Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.
MSD releases independent report into IT security breach
Posted on 2-Nov-2012 10:50 | Tags Filed under: News



The Ministry of Social Development today released the independent report by Deloitte into the security breach of Work and Income kiosks.

Ministry of Social Development Chief Executfive Brendan Boyle says the report is damning around MSD’s failure to separate public kiosks from a network containing corporate files.

“However I am very pleased to report that there has not been a widespread privacy breach. Investigations have determined that there is no evidence that the Kiosk breach went beyond that of Keith Ng and his associate Ira Bailey.

“Both men have cooperated with the Deloitte investigation and with the Privacy Commissioner. They have handed the information over and promised they have not shared that information with anyone else.

“I’m sorry that this matter has created concern amongst people who have information stored with us. However, it is good that we are able to reassure people today,” said Brendan Boyle.

“The report found insufficient work was done by the Ministry to ensure appropriate security was placed around the protection of information at the time the kiosk infrastructure and services were designed and built.

“While independent testing done on the kiosks was sound, the Ministry’s response to the security issues identified was inadequate.

“The review found the Ministry’s response to the issues raised by Keith Ng and Ira Bailey was sound, prompt and considered.

“In terms of people’s privacy we are extremely fortunate that the risk of harm from this is extremely low because there were only two people who looked at a limited number of the invoices. Both men have returned all the information and assured us and the Privacy Commissioner that they have not distributed it to anyone else.

“Around 1,432 of the 7,300 odd items did contain some personal information such as a person’s name and/or date of birth and some description of the medical and legal services that were purchased.

“Of all the items downloaded the invoices relating to 10 individuals contained highly sensitive information.

“In the case of the eight children and two adults whose invoices contained highly sensitive information – we will be working on how best to respond to these individuals. This approach is in accordance with the Privacy Commissioner’s guidelines.

“In announcing the independent review I said that what had occurred was completely unacceptable and I continue to hold that view.

“The review finds security issues were identified and raised on a number of occasions, including by Dimension Data, but staff woefully under-estimated the risk of a malicious attack.

“In doing so they appear to have failed to take the necessary steps to ensure the Ministry safeguarded people’s personal information.

“I’m gutted and disappointed that we’ve let people down.

“Of particular concern is that risks and concerns which were identified do not appear to have been escalated to the right people.

“The Deloitte report confirms that staff members in leadership positions were not alerted to these issues and therefore had no opportunities to exercise appropriate judgement.

“The report makes it clear there were risk and governance processes in place, however these were not appropriately used.

“Questions must now be asked about the adequacy of these processes and whether this was an extraordinary series of events, or whether it raises broader issues about the appropriateness and effectiveness of the Ministry’s wider information systems security.

“This will all be considered in the second phase of the Deloitte independent review, which will include consideration of our policies, governance, capability and culture.

“This second phase review will be completed later this month.

“In the meantime I can confirm that at this stage four employment investigations are being undertaken by an independent barrister.

“These investigations need to run their course before I determine the next steps.

“I can assure people that the employment investigations will be thorough and people will be held to account for their conduct,” concluded Brendan Boyle.


Download: http://www.msd.govt.nz/documents/about-msd-an...




comments powered by Disqus


Trending now »

Hot discussions in our forums right now:

iPhone 8/iPhone X, impressions?
Created by surfisup1000, last reply by Batman on 24-Sep-2017 13:59 (419 replies)
Pages... 26 27 28


Driving an automatic - do you use one foot or both?
Created by geekIT, last reply by Batman on 23-Sep-2017 05:28 (135 replies)
Pages... 7 8 9


Auckland Airport fuel supply obliterated by digger
Created by Batman, last reply by k1wi on 23-Sep-2017 03:12 (220 replies)
Pages... 13 14 15


IOS 11 email client and Office 365 - heads up people
Created by gjm, last reply by mattwnz on 20-Sep-2017 17:15 (18 replies)
Pages... 2


Spam Text
Created by rendezvous, last reply by KiwiSurfer on 24-Sep-2017 13:21 (17 replies)
Pages... 2


When did we become America
Created by BTR, last reply by Fred99 on 22-Sep-2017 12:12 (66 replies)
Pages... 3 4 5


Sky blames piracy for lost customers. Sky: it's time to wake up and smell the coffee.
Created by kingdragonfly, last reply by Rikkitic on 21-Sep-2017 11:10 (482 replies)
Pages... 31 32 33


vodafone shutting down email?
Created by FatFurryGuy, last reply by pristle on 22-Sep-2017 10:39 (296 replies)
Pages... 18 19 20