Skip to main content

Proceeding contribution from Barry Gardiner (Labour) in the House of Commons on Wednesday, 23 November 2005. It occurred during Adjournment debate on Cyber Security.


Cyber Security

: I understand the tenor of the hon. Gentleman's remarks. However, NISCC has established good working relations with the management of public and private sector owners of the infrastructure. It discusses with them, as a trusted partner, how those systems are secured against a constantly changing threat paradigm. It has established communities in the relevant sectors called information exchanges, where front-line security specialists can talk frankly about emerging problems and solutions. There are active information exchanges in the financial and communications sectors. In terms of this aspect of Government policy, we are one of the world's leading nations. The UK experience is seen as important, particularly as the EU gets to grips with the issue in the context of new threats to our security. Of course, the business community understands that the move to the information age will function only if there is confidence in systems and networks that are resilient and that do not pose a risk to the privacy or the pocket of the user. We all know that mistakes have been made in the past and that, in the rush to get the world connected, security was perhaps sometimes traded off against functionality. Those days are long gone and there has been a move by vendors to work towards a much more inherently secure generation of both hardware and software. I draw the hon. Gentleman's attention to the trusted computing initiative, which brings together the leading technology vendors in a joint enterprise to address the issue. That, of course, reflects an increased concern by Government that technology should develop in a way that is inherently more resilient. The continued resilience of the internet was one of the underlying public policy concerns that drove the recent world summit on the information society. I am pleased to say that, difficult as it was, we have an outcome in terms of future stakeholder engagement on these issues that is a step forward. I can report that we have had notable success and have agreed that the way forward from the summit will address cyber security and spam. The summit constitutes a call for further co-operation by all stakeholders, and for Government and industry to move forward in partnership. While the business community is addressing the issue, we must accept that there remain several important roles for Government. At this stage, we have not sought to go further than is necessary down the path of regulation. The relevant regulation in this area is rightly lean and focused. Those who process sensitive personal information are bound by the Data Protection Act 1998 to apply appropriate protection to ensure that such information is not inappropriately accessed. There are fairly broad requirements on those who provide communications services to ensure that they are secure. There is a role for Government and business to work together in a non-regulatory way. I have mentioned the work undertaken as part of our national security agenda and the collaboration with technology vendors in relation to the Government's own requirements. We are also working with technology vendors and service providers to deal with the new generation of malicious software, which first became a problem as those who pushed out spam sought to conceal their activities by colonising the computers of other internet users to pass on their products. That led to an explosion of criminal activity based on the ability to dupe innocent users into giving up personal information or downloading software that, through constantly changing technology, seeks to extract personal information or passwords in order to access online accounts. The new generation of malicious software, by which I mean spyware, keyloggers, adware and the like, is requiring new defences to work with the approaches developed to combat the virus and worm attacks that there have been since the late 1990s. The Government have been among the leaders in trying to develop a multifaceted approach to the problem, looking at a toolkit of regulatory technological processes and awareness-raising tools. One of the issues emerging is the pressing need to find a solution to the problem of identity online. The failure to have certainty about the identity of the person or body that one is dealing with is at the heart of many of the problems. I am glad to note that the question of electronic identities is moving up the agenda for further work in the EU, and the thinking on our own identity card will be informed by the need for greater certainty about online identities. My Department can make an important contribution to the future of cyber security through the work that we support in the research community and through our existing programmes to support innovation. I remind hon. Members that Lord Sainsbury of Turville, who is responsible for the Office of Science and Technology, commissioned a major piece of work in 2004 under the foresight programme. It was called cyber trust. It took a long-term, scenario-based approach and identified possible directions for technological and sociological work in this area. The Department's innovation programme is reflecting that thinking and work is under way to improve the way in which the UK's supplier base can improve its performance in adopting new ideas.


Secondary information

Type
Proceeding contribution
Reference
439 c478-80WH 
Session
2005-06
Chamber / Committee
Westminster Hall
Subjects
Hacking Cybersecurity
Link
View this Proceeding contribution on www.publications.parliament.uk