The Leading News & Information Service For The Facilities, Workplace & Built Environment Community

ONS Head - Gaping Hole in Government Info Security

16 September 2016 | Updated 01 January 1970
 

Protecting information while re-designing public services and introducing the technology necessary to support them is an increasingly complex challenge that is leaving a gaping hole in security arrangements, writes Amyas Morse, Head of the National Audit Office.

To achieve this, the Cabinet Office, departments and the wider public sector need a new approach, in which the centre of government provides clear principles and guidance and departments increase their capacity to make informed decisions about the risks involved.

The Cabinet Office has not yet established a clear role for itself in coordinating and leading departments’ efforts to protect their information, according to the National Audit Office.

A report released week ending September 16 found that its ambition to undertake such a role is weakened by the limited information which departments collect on their security costs, performance and risks. It also notes, however, that the UK Government has a strong international reputation in some areas of information security and digital government.

Protecting the information departments hold from unauthorised access or loss is a critical responsibility for departmental accounting officers. Departments are, however, increasingly required to balance this responsibility with the need to make this information available to other public bodies, delivery partners, service users and citizens via new digital services. And increasing dependencies between central government and the wider public sector mean that the traditional security boundaries have become blurred.

According to the NAO, too many bodies with overlapping responsibilities operate in the centre of government, confusing departments about where to go for advice. As at April 2016, at least 12 separate teams or organisations in the centre of government had a role in protecting information, many of whom produce guidance. While the new National Cyber Security Centre (NCSC) will bring together much of government’s cyber expertise, in the NAO’s view, wider reforms will be necessary to further enhance the protection of information.

As accountability for information security is devolved to departments, government does not currently collect or analyse its overall performance in protecting information on a routine basis. This means it has little visibility of information risks in each department and has limited oversight of the progress departments are making to better protect their information.

Reporting personal data breaches is chaotic, with different mechanisms making departmental comparisons meaningless. In addition, the Cabinet Office does not have access to robust expenditure and benefits data from departments, in part because they do not always collect or share such data. The Cabinet Office has recently collected some data on security costs, though it believes that actual costs are ‘several times’ the reported figure of £300 million.

Some departments have made significant improvements in information governance, but most have not given it the same attention as other forms of governance. The Cabinet Office does not currently provide a single set of standards for departments to follow, and does not collate or act upon those weaknesses it identifies.

 

Skills shortage

In the context of a challenging national picture it has been difficult for government to attract people with the right skills. The government established a security profession in 2013, and has undertaken some initial work to establish professional learning and development. Demand for skills and learning across government is growing and is likely to continue to grow. According to the NAO, plans to cluster security teams may initially share scarce skills, but will not solve the long-term challenge.

According to the NAO, the Cabinet Office is taking action to improve its support for departments, but needs to set out how this will be delivered in practice. The NAO recommends that to reach a point where it is clearly and effectively coordinating activity across government, the Cabinet Office must further streamline the roles and responsibilities of the organisations involved, deliver its own centrally managed projects cost-effectively and clearly communicate how its various policy, principles and guidance documents can be of most use to departments.

Picture: The pace of change in government is leaving it open to security breaches

Article written by Amyas Morse | Published 16 September 2016

Share


Related Articles

Mercury Rising, Straw Dogs, Hot Fuzz, Top Guns, The Crown & Vikings

We've got an FM Digest so good you'd almost want to make a movie out of it. Mercury have taken the Almac contract; Elior are eliminating plastic straws; Tenon are...

 Read Full Article
Skanska Wins Contract for 20 Ropemaker Street

Skanska has won a £240 million contract to construct 20 Ropemaker Street in Central London for Great Elm Assets Limited, in association with Old Park Lane...

 Read Full Article
X Marks The Spot Of The Tallest Tower In Town

The City of London Corporation has approved 1 Undershaft - AKA The Trellis - which will be the second tallest building in the Capital after The Shard and thus the second...

 Read Full Article
Airline Company Guilty For Unsafe Operation of Passenger Lift

Flybe, the airline company, was sentenced on 4 February 2020 for the unsafe operation of a passenger lift. Meanwhile, a number of other firms have found themselves...

 Read Full Article
A Top Ten Guide To Making Your Venue More Accessible

Eight venues have received awards from the disabled access charity Euan’s Guide for their work welcoming disabled visitors – and this prompted ThisWeekinFM to...

 Read Full Article
Tackling The People Challenge Through Technology

Report - CBRE and ThisWeekinFM recently lead a delegation of experts to provide a briefing on technology in workplace and real estate strategy. The breakfast briefing...

 Read Full Article
Net Zero Rush-Through Criticised By Lords, Forum Claims

The Global Warming Policy Forum has claimed the House of Lords has rebuked the Government for rushing through a commitment to a Net Zero economy. The Forum refutes the...

 Read Full Article
Holland Match - It's All Gone Gooee Over There

ProptTech history has been made with global M&E firm Croonwolter&dros agreeing to connect the 5,000 commercial buildings it runs in the Netherlands  to the...

 Read Full Article
'IRA' Claim Parcel Bomb Responsibility In Correctly Coded Call

A claim has allegedly been made on behalf of the ‘IRA’ for the parcel bombs that were delivered to premises in the UK - using a recognised codeword. A call...

 Read Full Article
Emcor UK Takes Insurance On TFM Contract

Emcor UK, has been awarded a contract with multinational insurance company RSA Insurance Group which is being described as a total facilities management contract. It will...

 Read Full Article