Feeds

Government data protection standards are protected data

We could tell you, but then we'd have to kill you

Maximizing your infrastructure through virtualization

As yet another laptop full of confidential data goes up for sale on Ebay – this one belonging to Charnwood Borough Council - the government's failure to set and publicise standards for wiping data makes it inevitable that there will be many more, and worse, incidents of this kind.

“Wiping data” may sound easy – to the non-techy it is as simple as hitting “delete”. In fact, unless very stringent measures are applied, this does nothing to protect the underlying data from prying eyes.

Charnwood Council thought they were safe, requiring 3rd parties to apply DoD Standard 5220.22M to all data erasures. Unfortunately, at the time they set this standard, the data wiping sections in this document were non-existent.

The reference to this odd-sounding standard is taken from the US Department of Defense’s National Industrial Security Program Operating Manual(pdf.) (NISPOM). The manual deals with the key question of how to prevent unauthorized disclosure of classified information, with data clearing and sanitization covered in two short paragraphs.

When first issued, it didn't specify any particular method for achieving secure erasure, so in no way could the manual be considered a standard.

What it does say is that "instructions on clearing, sanitization and release of IS media shall be issued by the accrediting CSA." Standards for data cleansing are left up to the Cognizant Security Agency, which can be the Department of Defense (DoD), the Department of Energy (DOE), the Natural Resources Commission (NRC) and the Central Intelligence Agency (CIA).

At least, they were approximately two years ago, when Charnwood Council set its criteria for supplier selection, and the relevant edition of NISPOM was the one dated February 2006. The situation has since changed, with an updated manual produced this year, together with an enhanced “Clearing and Sanitization Matrix”, which provides much greater detail.

However, this still remains a highly technical area and one where it is questionable as to whether individual local councils are in any way the right bodies to be researching and setting standards. After all, what is right for erasing data in Cornwall is probably just as right in the Home Counties. So why not set a National standard?

El Reg looked in vain at recent Cabinet Office releases on this subject. And lo! Toward the end of June, the Cabinet Office produced “The final report on data handling procedures across government” (pdf.), as well as “New arrangements for data handling procedures” (pdf.).

These are splendid documents. Much thinking has clearly gone into them, but they are about processes – not precise procedures. Take the second of these documents. This rather insightfully observes that departments should “dispose of electronic media that have been used for protected personal data through secure destruction, overwriting, erasure or degaussing for re-use”. Fancy that!

A little more prodding reveals that the Government actually DOES have a list of products that are recommended for data sanitisation. This list is produced by the National Technical Authority for Information Assurance, aka CESG. Don’t ask what the initials stand for: they are based in Cheltenham, and we are now into serious spook territory.

All well and good – although connoisseurs of software development will note that just providing a list of OK products is no great help for UK software developers trying to create products to sell to government. Standards really WOULD be helpful.

We have been informed that CESG might possibly have created such a document – but at time of writing, they were unable to confirm or deny this. If they do get back to us, El Reg readers will be the first to know, although perhaps, given its pedigree, it is MEANT to be a secret!

In the meantime, laptops will be lost, data sticks misplaced: and whether the data involved has been effectively wiped – or just partially over-written will depend on the random chance of whether the local government body involved did or did not possess the in-house expertise to identify a decent data wiping standard.

Or as Paul Bargewell, Technical Service & Strategy Manager at Charnwood Council puts it: “This is not an area where it is reasonable to expect that local councils will have the expertise required. A published national standard for data erasure would do no harm – and be of immense value to pretty well everyone.”

A spokesperson for CESG DID get back to us and admitted that yes: standards on data sanitisation DO exist and are provided by CESG to the Cabinet Office, who insert them into what is known as the “Manual of Protective Security. However, as we also guessed, this document is pretty hush-hush. Not “Secret”, which is a super-spook category: but “Restricted”, which means it is not publically available. In theory, this means it can be made available to Government both nationally and at local level. However, our own phone round suggests that awareness at local level is pretty poor.

Top three mobile application threats

More from The Register

next story
Arrr: Freetard-bothering Digital Economy Act tied up, thrown in the hold
Ministry of Fun confirms: Yes, we're busy doing nothing
ONE EMAIL costs mining company $300 MEEELION
Environmental activist walks free after hoax sent share price over a cliff
'Blow it up': Plods pop round for chat with Commonwealth Games tweeter
You'd better not be talking about the council's housing plans
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
Apple smacked with privacy sueball over Location Services
Class action launched on behalf of 100 million iPhone owners
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.