Latest Comments
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM

HMRC slammed over child benefit fiasco

  • Email a Friend
  • Print Page
By Guy Dixon
Jun 27, 2008 9:55 AM
Tags: HMRC | slammed | over | child | benefit | fiasco

The Independent Police Complaints Commission (IPCC) has delivered a damning verdict on the loss of 25 million child benefit records at HM Revenue & Customs, citing widespread "culture failures".

The 59-page report found that staff were working on a "muddle through" ethos and that processes at the department were "far from what they should have been" in the run up to the loss of two CDs in October 2007.

"Staff found themselves working on a day-to-day basis without adequate support, training or guidance about how to handle sensitive personal data," the IPCC inquiry said.

"The IPCC uncovered failures in institutional practices and procedures concerning the handling of data, and the absence of a coherent strategy for mass data handling. Generally speaking, practices and procedures were less than effective."

The report was delivered in tandem with the final version of the Poynter review, headed up by PricewaterhouseCoopers chairman Kieran Poynter.

The Poynter review was equally scathing about the incident, accusing HMRC of "serious institutional deficiencies" and having "no visible management of data security at any level".

IT security vendors have been quick to join in the latest round of government bashing over data breaches.

Brian Spector, general manager at Workshare, suggested that the findings of both reports confirmed that government measures to protect sensitive information were wholly unsatisfactory.

"The government has today pledged to address the issue of data leakage through the use of training and a change in management structure," he said.

"But unless security policies are enforced through the use of proven technology it will face an uphill struggle in convincing the general public that it can be trusted with their confidential data."

Meanwhile, antivirus vendor McAfee pointed to the dangers of human error faced by all organisations.

A recent survey by the company showed that 98 per cent of UK office workers do not see the protection of corporate electronic data as their responsibility.

"Technology can always provide a back up, but employees need to be educated about why they should be careful with data, and usage policies are needed to enforce good data protection practices," said McAfee security analyst Greg Day.

Copyright © 2008 vnunet.com

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Breaches & Exposures Whitepapers