Memo reveals multiple breaches of ID card database

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

The database that will take a central role in the national identity-card scheme has been breached more than 30 times since 2006.

The breaches of the Customer Information System (CIS), which is run by the Department of Work and Pensions, were revealed in a DWP memo to housing benefit and council tax benefit staff on 15 January.

CIS is designed to give local authorities access to citizens' data, including HMRC tax-credit information. In 2006, it was decided that the ID card project would use CIS for biographical information, to avoid having to create a new, monolithic database of the UK's inhabitants.

In the DWP memo, the government department said that desktop access to CIS had helped to "significantly improve service delivery" to citizens, but noted that a series of checks had identified that some local-authority staff were committing serious security breaches using the system.

On Wednesday, a spokesperson for the Department of Work and Pensions told ZDNet UK that 33 such breaches had been identified since 2006, but said the breaches were not necessarily intentional.

"The breaches were not necessarily someone purposely going on there and checking something they shouldn't," the DWP spokesperson said. "They could be inadvertently clicking on information."

The departmental memo reminded local-authority staff of CIS access rules. These are: staff cannot access their own records or the records of friends, relatives, partners or acquaintances; they cannot make enquiries on behalf of colleagues in respect of their friends, relatives, partners or acquaintances; they cannot share their system, Government Gateway or other identity password with their colleagues; and they must not access CIS for any unauthorised purpose.

The DWP's spokesperson did not respond to a request to describe how it might be possible to break these rules by inadvertently clicking on information in the CIS database, but did claim the number of breaches revealed in the memo showed the system was secure.

"The small number of breaches shows that the CIS security system is working and is protected by several different audit and monitoring controls, which actively manage and report attempts at unauthorised or inappropriate access," the spokesperson said.

The security analyst firm NCC Group said on Wednesday that the breaches showed the general inexperience of local authorities when dealing with large amounts of sensitive data.

Pointing out that it was "incredibly difficult" to know the true scale and frequency of such breaches, NCC Group director Ken Munro said in a statement that "central government understands protective marking of sensitive data, and vets staff appropriately, while many local authorities are found wanting in this area".

"Access to data such as this must be purely on a need-to-know basis, and should be carefully logged and reviewed on a regular basis," Munro said. "Personal data is of great use to the identity thief, and taking into account the number of individuals with access to the DWP CIS database, it would not be surprising if a small number could be coerced into extracting information for the needs of fraudsters."

Susan Hall, an ICT specialist at the law firm Cobbetts, said the news of the breaches "must be the final nail in the coffin for the government's national ID card programme".

"If council staff are able to snoop at our records so easily and undetected for so long, then how can an even larger and more complex database be safe?" Hall asked. "It has been reported that 'routine checks' unearthed these cases but if there are breaches dating back to 2006, then they are not proving very effective. Such negligence reinforces the need for custodial sentences for breaches of the Data Protection Act."

Asked whether the fact that it took up to two years for the breaches to come to light meant such events were not being picked up in time, the DWP's spokesperson claimed CIS control systems "actively manage and report attempts at unauthorised or inappropriate access on an ongoing basis".

"Checks are generated after the accesses and are followed up immediately by investigations where no business justification is apparent," the spokesperson added.

Talkback

"The breaches were not necessarily someone purposely going on there and checking something they shouldn't," the DWP spokesperson said. "They could be inadvertently clicking on information."

The above quote, apparently trying to make the issue sound less of a problem actually does the reverse. If they believe these breaches are inadvertent:

A: the system must be utter crap.

B: how easy it must be for someone who really does intentionally hack the system.

Tezzer 25 February, 2009 17:34
Reply

"did claim the number of breaches revealed in the memo showed the system was secure." I fail to understand the reasoning as, to me, one breach of the security shows the system is Insecure. A breach can only occur by a physical (hardware or software) error or by a user. If the breaches were by human error then the human interface control is inadequate, whether it is due to the dumb civil servant or the bad interface control. The dumb civil servant can be controlled by dismissal or criminal charges. If it is due to a physical system defect then it must be all systems stop while the bug is found and corrected. Only NO breaches is the acceptable standard and senior executives must personally accept the responsibility.

1000215420 26 February, 2009 20:01
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

32 minutes ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

9 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

15 hours ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

16 hours ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

16 hours ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store
Paul Fezziwig

Keep the crap apps out?! How will they compete with Android and Apple's claim to fame of having so many life changing apps? I wonder if the media...

21 hours ago by Paul Fezziwig via Facebook on RIM: BlackBerry will keep 'garbage' apps out of store
Aigars Mahinovs

It has been shown time after time that if there is an author store that sells the songs at even 1$ per song and gives you a high-quality digital...

22 hours ago by Aigars Mahinovs via Facebook on Copyright isn't working, says European Commission
awbMaven

""As a result of Butyka's alleged conduct, researchers were unable to use the computers for more than two months while NASA removed the malicious...

1 day ago by awbMaven on US indicts Romanian over NASA climate change hack
subhorup

It simultaneously worries me and uplifts me that a self-proclaimed group of internet activists name themselves after Indian mythical figures....

1 day ago by subhorup on Anonymous activists release PCAnywhere source code
naviathan

It's actually far easier to work anonymously on the internet than you think. With tools like Tor bouncing your traffic around the world before...

2 days ago by naviathan on Anonymous activists release PCAnywhere source code
Agnostic_OS

1000272134 and bluedalmatian with you both there but then I'm still in 10.04 land (and happy with it)

2 days ago by Agnostic_OS on Ten factors that make Ubuntu 11.10 a hit
apexwm

Interesting article and definitely see your points on the products mentioned. One of the top products for our Help Desk (approximately 20% of all...

2 days ago by apexwm on Ten flawed products that derail productivity
Paul Hutchinson

Absolutely - this should obviously not be handled my isp - but handled by their hosting operator. What's been suggested here is that my isp police...

2 days ago by Paul Hutchinson via Facebook on MPs urge ISPs to take down terrorist material
Techs UK

Looks like a great phone. I don't notice any deficiencies in WP7. used IOS before, that's pretty good. I don't spend much time in Apps, all i need...

2 days ago by Techs UK on Nokia pins US 're-entry' hopes on Lumia 900
Larry Bloggy

Now with the help of these apps you are always synced with MS outlook while on the move. Just download apps like xobni or outlookreflex and get...

2 days ago by Larry Bloggy via Facebook on Outlook Social Connector beta 2 and the LinkedIn connector
mike40g123

Your details are wrong. The version currently being made is the one with 2 USB ports, 256MB RAM and a network port. This is the Model B. The...

2 days ago by mike40g123 on Raspberry Pi boards set to go on sale
Moley

The thing that has been puzzling me for quite a while is how Anonymous can remain anonymous whilst not only being active on the Internet but also...

3 days ago by Moley on Anonymous activists release PCAnywhere source code
Don Dilly

If what Semantec is saying is rue, that is even worse and shows a complete disregard for thier users. If what Anonymous claims is true and the...

3 days ago by Don Dilly via Facebook on Anonymous activists release PCAnywhere source code
MattChurchy

Didn't seem particularly biased to me either. Oh though you might have mentioned some other competitors with free search and email services...

3 days ago by MattChurchy on Time for an evil umpire: Google, Microsoft & privacy
Simon Bisson and Mary Branscombe

James - exactly as much as anyone paid you for your comment; I don't feel that I need to say that I'm independant and unbiased, but just for you...

3 days ago by Simon Bisson and Mary Branscombe on Time for an evil umpire: Google, Microsoft & privacy