Feeds

Government data protection standards are protected data

We could tell you, but then we'd have to kill you

Reducing security risks from open source software

As yet another laptop full of confidential data goes up for sale on Ebay – this one belonging to Charnwood Borough Council - the government's failure to set and publicise standards for wiping data makes it inevitable that there will be many more, and worse, incidents of this kind.

“Wiping data” may sound easy – to the non-techy it is as simple as hitting “delete”. In fact, unless very stringent measures are applied, this does nothing to protect the underlying data from prying eyes.

Charnwood Council thought they were safe, requiring 3rd parties to apply DoD Standard 5220.22M to all data erasures. Unfortunately, at the time they set this standard, the data wiping sections in this document were non-existent.

The reference to this odd-sounding standard is taken from the US Department of Defense’s National Industrial Security Program Operating Manual(pdf.) (NISPOM). The manual deals with the key question of how to prevent unauthorized disclosure of classified information, with data clearing and sanitization covered in two short paragraphs.

When first issued, it didn't specify any particular method for achieving secure erasure, so in no way could the manual be considered a standard.

What it does say is that "instructions on clearing, sanitization and release of IS media shall be issued by the accrediting CSA." Standards for data cleansing are left up to the Cognizant Security Agency, which can be the Department of Defense (DoD), the Department of Energy (DOE), the Natural Resources Commission (NRC) and the Central Intelligence Agency (CIA).

At least, they were approximately two years ago, when Charnwood Council set its criteria for supplier selection, and the relevant edition of NISPOM was the one dated February 2006. The situation has since changed, with an updated manual produced this year, together with an enhanced “Clearing and Sanitization Matrix”, which provides much greater detail.

However, this still remains a highly technical area and one where it is questionable as to whether individual local councils are in any way the right bodies to be researching and setting standards. After all, what is right for erasing data in Cornwall is probably just as right in the Home Counties. So why not set a National standard?

El Reg looked in vain at recent Cabinet Office releases on this subject. And lo! Toward the end of June, the Cabinet Office produced “The final report on data handling procedures across government” (pdf.), as well as “New arrangements for data handling procedures” (pdf.).

These are splendid documents. Much thinking has clearly gone into them, but they are about processes – not precise procedures. Take the second of these documents. This rather insightfully observes that departments should “dispose of electronic media that have been used for protected personal data through secure destruction, overwriting, erasure or degaussing for re-use”. Fancy that!

A little more prodding reveals that the Government actually DOES have a list of products that are recommended for data sanitisation. This list is produced by the National Technical Authority for Information Assurance, aka CESG. Don’t ask what the initials stand for: they are based in Cheltenham, and we are now into serious spook territory.

All well and good – although connoisseurs of software development will note that just providing a list of OK products is no great help for UK software developers trying to create products to sell to government. Standards really WOULD be helpful.

We have been informed that CESG might possibly have created such a document – but at time of writing, they were unable to confirm or deny this. If they do get back to us, El Reg readers will be the first to know, although perhaps, given its pedigree, it is MEANT to be a secret!

In the meantime, laptops will be lost, data sticks misplaced: and whether the data involved has been effectively wiped – or just partially over-written will depend on the random chance of whether the local government body involved did or did not possess the in-house expertise to identify a decent data wiping standard.

Or as Paul Bargewell, Technical Service & Strategy Manager at Charnwood Council puts it: “This is not an area where it is reasonable to expect that local councils will have the expertise required. A published national standard for data erasure would do no harm – and be of immense value to pretty well everyone.”

A spokesperson for CESG DID get back to us and admitted that yes: standards on data sanitisation DO exist and are provided by CESG to the Cabinet Office, who insert them into what is known as the “Manual of Protective Security. However, as we also guessed, this document is pretty hush-hush. Not “Secret”, which is a super-spook category: but “Restricted”, which means it is not publically available. In theory, this means it can be made available to Government both nationally and at local level. However, our own phone round suggests that awareness at local level is pretty poor.

Maximizing your infrastructure through virtualization

More from The Register

next story
Major problems beset UK ISP filth filters: But it's OK, nobody uses them
It's almost as though pr0n was actually rather popular
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
ITC: Seagate and LSI can infringe Realtek patents because Realtek isn't in the US
Land of the (get off scot) free, when it's a foreign owner
MPs wave through Blighty's 'EMERGENCY' surveillance laws
Only 49 politcos voted against DRIP bill
EU's top data cops to meet Google, Microsoft et al over 'right to be forgotten'
Plan to hammer out 'coherent' guidelines. Good luck chaps!
US judge: YES, cops or feds so can slurp an ENTIRE Gmail account
Crooks don't have folders labelled 'drug records', opines NY beak
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.