Latest Public Sector News

21.02.08

Encryption - no longer just for spies!

The high profile publicity surrounding the reported loss by HM Revenue & Customs of personal financial information relating to 25 million child benefit claimants highlights the increasing requirement for encryption technology to protect sensitive data within government settings, says Stephen Lewis

In the past, encryption may have been viewed as the preserve of espionage and the intelligence agencies. But today it is fast becoming a mainstream technology for securing information throughout government, widely used both for protecting data at rest – stored on disk or other storage media devices - and for securing data in motion over public networks or the internet.

In simple terms, encryption is the process of scrambling and unscrambling information using secret codes or keys. Employing the codes makes it difficult for any unauthorised person who is able to ‘listen in’ or intercept the communication understand or change it.

Public key cryptography - the most commonly used encryption - was developed in the early 1970s within GCHQ. And increasingly, commercially developed systems for encryption are being used to protect information classified as confidential and restricted grade under UK government protective markings. Moreover, commercial encryption for less sensitive information is now widely employed throughout many parts of central and local civilian government.

For data in motion, the primary advantages of protecting data using encryption rather than protecting the physical network are cost and flexibility. Its importance is growing as IT departments recognise the need for more than traditional network protection techniques, such as firewalls, to police the network. But encryption also has advantages beyond its main purpose of maintaining confidentiality.

If you sent data in an encrypted packet, any tampering that might have happened to it in transit can be very quickly identified. If a plain text document has a word altered during transit, for example, then this may never become apparent to the recipient at the other end. But even a very minor change to an encrypted message would potentially render it impossible to decrypt, thereby raising the alarm.

There is obviously a requirement for site to site encryption of data being transported between branch and regional offices of a department or an agency. But another application relates to the large numbers of public sector workers sharing resources and sensitive information with other departments or required to collaborate with other organisations and agencies. Encryption of intra agency communications such as this would be appropriate if a field operative in a child services department, for example, wants to work in the centre, but also needs to collaborate with NHS Trusts, police forces and child protection and care charities.

An overall driver for encryption has been central government championing of policies supporting flexible and home working and the drive to make savings on office accommodation. This has led to an increase in portable encryption systems enabling staff to work remotely while securely accessing network resources.

Systems for encrypted remote working are often used by staff stationed in temporary incident rooms at crime scenes, for example, or at outside meetings and conferences at locations which do not have secure communications. And rising concerns over the impact of pandemics is a related factor. As part of disaster management strategies, it is necessary for staff to be able to work from outside the office using remote access.

Securing information in such scenarios is obviously of paramount importance and the growing number of departments involved in tackling terrorism and serious crime means the volume of information requiring protection is increasing.

As their use escalates, encryption systems are becoming more intelligent and automated. But you can’t simply rely on the technology to ensure information is not put at risk. Staff must play their part in securing information, requiring policies and training to be established for basic rules such as password protection and not leaving screens switched on and unattended, to issues such as who is to be given access to encryption keys and in what situations encryption must be used.

Tell us what you think – have your say below, or email us directly at [email protected]

Comments

There are no comments. Why not be the first?

Add your comment

public sector executive tv

more videos >

last word

Prevention: Investing for the future

Prevention: Investing for the future

Rob Whiteman, CEO at the Chartered Institute of Public Finance (CIPFA), discusses the benefits of long-term preventative investment. Rising demand, reducing resource – this has been the r more > more last word articles >

public sector focus

View all News

comment

Peter Kyle MP: It’s time to say thank you this Public Service Day

21/06/2019Peter Kyle MP: It’s time to say thank you this Public Service Day

Taking time to say thank you is one of the hidden pillars of a society. Bei... more >
How community-led initiatives can help save the housing shortage

19/06/2019How community-led initiatives can help save the housing shortage

Tom Chance, director at the National Community Land Trust Network, argues t... more >

interviews

Artificial intelligence: the devil is in the data

17/12/2018Artificial intelligence: the devil is in the data

It’s no secret that the public sector and its service providers need ... more >