Feeds

Basic security housekeeping vital, says GCHQ boss

Containing cyber threats mostly straightforward

Providing a secure and efficient Helpdesk

GCHQ's director has said that 80 per cent of the government's cyber security vulnerabilities can be solved through good information assurance.

Iain Lobban, the director of the signals intelligence and information security organisation, said if government departments observed basic network security disciplines, such as "keeping patches up to date", combined with the necessary attention to personnel security, their online networks would be much safer.

"But the scale of the challenge is changing, and the remaining 20 per cent of the threat is complex and not easily addressed by just building the security walls higher and higher," he told an audience at the International Institute for Strategic Studies on 12 October 2010. "As Bill Lynn, the US Deputy Secretary of Defense has said, a 'Maginot line' approach to defence will not be sufficient of itself."

"The 20 per cent which is made up of that complex threat needs to be defended against in cyberspace itself."

The GCHQ boss also warned that as the government puts more of its services online, the public increasingly expects services to be completely secure.

Lobban urged the government to deepen its dialogue and partnership with the companies which deliver the systems and services that need securing.

"In many cases they have an equal or greater stake in ensuring proper protection and realising efficiencies," he said. "There is a strong foundation on which to build in the structures that have been created under the Centre for the Protection of National Infrastructure and a number of Whitehall/industry bodies."

Lobban also hopes that government organisations will respond more swiftly to "match the speed at which cyber events happen". This can be achieved through ensuring there is a direct feed of information from operators, he explained.

"But such feeds could give us the opportunity to respond, if necessary, with some active defensive techniques, as well as to spread knowledge of the threat quickly to others who may be vulnerable," he added.

This article was originally published at Kable.

Kable's GC weekly is a free email newsletter covering the latest news and analysis of public sector technology. To register click here.

New hybrid storage solutions

More from The Register

next story
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
TorrentLocker unpicked: Crypto coding shocker defeats extortionists
Lousy XOR opens door into which victims can shove a foot
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.