NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Technology
Slice by Program

THE BIG CHILL

By: Richard Bray(08/01/06)

Newton's Third Law works in the physical world, but politics is different. When citizens demand swift action, the reaction to every action is not equal. In a crisis, Newton's theorem could be restated as: "Every action results in bureaucratic overreaction, in direct proportion to the emotional impact of the headlines." The U.S. Sarbanes-Oxley legislation, or SOX, is a case in point.

In the late '90s, the blatant criminality of corporate executives at Enron, Tyco International and WorldCom outraged shareholders. People around the world lost money, but it was U.S. investors whose critical mass of indignation led to the Public Company Accounting Reform and Investor Protection Act of 2002, or Sarbanes-Oxley.

That law sets new standards of behaviour for directors, managers and accounting firms at publicly traded corporations doing business in the United States and calls for heavy fines and jail time for executives who fail in their duty to shareholders.

Even though the frauds that led to SOX had nothing to do with computer security, the legislation has had a direct impact on the management of IT networks because it requires corporate executives to assume responsibility for the accuracy of their financial statements.
That accuracy depends on the security and integrity of the company's computer systems.
In more innocent times, there was no detailed examination of an organization's internal information technology processes.

The IT department was seen as a "black box" that produced either accurate results or nothing at all. But those days of magic behind closed doors are long gone.

IT managers now have to show that they can produce verifiable results using well understood and widely accepted processes and controls.

How long can government IT administrators avoid the same level of scrutiny?
Every week, if not every day, brings fresh news about public sector data breaches, particularly in the United States.

Not long ago, for example, an Internal Revenue Service laptop computer with the names, Social Security numbers, birthdays and fingerprints of almost 300 employees and prospective employees was lost while being shipped to a departmental event. The laptop itself was secured by two passwords, but the data it contained was not encrypted.

In a more serious case, the U.S. federal government has been forced to pay for credit monitoring after confidential information about millions of former service personnel went missing in the theft of a Department of Veterans Affairs computer. For some reason, a data analyst took the names, Social Security numbers and birthdates of between 17 million and 25 million veterans home on a laptop. Almost three weeks elapsed before Veterans Affairs began notifying people that their credit might be in jeopardy. The department eventually paid about $14 million to notify veterans that their identities had been compromised, but that was just a small down payment on a bill that will certainly run to the hundreds of millions. A U.S. Senate committee has already voted $160 million in emergency funding.

At least one senior executive has resigned, and some have been reassigned, in the wake of this security breach, but it is hard to believe politicians will be satisfied. Why should they? And why should taxpayers and citizens be satisfied with expensive, time-consuming clean-up efforts that may or may not be effective?

Several weeks after that, information about 13,000 District of Columbia employees and retirees was stolen from ING U.S. Financial Services. Because the company had no idea what was on the missing laptop, stolen on a Monday, it did not begin notifying employees and retirees that their unencrypted Social Security numbers and other personal information was in the hands of a thief until the following Friday. (Two unencrypted ING laptops with information about 8,500 Florida hospital workers were stolen in December but they were not notified for months.)
Governments in the United States and Canada have not been at all reluctant to impose tight regulations and strict penalties on the private sector to ensure that citizens' data is well protected.

In Canada, under PIPEDA, the Personal Information Protection and Information Privacy Act, fines for breaches or non-compliance can be as high as $100,000.

The politicians who voted for intense scrutiny for the private sector did so on behalf of consumers and shareholders. When will they mandate some form of sanction to protect citizens and taxpayers?

To date, there has been little focused outrage about data breaches. Many victims have insufficient information about a specific incident to relate it to their own credit difficulties. They may lack the knowledge to express their anger to the right audience. Perhaps most importantly, the criminals who might make use of their stolen identities can be extremely patient, waiting many months before opening credit card and bank accounts to make purchases and transactions in others' names.

If public sector data breaches bring an increase in identity theft here, the result could be demands for SOX-like legislation for government operations, legislation that dictates not just the "what" but the "how," with severe penalties for organizations and individuals that fail to measure up. After all, why should shareholders and consumers have protection that citizens and taxpayers do not? They're the same people.

Richard Bray (rbray@itworldcanada.com) is an Ottawa-based freelance journalist specializing in technology and security issues.


Read about the state of Security and Emergency Services in Canada
Read more articles on Government wide security

Learn about Emergency responders

More news on Canadian Government Technology
Complete coverage on Canada Inter-Government News site map

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Stalled PCI DSS compliance efforts put Canadian organizations in limbo: Hereb�s how to get back on track
You might have long ago abandoned your efforts to achieve full PCI DSS compliance, but herebs a report that offers some helpful ideas to get back on track again. It highlights the five bsticking pointsb that typically hinders PCI DSS compliance progress and suggests how to get unglued from the mess.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada