NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Program
Slice by Program

Making Secure Channel work

By: Richard Bray, CIO Government Review(03-12-2007)



Secure Channel will be mandatory for all federal government departments and agencies. At last. But just as no good deed goes unpunished, it seems no good decision goes unquestioned.

As winter tightened its icy grip on Ottawa, the House of Commons Public Accounts Committee was planning to put Secure Channel on the hot seat, with the flames underneath fed by incendiary newspaper accounts calling it "the technology system that no one wants to use" and quoting anonymous bureaucrats calling it "the monster" and a "white elephant." No one ever claimed Secure Channel would be simple or cheap. But neither has anyone yet claimed it doesn't work.

As infrastructure, Secure Channel was arguably ahead of its time, using the hardest security technology available, then or now. PKI, or Public Key Infrastructure, can be described as cumbersome, but so is getting a passport. Newspaper reports were careful to point out there was plenty of off-the-shelf alternatives to Secure Channel that were both less costly and less complicated. Of course, if you could get travel documents at the local convenience store, then getting a passport wouldn't be such a nuisance either. The federal government stands by its passports, it plans to stand by Secure Channel, and it doesn't plan to offer any alternatives.

The point was made that banks and credit card companies have been getting by without security standards as high as Secure Channel's. But, as former Public Works ADM Michael Turner points out (Turner was in charge of Secure Channel's early construction), banks and retail firms have been putting up with security failure rates that no government could even consider tolerating. In fact, they are now contemplating, if not already implementing, much tighter security.

It was always intended that all departments would ultimately buy into Secure Channel, but some argue that since deputy ministers have full responsibility for security within their departments, it's only fair they have the choice of products. Part of that range of choice, however, meant tinkering and fiddling with the Secure Channel product to make it acceptable to their department's unique requirements. While it's unknown just how far the Secure Channel team went to meet client demands, the Canada Revenue Agency probably stood out as especially demanding.

Critics of Secure Channel have seized on the story of Canadians abandoning online registration with Canada Revenue because they did not want to wait five days to receive their out-of-band passwords in the mail. Wait a minute. For purposes of filing income tax online, using only SSL encryption, Line 150 of last year's tax return has been a perfectly acceptable shared secret for some years now - but when it comes to Secure Channel, the agency must turn to Canada Post?

There may be a valid reason for CRA turning to snail mail to deliver Secure Channel passwords, but dozens of other departments and agencies have been managing to deal successfully with the public, businesses and other government departments over Secure Channel for several years now, without licking a single stamp.

The auditor general has taken Secure Channel to task for not having a business case, but it's impossible to forecast uptake when your customers are really your colleagues, and sometimes even competitors for the scarce resources of budgets, headcounts and prestige.

Another argument against Secure Channel suggests that major shared services don't work. Turner has little patience with that one: "Enterprise-wide shared services systems have already been mandated and implemented in other governments, including several provinces and of course many companies, saving millions annually. Just ask companies like IBM or Accenture."

Recently it has been common wisdom if not certain knowledge that Secure Channel would become mandatory. A strong hint came two years ago when the report of the Information Technology Services Review said: "Secure Channel needs to be leveraged as the first element of mandatory common IT service infrastructure because it underpins IT telecommunications connectivity and the security of data transmission."

Secure Channel is not one technology, but many. Within certain limitations, it can be customized and tailored to meet special cases, but there is no longer an argument that a department, branch, program, policy or process is unique and therefore exempt from a shared security service.

Uniqueness must express itself within a narrower range. On the other hand, departments will pay for Secure Channel from their own budgets, and that can only mean leverage over present performance and future design. It is now in everyone's interest to make the best of a good situation, sharing the management as well as the cost.

Richard Bray is an Ottawa-based freelance journalist specializing in high technology and security. He can be contacted atrbray@itworldcanada.com

Related content:

Managing identity: Data sharing meets privacy

Auditor General's Report: Large information technology projects

The new face of inter-governmentalism

Still a struggle: Security, privacy driving IM agenda

BC OnLine boosts public-private collaboraion

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Info-Tech Research Note: WAN Optimization Tools worth the investment
Multi-site enterprises experiencing WAN bandwidth demand growth and struggling to maintain acceptable application performance should evaluate WAN optimization technology immediately. WAN optimization appliances can dramatically improve inter-site WAN performance, reduce bandwidth requirements, and allow for server centralization. For many enterprises a positive ROI can be achieved in less than a year. Download this research note now. Complimentary with registration.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada