Delicious/delimiterau
- Earning billions and getting taxed a pittance
- Dell chief defends transfer pricing
- Qantas tech exec shifts to Jetstar
- Zurich Australia leads regional thin client push
- Early investors drop Facebook
- Victoria kills HealthSMART IT project
- Woz not great - mUmBRELLA
- Santos' thin client starts big-data plans
- Nokia Lumia 800 revs up at Bridgestone
- Telstra privacy breach was 'one little oops'
International - Written by The Guardian on Monday, April 2, 2012 15:33 - 0 Comments
Data protection by design: CIOs’ response to new security challenges
Protecting data is already a tough job for public sector chief information officers (CIOs) – and it’s only going to get tougher in future.
The European commission recently proposed a comprehensive reform of the EU’s 1995 data protection rules which, if it goes ahead, would have far-reaching effects for the way public sector bodies process personal data.
Such reforms would add a further layer of compliance for government CIOs, who must already deal with the demands of the information commissioner, freedom of information requests and the day-to-day need to keep user and staff data secure.
“It’s tough to know if public sector CIOs are already being more proactive in regards to information security,” says Dominic Batchelor, a partner at law firm Ashurst. “Data protection by design has only become fashionable during the past 12 to 18 months, but its popularity will continue to grow because of changes to the regulatory environment and the requirement for smarter data protection.”
Data protection by design aims to achieve a more proactive approach to security: it ensures no data is collected without the prior identification of a set business purpose and relies on a sound comprehension of the regulatory environment as well as a thorough understanding of organisational objectives.
Rather than being bolted on as an afterthought, privacy is set at the centre of a strategic approach that draws on a careful mix of technology, policy and people.
Kurt Frary, ICT architecture manager at Norfolk county council, says protection by design is the only possible way to manage public sector IT. “It’s not even a choice,” he says. “Modern CIOs have to create security by design if they want to do their job properly. We don’t have to convince people, either; security is absolutely core to our working culture.”
Frary’s strategy places security at the heart of every job role, with employees in Norfolk’s 240-strong IT department aware of their responsibilities. Job descriptions, for example, stipulate how and why an individual is responsible for a particular piece of kit, such as a server system. “We take a role-based approach to the way staff access systems. Security by design, and the opportunity to only access certain data defined by your specific role, is embedded in the way we work,” he says.
Dedicated managers, a security architect and an information architect report directly to Frary and help establish a security framework with different levels of policy. The framework is supported by a mixture of in-house technologies and tools provided through the council’s managed services agreement with BT.
The storage and use of an organisation’s information, rather than its security set up, creates a larger headache for public sector CIOs, Frary believes.
“When we’re considering whether to upgrade services, we have to take safe harbour considerations into account and make sure that data is not moving outside the EU,” he says, while potential fines from the information commissioner mean security must remain a priority for any public sector organisation.
Sander Kristel, CIO at Staffordshire county council, is also concentrating on information storage.
Data by design is theoretically the way forwards for information-swamped councils, but such an approach needs to be driven by customer need, according to Kristel, with attention directed towards the reasons for collecting, retaining and using customer data.
“Most organisations have taken the ‘protect all data’ approach, which is expensive from a technical perspective, but is easier from a process perspective,” says Kristel.
“Basically, government CIOs often secure a lot of data at the moment that is actually freely publicly available through freedom of information requests. If we do want to use cloud solutions in the public sector, it is really important to be more careful with the data we store before we make a decision.”
Centrally stipulated codes of connection are helping to create a platform for the types of technologies, policies and people processes that can drive data protection by design, the CIO says.
He believes codes stipulated through initiatives such as the Public Services Network will significantly improve customer service, while also working to reduce security risks and data duplication. But the continued use of such codes means CIOs must be proactive and understand how central policy impacts users at the local level.
“Data protection by design is going to be even more complex if we still need to comply with different codes of connection at the same time,” he says. “Cloud will inevitably mean that more of the information governance responsibilities will shift from IT teams to front line users. This shift will require simple, clear local policies and extensive training.”
This article is published by Guardian Professional. For weekly updates on news, debate and best practice on public sector IT, join the Guardian Government Computing network here.
guardian.co.uk © Guardian News & Media Limited 2010
Published via the Guardian News Feed plugin for WordPress.
Related posts:
- Hacks focus CIOs on IT security
- Pay freezes and cuts for CIOs at Whitehall’s biggest departments
- Apple and big data on the Horizon: the tech transformation under way at TfL
- Australian CIOs optimistic about future
- NSW Govt can’t guarantee IT security
| Tweet | |
![]() |
Enterprise IT, News - May 24, 2012 17:40 - 1 Comment
Bridgestone picks Lumias for smartphone fleet
More In Enterprise IT
- SAP’s SuccessFactors deploys Aussie datacentre
- Govt pushes ahead with cloud-sharing approach
- The ABC didn’t sack Bitcoin miner
- Victoria dumps HealthSMART e-health project
- HP completes giant new NSW datacentre
News, Telecommunications - May 24, 2012 13:02 - 5 Comments
Rural Australia wants the NBN as quickly as possible
More In Telecommunications
- The NBN, service providers and you … what could go wrong?
- NBN here to stay under Coalition, says analyst
- iiNet ramps up Internode digestion
- China concerned by Huawei NBN ban, says Bob Carr
- Parliament knocks back surveillance terms
Gadgets, News - May 24, 2012 16:43 - 0 Comments
Telstra launches first 4G Windows phone
More In Gadgets
- IT price hike inquiry kicks off: Submissions wanted
- Galaxy S III listed for Telstra, Optus and Vodafone
- Will Telstra skip Nokia’s Lumia 900?
- New BlackBerry OS 7.1 hits Australia
- ASUS Transformer Pad tablet hits Australia
Reviews - May 7, 2012 18:16 - 2 Comments
Telstra Mobile Wi-Fi 4G: Review
More In Reviews
- Samsung Galaxy S III: Preview
- HTC Titan II 4G: Preview
- Nokia Lumia 710: Review
- Sony Xperia S: Review
- Samsung Omnia W: Review









sponsored post ING Direct recently implemented a private cloud solution to virtualise its entire banking platform, allowing it to provision a new copy of itself -- a so-called 'bank in a box' -- within minutes. 
Leave a Comment