shadowy figure
R E L A T E D   C O N T E N T
ADVERTISEMENT

Government plans to store comms data

Proposed database could mean logs of all phone calls, emails and internet usage are centrally stored

Phil Muncaster, IT Week 20 May 2008
ADVERTISEMENT

New government proposals for a database to store details of all phone and VoIP calls, emails and internet usage by UK citizens could force firms to look at their corporate communications policies more closely, according to experts.

The proposals are part of the draft Communications Data Bill which has yet to be fully released, and would extend the current requirement for telcos and service providers to store details of phone calls and text messages for 12 months.

It's unlikely that the government will require corporates to hand over data relating to their internal communications and those sent encrypted by private channels to third parties, argued Mike Smart of security vendor, Secure Computing.

But the proposals may persuade CIOs to re-examine their controls on data in transit. For example, if users are sending out confidential data via webmail or other unregulated channels, the records may end up in the proposed government database.

"Sometimes it takes regulations to remind people to think about what they're doing, why they're doing it and what's the best practice [around sending data], " he added. "CIOs will have to decide what they consider to be important data and ask 'should I be looking to put local controls in place?'."

Others were quick to attack the government's poor track record on guarding its citizens' data.

"If the government is to avoid another high-profile data breach which could expose even more people to the risk of identity fraud, effective controls need to be put in place with immediate effect," argued Brian Spector of data protection firm Workshare.

Chris Dean, director at independent IT consultancy DMW Group, argued that the government may struggle to find a cost effective way to "manage the storage, movement, and retrieval and deletion of data".

"In summary the project will be expensive, and risk failure – as with all large projects. [It could even] threaten civil liberties," he added.

Aside from the risk of internal threats, hackers may target the data as it is transported from ISPs and telcos to the government database, according to Toby Weiss, chief executive of security firm Application Security Inc.

When Fort Knox was constructed one of the key concerns was how to move the gold into the vault, he explained. "In this case you'll have new data going in and probably coming out all the time – it's a big concern."

These concerns were echoed by the Information Commissioner's Office.

‘If the intention is to bring all mobile and internet records together under one system, this would give us serious concerns and may well be a step too far, " wrote assistant information commissioner Jonathan Bamford in a statement. "We have warned before that we are sleepwalking into a surveillance society. Holding large collections of data is always risky; the more data that is collected and stored, the bigger the problem when the data is lost, traded or stolen."

See also:

The Information Commissioner has finally got his wish, increased powers to tackle data breaches  09 May 2008
Increasing sensitivity about corporate repuations is spurring actions on leaks  25 Apr 2008
richard thomasTough penalties need to be used to protect personal data, says commissioner  23 Apr 2008
padlock on keyboardEC study reveals current law not suited to protecting online transfer of personal data  18 Apr 2008
prisonWebsense survey finds IT is not to blame  08 Apr 2008
houses of parliamentJoint Committee on Human Rights criticises "lax standards"  14 Mar 2008
padlock and chainSecurity breaches have far reaching implications for businesses finds report  27 Feb 2008

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
West Midlands, Warwickshire, United Kingdom | Latham
System Tester/Test Analyst £27K-£32K + bonus, flexitime, 35 hour week, South Warwickshire, West Midlands. System Tester, Test Analyst, Systems Tester. Large financial services company looking for proven Testers and Test Analysts. Do you have at least ... more >
Elstree, United Kingdom | NHS Blood and Transplant
  Operations Engineer, Bio Productory Laboratory,  £28,313 - £37,326 pa plus High Cost Area Supplement, Elstree About us The National Blood Service is an integral and vital part of the NHS. Our two million volunteer donors contribute ... more >
United Kingdom | London Borough of Kingston
Community Services, Housing, Performance & Information Officer, £29,286 - £33,285 p.a. , For 36 hours Responsible for performance and information management, you'll be a key member of the Housing IT Team on both an operational ... more >
South West, Darlington, United Kingdom | University College Falmouth
  Web Sharepoint Development Manager, £23,692-£26,665 (£29,138) per annum (Grade 5) The creation of a new University for the Arts in the South West has taken a major step forward with the merger of University ... more >
More job opportunities