DWP
DWP fails to practice what it preaches

DWP guilty of security lapses

Freedom of information requests reveal the DWP was guilty of the same security breaches it warned others about

Written by Tom Young

Much of the recent furore about the growth of the “database state” and information sharing between Whitehall departments has obscured just how much data is already held by the government about citizens.

The Department of Work and Pensions’ (DWP’s) £72m Customer Information System (CIS), for example, is rarely mentioned in the national media, and relatively unknown in the public realm.

The database makes 92 million tax and benefit records available to 80,000 DWP employees, 60,000 workers from other government departments, and staff from 445 local authorities.

And since July 2008 these workers have also had access to HM Revenue and Customs’ (HMRC’s) tax credit data through the system.

CIS is an Oracle database built by Accenture which holds information on anybody with a national insurance number, including where they live, their ethnicity, and their tax status.

The system is also to serve as the blueprint for the biographical element of the National Identity Register (NIR) supporting ID cards, which is currently under construction ­ as distinct from the biometric database, which is being built
from scratch.

Clearly, security is a key consideration for such a vital system, as the DWP said in a statement in February 2007: “With regard to the CIS, there are strict measures in place to protect the integrity of people’s data. Access to the information is only allowed where it is legal to do so, and it is restricted to the specific business needs of the customer. Specific controls are in place to restrict who can see each field, which manages the risk of unauthorised or inappropriate access.”

So it will be a concern to many people worried about the integrity of NIR to know that CIS has suffered a number of security breaches in recent months.

Freedom of information requests submitted by Computing reveal that, in the six months to January 2009, six DWP employees were disciplined for “inappropriate use” of the system.

In the same period, local authorities were obliged to carry out internal investigations eight times after being notified by DWP that CIS had been accessed inappropriately.
These 14 incidents were in just six months. Last month, the department admitted that since August 2006, 33 local authority staff have been confirmed as accessing records “without business justification”.

The DWP became so concerned about instances of unjustified access that in January it sent out a memo to authorities warning them that the practice must stop.

“Anyone found to be abusing CIS may face sanctions ranging from disciplinary action to prosecution,” read the memo. “DWP will support your local authority to ensure appropriate disciplinary or prosecution action is taken, and may consider prosecuting directly under social security legislation.”

The memo did not mention that similar breaches were taking place within the department itself.

One of the problems with securing CIS is there are so many points of access. Although the DWP does not allow workers to access the system from remote or home locations, or via wireless connections, it still has more than 140,000 users to police.

Couple this with a culture in the public sector that does not yet have privacy practices ingrained, and the DWP has a serious challenge, said Sarah Burnett, public sector analyst at Butler Group.

“There is a big turnover of staff and it is often difficult to fire people in the public sector,” she said.

“This makes it a tough job to instill a culture of respect for people’s personal information.”

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

DWP logoPublic Sector

DWP plans £400m application development spend

Development will be based on existing structure 12 Mar 2009

 

Government issues £4.5bn desktop services tender

Contract includes provision of PCs and laptops, software, security, infrastructure and support 25 Sep 2008

DWP sending sensitive data with passwords

Email indicates that security measures introduced after HMRC breach are not working 09 May 2008

Security spending remains robust in face of downturn

IT leaders tighten defences in the face of the economic storm 26 Mar 2009

Government wants to monitor Facebook users

Data retention directive needs to be extended to cover social networking sites, says Home Office minister 25 Mar 2009

Civil servant jailed for accessing DWP systems for fraud

Government records were used to facilitate tax credit fraud 21 Sep 2009

Council staff making "serious security breaches" of key government database

DWP admits 33 people accessed Customer Information System - containing 75 million citizen records - without justification 25 Feb 2009

Government’s refusal of FOI requests at its peak

The Government’s response rates to Freedom of Information Act (FOIA) requests has deteriorated significantly since the Act was introduced five years ago. Furious info pros want stricter penalties to apply to public sector bodies failing to comply with the spirit of the Act 08 Feb 2010

related whitepapers

today's top stories

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

PaperlinX outsources IT and comms to Bull and BT

Paper company spends €22m on five-year deal for desktop management, helpdesk and datacentre services 05 Feb 2010

Social tools take KM to a new level

Technology expert David Tebbutt explains how – and why – organisations should integrate social networking tools into their knowledge management strategy 02 Feb 2010

EDS court defeat puts vendors on their guard

BSkyB’s victory in a long-running court case against EDS has serious implications for the IT industry 02 Feb 2010

Law firm monitors web traffic violations

Bucks declining global security appliance sales with unified threat management (UTM) platform deployment 01 Feb 2010

Advertisement

Security: The New Face of Intrusion Prevention
An outline of traditional IPS functionality, modern developments and how IPS can be deployed easily.

UK businesses’ attitudes to Cloud Computing revealed

Features results from a survey of over 200 Computing readers.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

Internet Explorer 6

Internet Explorer 6

Following recent concerns about the security of Internet Explorer 6 are you planning to phase it out?

View poll results

Latest audio and video articles

Tony McAlisterVideo

Video Q&A: Tony McAlister, CTO, Betfair - Part one

On changing the skills development strategy at the online gambling firm - part one of a two-part video interview 05 Nov 2009

Video

Nokia shows upcoming handset technologies

Mobile phone features of tomorrow take the stage 21 Oct 2009

Latest in-depth articles

Analysis

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

Businessman with eye patch, dagger and tie round head, sitting at laptopFeatures

Are you sure you're not a pirate?

It is alarmingly easy for an IT leader to unwittingly exceed the scope of a software licence, and the chances of being caught out have never been greater, as technology lawyers Mark Weston and Paul Gershlick explain 09 Feb 2010

Primary Navigation