June 2009

Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30        
Blog powered by TypePad

« Security Executive | Main | Do Mess With Texas »

July 12, 2007

Negligence and Breaches

richard_thomas.jpg
Banks, shops and government departments have exposed thousands in Britain to the risk of fraud through "horrifying" breaches of data protection laws, a watchdog said on Wednesday.

In his annual report, Information Commissioner Richard Thomas, whose office enforces the Data Protection Act, said firms must do more to secure people's private details.

"The roll-call of banks, retailers, government departments, public bodies and other organisations which have admitted serious security lapses is frankly horrifying," he said in the report.

Privacy watchdog warns of "horrifying" breaches, The Scotsman, Reuters, 11 July 2007

He's not talking terrorism, so we can hope this is not just more FUD.

And it's not: he supplied a number of examples. My favorite is:

  • A job application Web site for junior doctors was dogged by a catalogue of security breaches that allowed access to other people's personal details.
All of his examples sound all too familiar to anyone who has dealt with information security.

What is to be done? Well, what about breach discovery in the UK:

The National Consumer Council believes it should be mandatory for businesses to warn people if sensitive personal information is compromised.

Call for more ID theft protection, By Chris A'Court, BBC Radio 4's Money Box, 29 August 2006

Unfortunately, Thomas is not for it:
He would like to encourage organisations to notify security breaches as "good practice" but said whether to make that a legal requirement needs a greater debate which has not yet started.

Any changes to the Data Protection Act would come via Parliament.

That would be the same Parliament that appears to have exempted itself from the British Freedom of Information (FOI) Act, so don't hold your breath.

-jsq

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341cb65b53ef00e00991b82a8833

Listed below are links to weblogs that reference Negligence and Breaches:

Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

My Photo

Risk Reading