - selected experts Meets virtually Data Stewardship Group Chair - HoP Statistics Members - Senior business managers Meets 1/4ly Security Committee Chair - DSO Members - corporate IS officers Meets 1/4ly Information Exploitation and Assurance Committee Chair - SIRO Members - IAOs and DSO Meets 1/4ly SIRO DG ONS
QuickTime™ and a decompressor are needed to see this picture.
QuickTime™ and a decompressor are needed to see this picture.
QuickTime™ and a decompressor are needed to see this picture.
QuickTime™ and a decompressor are needed to see this picture.
*Society of Information Technology Management
A timely wake-up call It should be easier to do the right thing than the wrong thing. Innovation is essential Web 2.0, data cubes, visualisations, API, creative commons licences Internet data collection
365 data losses formally reported so far in 2009 (At least we know) So far only costs - benefits down the line, we hope.
Do your data flows look like this :
etc. etc.