Feeds

Basic security housekeeping vital, says GCHQ boss

Containing cyber threats mostly straightforward

The Power of One eBook: Top reasons to choose HP BladeSystem

GCHQ's director has said that 80 per cent of the government's cyber security vulnerabilities can be solved through good information assurance.

Iain Lobban, the director of the signals intelligence and information security organisation, said if government departments observed basic network security disciplines, such as "keeping patches up to date", combined with the necessary attention to personnel security, their online networks would be much safer.

"But the scale of the challenge is changing, and the remaining 20 per cent of the threat is complex and not easily addressed by just building the security walls higher and higher," he told an audience at the International Institute for Strategic Studies on 12 October 2010. "As Bill Lynn, the US Deputy Secretary of Defense has said, a 'Maginot line' approach to defence will not be sufficient of itself."

"The 20 per cent which is made up of that complex threat needs to be defended against in cyberspace itself."

The GCHQ boss also warned that as the government puts more of its services online, the public increasingly expects services to be completely secure.

Lobban urged the government to deepen its dialogue and partnership with the companies which deliver the systems and services that need securing.

"In many cases they have an equal or greater stake in ensuring proper protection and realising efficiencies," he said. "There is a strong foundation on which to build in the structures that have been created under the Centre for the Protection of National Infrastructure and a number of Whitehall/industry bodies."

Lobban also hopes that government organisations will respond more swiftly to "match the speed at which cyber events happen". This can be achieved through ensuring there is a direct feed of information from operators, he explained.

"But such feeds could give us the opportunity to respond, if necessary, with some active defensive techniques, as well as to spread knowledge of the threat quickly to others who may be vulnerable," he added.

This article was originally published at Kable.

Kable's GC weekly is a free email newsletter covering the latest news and analysis of public sector technology. To register click here.

Designing a Defense for Mobile Applications

More from The Register

next story
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
Putin: Crack Tor for me and I'll make you a MILLIONAIRE
Russian Interior Ministry offers big pile o' roubles for busting pro-privacy browser
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.