Martin Sugden 23 September 2014

Local authorities: facing up to data loss

Local authorities have come under increased scrutiny following the recent publication of results from an audit of sixteen local authorities by the Information Commissioner’s Office (ICO), which found that collectively there was “clear room for improvement” in how they comply with the Data Protection Act.

With data loss never far from the news, protecting sensitive information is no longer the sole preserve of national security organisations – it has become a key concern for all levels of government organisation and indeed, private enterprise.

A data breach can greatly impact local government organisations – whether its direct harm caused to an individual or organisation as a result of disclosed information, in monetary terms due to ICO fines, loss of funding or negative publicity garnered by the news of a breach. As a result, it is no longer enough for local government organisations to treat data security as a ‘nice to have’, instead they must actively implement measures to protect both their staff and the information assets they hold.

Government Security Classification scheme

Central Government understands that it is vital to take measures to protect data and have rightly identified data classification as being increasingly important to help staff understand the value of the data they receive, handle and create. On the 2nd April 2014, the Cabinet Office launched the Government Security Classification (GSC) scheme, which aims to simplify classification of government data and make it easier and more cost-effective for material to be marked, handled and protected in a proportionate way.

However, in the lead-up to the changes, we were surprised to find only 20% of the government staff we spoke to had plans to transition to the new scheme and that there was a general consensus that clearer guidance is needed on how to implement, enforce and train staff to use the new classification system.

This guidance is still lacking months after the launch of the GSC and until the Cabinet Office addresses this, we will continue to see avoidable data breaches across government.

Making data security more people-centric

One of the ways in which organisations can protect their data and meet the requirements of GSC is through the use of data classification solutions, which empower staff to assign a value to data (whether it’s an email, document, image or CAD design file) they create and handle, so informed decisions can be made about how that information is managed, used and shared. The creator of the data is usually best-placed to make this value judgement, as they will be more aware of its context.

By putting the classification obligation in the hands of staff at all levels, you effectively draw them into an active role in data security, which provides a greater defence against the loss of sensitive information.

Technologies such as Data Classification and DLP can be combined as part of a layered security approach to help prevent government organisations from incurring the wrath of the ICO. Visual classifications can help to raise awareness of data security but only a data classification solution which translates these into metadata which can be used by other security technologies can be totally effective in enabling an organisation to control the sharing and release of information.

Education and best practice

Following the ICO’s audit of local authorities and the resulting recommendations, it is hoped the number of data breaches and subsequent fines is reduced. Certainly the recommendations and best practice examples supplied by the ICO should go some way to increase awareness of the need for all employees at all levels to protect data right through the cycle.

It is encouraging that the ICO is taking on more of an educational role, rather than being a solely punitive organisation slapping fines on local councils with little help to solve the underlying issues around data loss, yet we are still some way from a providing local government with enough support to make sure data leakage is plugged.

Martin Sugden is the MD of Boldon James

SIGN UP
For your free daily news bulletin
Highways jobs

Financial Assessment Officer

London Borough of Richmond upon Thames and London Borough of Wandsworth
£30,510 - £45,564 per annum
Financial Assessment Officer
Recuriter: London Borough of Richmond upon Thames and London Borough of Wandsworth

HDRC Partnerships Officer

Essex County Council
£26786.00 - £31512.00 per annum + + 26 Days Leave & Local Gov Pension
HDRC Partnerships OfficerFixed Term, Full Time£26,786 to £31,512 per annumLocation
Recuriter: Essex County Council

Special Educational Needs (SEN) Delivery Lead

The Royal Borough of Kensington & Chelsea Council
Negotiable
Lead the daily operations of our SEN service, ensuring every child receives the support they deserve. Working as an SEN Delivery Lead means being at t England, London, City of London
Recuriter: The Royal Borough of Kensington & Chelsea Council

Complex Case Officer (SEN)

The Royal Borough of Kensington & Chelsea Council
Negotiable
Support children and young people with complex needs, ensuring they receive the right help at the right time. Working as a Complex Case Officer in ou England, London, City of London
Recuriter: The Royal Borough of Kensington & Chelsea Council

Events Officer - Harlow District Council

Essex County Council
Up to £18.28 per hour
Events Officer- Harlow District CouncilHarlow, Essex Full time, Temporary £18.28 per hour PAYE Closing Date
Recuriter: Essex County Council
Linkedin Banner