R E L A T E D   C O N T E N T
ADVERTISEMENT

UK Government was warned on data loss

Risk assessment raised concern about junior staff access in 2004

Matt Chapman, vnunet.com 10 Dec 2007
ADVERTISEMENT

The UK Government was warned that allowing junior staff to access the child benefit database was a security risk three years before discs containing 25 million records were lost.

Treasury risk manager Richard Fennelly carried out the assessment in March 2004 and sent a letter warning of weak procedures to the Treasury.

That revelation will cause embarrassment for current Prime Minister Gordon Brown, who was Chancellor of the Exchequer at the time.

"Fraudulent/malicious activity was not being detected," said a copy of Fennelly's comments obtained by the News of the World.

"Live support staff had root access and could do anything without being detected with obvious risks."

Fennelly also warned that there was "no encryption between certain elements in the system".

Shadow work and pensions secretary Chris Grayling said the document rubbished Gordon Brown's claims in Parliament that the data breach was a one-off incident.

"Now we know that internal watchdogs in the government were warning three years ago that the child benefit database was at risk," he told the News of the World.

"Because no one took any action we now face a situation where millions of bank account details and information about all our children has been lost."

HM Revenue and Customs (HMRC) lost discs containing the child benefit records of 25 million people, including the bank details of 7.25 million families, when it sent the unencrypted data through the regular postal service.

Information Minister Richard Thomas has warned that other damaging data loss incidents could emerge, as several public bodies have secretly admitted to losing data following the HMRC crisis.

See also:

Managing risk is biggest driver behind security strategies  10 Dec 2007
Greatly increased threat to UK business  06 Dec 2007
Information on 8.5 million customers on sale for five years  05 Dec 2007
As little as £1 buys you an active bank account  03 Dec 2007
Companies know there is a problem, claims SanDisk  15 Nov 2007

All Public Sector IT

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
| Aston Carter
Your role will be working on direct market access and exchange connectivity part of the application built in C++ on a Unix platform. The team is currently just 9 people including architect and team lead, ... more >
| Aston Carter
This is a fantastic opportunity working for a leading global software house, which is part of a larger multi media company. The role is working in the core development team in central London developing a ... more >
| Aston Carter
C++, Developer, OO, Unix/NT, API, London, City, Graduate A senior core C++/ Unix developer wanting to work in the heart of the city for one of London's most successful companies is required. The successful candidate ... more >
More job opportunities