NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Registration
Slice by Program

MITS as a matter of trust

By: Bruce Cowper(12-12-2006)

Canadians expect privacy and secure transactions when conducting their government business online.

Ensuring that the Government of Canada has a consistent approach to IT security helps build trust in the overall system. This approach must link together the various programs and efforts of federal agencies and departments under a single framework.

The federal government is taking some important steps to provide guidance in the IT security area with the Management of Information Technology Security (MITS) standard. MITS is an operational security standard spearheaded by Treasury Board Secretariat that identifies a minimum baseline standard of care for IT security.

With high-level accountability and established security guidelines in place under the MITS standard, more and more Canadians will feel comfortable using the Web to conduct their government business. The result will be simpler, safer and better access for citizens, as well as a secure IT environment for departmental interaction and consolidated service delivery.

Essentially, the MITS standard is an extension of the Government Security Policy (GSP) and the Policy on the Management of Government Information. MITS itself is complemented with other operational security standards, as well as more detailed technical documentation available from other key departments and agencies such as the Communications Security Establishment and the Royal Canadian Mounted Police.

In September, federal departments had to submit a progress report to Treasury Board - the agency that is overseeing policy implementation around MITS compliance. All federal departments and agencies must comply with MITS by the end of the year. Treasury Board and a number of private sector organizations are helping federal departments and agencies prepare to meet this deadline. Ultimately, deputy ministers are responsible for IT security within their own departments and agencies, in accordance with the GSP, and the MITS standard should be viewed as a tool to help meet this obligation.

The MITS standard identifies over 120 mandatory requirements, but to help IT managers and other key stakeholders understand where security needs to happen, the specifications can be encapsulated by 20 technology categories, such as document management, risk assessment, identity management, vulnerability identification, disaster recovery and failover, and incident management.

The government is working with its partners in industry to achieve compliance both in terms of mapping the requirements of MITS to practical solutions as well as incorporating the lessons learned in implementing similar standards elsewhere.

Operationally, the standard helps government departments and agencies take a more complete view of their IT systems and assists in identifying the people, processes and technologies required to provide security and management across the board. There is great emphasis on understanding the lifecycle of IT systems and technology and how the way they are used changes over time.

It should be noted that MITS compliance is an essential step in the right direction, but additional guidance is expected to be shared in the future. For example, Treasury Board is working with several key departments and agencies to develop a federal IT security strategy as part of an overall approach to making government a safer place to conduct business.

Many of the government bodies will likely go beyond the MITS standard to address the needs of their departments and the users and citizens they serve. As a result, all Canadians can be assured that when communicating across various systems that each group has achieved compliance.

The information security landscape is continually changing, so it is important that the associated guidelines be both flexible and extensible. This ensures that the most effective and up-to-date guidance is being disseminated to those who need it.

A key driver for the MITS standard is the way in which Canadians use technology to connect with the government. Compliancy will be fundamental in providing Canadians with confidence about how departments protect our privacy and provide us with a secure way to conduct business across the government.

Bruce Cowper is senior program manager for Microsoft Canada's security mobilization initiative. He can be reached at bruce.cowper@microsoft.com


Read more articles on Security and Emergency Services in Canada
More information on Management of IT Security
Read news on National Security
More news on Canadian Government Technology
Complete coverage on Canada Inter-Government News site map
Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Stalled PCI DSS compliance efforts put Canadian organizations in limbo: Hereb�s how to get back on track
You might have long ago abandoned your efforts to achieve full PCI DSS compliance, but herebs a report that offers some helpful ideas to get back on track again. It highlights the five bsticking pointsb that typically hinders PCI DSS compliance progress and suggests how to get unglued from the mess.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada