NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Policy
Slice by Program

Ottawa doing a poor job on IT security says auditor generalFraser's report says Government not meeting its own minimum standards

By: Vanessa Ho(02/16/05)

The Canadian government doesn't meet its own minimum standards for IT security, Canada's auditor general said Tuesday.

In a report that pulled no punches Sheila Fraser dubbed the government's IT security efforts as "unsatisfactory."

"Two and a half years after revising its Government Security Policy the government hasb&to translate its policies and standards into consistent, cost-effective practices that will result in a more secure IT environment in departments and agencies," the report said. I am disappointed that the government still does not meet its own minimum standards for IT security, even though most of the standards have been well known for more than a decade.Sheila FraserCanada's Auditor GeneralTextThose findings - tabled in the House of Commons on Tuesday afternoon - are an update to a 2002 report that put IT security under scrutiny. Fraser expressed concern that the government has made little progress on the earlier report's recommendations.

"In many departments and agencies, senior management is not aware of IT security risks and does not understand how breaches of IT security could affect operations and the credibility of the government," Fraser told the House. "If security weaknesses allowed someone to access a database or confidential information, Canadians' trust in the government would be greatly eroded."

Her report warned that if a citizen's privacy were violated because of a failure to keep confidential information secure, "it could cause that person hardship and seriously undermine the government's efforts to deliver services to Canadians electronically."

In a news release on the report Fraser expressed disappointment that though most IT security standards have been known for more than a decade the government still does not fully comply with them. "It means government systems and the sensitive data they hold are vulnerable to security breaches."

Her audit found that - in general - departments and agencies have not adequately assessed IT security risks. It identified key security weaknesses in several (unnamed) government departments and agencies. These weaknesses include:

b" Failure to adequately control access to sensitive data and programs; and,

b" Inadequate networks security and network access controls.

The auditor general recommended that departments and agencies subject to the Government Security Policy provide the Treasury Board Secretariat with an annual schedule of planned IT security monitoring activities. "As more and more government services are offered on-line, individuals and businesses need to have confidence that the information they share will be well protected," she said.

The audit found most departments and agencies did not fully comply with the federal government's IT Security policy. Possible reasons for this, it said, include a shortage of money and people, as well as a lack of overall interest in IT security by senior management in government.

The report said compliance and awareness failures have broad implications and could "erode the trust Canadians have in the ability of their government to transact business online, in a secure and confidential environment." The auditor general recommended all departments and agencies should prepare timely IT security action plans, which would be reviewed in December, 2006.

A Canadian security expert agrees that Ottawa needs to pay more attention to IT security and says an overhaul of security technologies would be a good place to begin.

"[The government should] understand that some of yesterday's solutions are not applicable anymore and (should) look for new solutions and technology," said Brian O'Higgins, CTO for Ottawa-based Third Brigade, a software security firm. Outdated technology, he said, could lock down networks.

O'Higgins said the federal government needs to allocate more money to IT security. He estimated the Canadian government spends less than three per cent of its IT budget on security, which is relatively low compared to government investment in other areas of IT. In stark contrast, he said, the U.S. recently announced a 15 per cent IT security spending increase in its budget.

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Stalled PCI DSS compliance efforts put Canadian organizations in limbo: Hereb�s how to get back on track
You might have long ago abandoned your efforts to achieve full PCI DSS compliance, but herebs a report that offers some helpful ideas to get back on track again. It highlights the five bsticking pointsb that typically hinders PCI DSS compliance progress and suggests how to get unglued from the mess.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada