Feeds

Leaked email reveals civil service laptop rules

Civil servant finally leaks data correctly - to us...

Security for virtualized datacentres

The Register has received the email sent out to all staff at the Medical Research Council passing on instructions from the Cabinet Office that the ban on taking laptops out of the office could apply to mobile phones too.

The mail was sent to senior staff on Wednesday afternoon, but forwarded onto to everyone within the department this morning.

It warns staff that the first step is that no unencrypted laptops or drives containing personal data should be taken outside secured office premises. The mail said: "Clarification has been given that this applies to any mobile device with storage capacity, including mobile phones and PDA’s."

The email also provides a definition of what "personal data" actually is:

Any information that links one or more identifiable living person with private information about them” or “Any source of information about 1000 identifiable individuals or more, other than information sourced from the public domain.

The mail says senior staff are seeking clarification on what this will mean in practice, but meanwhile staff are told to "err on the side of caution... we should assume for the time being that emails and contacts stored in an email system count as personal data."

Here's the whole thing:

Sent: Wednesday, January 23, 2008 3:56 PM

Subject: Personal Data Security and Restrictions on use of Laptops

Colleagues

Following the recent government-wide review of procedures for the storage and use of data, we received a letter this morning from Ian Watmore, Permanent Secretary of the DIUS containing new Cabinet Office instructions and guidance on personal data.

There is a programme of actions that have to be undertaken, but the most immediate states that “From now on, no unencrypted laptops or drives containing personal data should be taken outside secured office premises.” Clarification has been given that this applies to any mobile device with storage capacity, including mobile phones and PDA’s.

Personal data is defined as “Any information that links one or more identifiable living person with private information about them” or “Any source of information about 1000 identifiable individuals or more, other than information sourced from the public domain”. Clarification is being sought urgently on the interpretation of these rules in practice but as we have been instructed to err on the side of caution, we should assume for the time being that emails and contacts stored in an email system count as personal data.

With immediate effect therefore, please ensure that your Establishment complies with the instruction not to allow unencrypted laptops or drives containing personal data, including emails, to be taken outside of secured office premises.

We will be disseminating information about the other measures as soon as we can. If you have any questions about this, please contact the MRC’s Information Security Officer xxxx.xxxx@xxxx.mrc.ac.uk and he will do his best to answer them for you.

Regards

Nigel

Nigel Watts

Finance Director

MRC

20 Park Crescent

London W1B 1AL

Staff have been told encryption software will be installed on their machines next week. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
Apple CEO Tim Cook: TV is TERRIBLE and stuck in the 1970s
The iKing thinks telly is far too fiddly and ugly – basically, iTunes
Huawei ditches new Windows Phone mobe plans, blames poor sales
Giganto mobe firm slams door shut on Microsoft. OH DEAR
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Found inside ISIS terror chap's laptop: CELINE DION tunes
REPORT: Stash of terrorist material found in Syria Dell box
Show us your Five-Eyes SECRETS says Privacy International
Refusal to disclose GCHQ canteen menus and prices triggers Euro Human Rights Court action
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.