Showing posts with label government. Show all posts
Showing posts with label government. Show all posts

Saturday, 17 January 2009

Government Security - Miss Security Target



Just 27 percent of IT systems at the Ministry of Defence and its agencies fully meet government security guidelines, the secretary of state for defence has admitted



Bob Ainsworth revealed the statistics on Monday in a written reply to a question from Conservative MP Shailesh Vara. In the reply, Ainsworth wrote that 58 percent of IT systems at the ministry and its agencies have been through the security accreditation process laid out by the government a year ago. The systems range from corporate IT set-ups serving thousands of users to business-level systems used by smaller groups.

Only 27 percent of these systems are fully security accredited and are being operated within the ministry's "senior information risk owner (SIRO)'s risk appetite", according to Ainsworth, which balances security risk against operational reward. The other 31 percent have conditional or interim accreditation, "with constraints placed on the operation of the system to ensure that identified risks are adequately managed within SIRO's risk appetite". The guidelines in question were instituted after an MoD laptop, containing the details of 600,000 people, was stolen. They cover issues such as the ability of staff to put sensitive or personal information onto flash drives or laptops — which may be mislaid — and the need to encrypt information. Forty-two percent of systems are not accredited at all. "This represents the significant workload undertaken to plan and develop solutions for new equipment systems or platforms," wrote Ainsworth. "This also includes applications from legacy systems, many of which will be migrated onto the developing defence information infrastructure."

Ainsworth's breakdown covered systems whose accreditation is controlled centrally by Defence Security and Standards Assurance (DSSA). These number in the hundreds. In addition to systems connected to Ministry of Defence networks, the total includes systems not connected but which contain sensitive or personal data — those given a rating of "stand alone above Secret" or "contain significant value to the MoD".

Platforms and systems that are not security-checked by the DSSA are not included.
On the same day, Ainsworth also provided a written answer to a question from the Tory MP Patrick Mercer, who had asked how many mislaid desktop computers, laptops, hard drives and USB flash drives had been lost then recovered by the MoD and its agencies in each year since 2003.

According to Ainsworth, a total of 43 such devices were recovered in 2008 by the MoD (up from 11 in 2007). This figure includes one desktop PC, 26 laptops, five hard drives and 11 USB flash drives. The answer did not state whether 2008 saw a jump in recorded recoveries because of improved recovery processes, or because more data-bearing devices were lost that year.


Do you think we should let them know IronKey exists.


Malware on Unsecure Flash Drives - The IronKey Response Part I

The media has recently reported incidents involving the spread of the W32.SillyFDC worm, a low-risk piece of malware that sometimes infects PCs and networks via USB flash drives. Several government agencies have implemented a temporary ban on removable media.

IronKey have announced a comprehensive initiative to protect portable and mobile media from viruses, worms, trojans, botnets, crimeware and other malware threats. IronKey’s initial research was partially funded by the Department of Homeland Security’s (DHS) Science and Technology Directorate.

The IronKey secure USB devices can withstand both simple and sophisticated attacks and all IronKey products have been FIPS 140-2 Level 2 validated. IronKey devices are intelligent, secure storage devices with strong, two-factor authentication and on-board security co-processors. As security processor costs become more affordable, it is possible to embed increasingly sophisticated layers of protection inside portable devices to protect enterprise and government networks from media-borne malware and crimeware. This enables IronKey secure storage devices to provide the highest levels of anti-virus and anti-malware support in hardware. Hardware support for anti-malware provides an unbeatable layer of protection for mobile devices to prevent malware from spreading onto enterprise networks.


The IronKey Anti-Malware Initiative information can be found here.
Key points of the initiative include:- Always-on Milirary Grade hardware encryption.- Malware-protected software and firmware updates.- Secure manufacturing processes.- Secure provisioning and quality assurance processes.- Real-time anti-malware scanning.