Skip to main content

Written question asked by Viscount Waverley (Crossbench), in the House of Lords. It was answered by Lord Patel of Bradford (Labour) on Wednesday, 29 October 2008.


Government: Online Transactions

Question
Whether it is their policy for all government websites that solicit information to use computerised certificates; and
Answer

There are many different ways of securing communications between government departments and citizens. The appropriate method is adopted to suit the needs of the particular business. Such security and authentication regimes include measures such as: traditional cryptography, transport layer security, and X.509 server certificates as well as digital certificates. Many of the secure links between government departments use traditional cryptography which does not use certificates. Where personal or sensitive information is exchanged electronically with a member of the public, this is usually secured through the use of the industry standard transport layer security (TSL) and an X.509 server certificate rather than using a HMG root certificate. Central government departments with internet websites using personal or other sensitive information are required to implement appropriate protective measures. Normally, this would include the use of the industry standard transport layer security (TSL) one component of which would be an X.509 server certificate. In exceptional cases client certificates are also used. Some public key certificates issued by the Government can be expected to be held overseas. For example, certificates relating to verifications of passports need to be held overseas in order to check the authenticity of UK passports. Certificates issued to departments or their agencies contain no reference to individuals or their personal information. There is no requirement for these certificates to be treated confidentially. Some certificates are issued to individuals and could contain personal information. In such instances, the handling of these certificates would need to comply with the relevant data protection principles. Data stored in the UK and overseas must adhere to data protection legislation.


Secondary information

Type
Written question
Reference
704 c169WA; 4029
Session
2007-08
Subjects
Data protection Government departments Internet Email Security Electronic government
Link
View this Written question on www.publications.parliament.uk