Select Committee on Science and Technology Minutes of Evidence


Memorandum by the Government (Home Office and the Department of Trade and Industry)

Security issues affecting private individuals when using communicating computer-based devices, either connecting directly to the Internet or employing other forms of inter-connectivity

SUMMARY

  THE INTRODUCTION SETS OUT OUR APPROACH TO THE WRITTEN EVIDENCE AND HIGHLIGHTS SOME OF THE KEY ISSUES AROUND SECURITY ISSUES AFFECTING PRIVATE INDIVIDUALS WHEN USING THE INTERNET.

In Section 1, we define what we know about the problem of security threats to private individuals by discussing the emergence of virtual organised crime groups who are organised and operate exclusively via the Internet. We highlight some of the methods used by the groups to exploit the Internet and give some statistics to demonstrate the scale of the problem. We end this section by discussing research which suggests that users do not understand the nature of online threats.

  In Section 2, we discuss how we are currently tackling the problem of security issues affecting private individuals. We highlight the potential concerns/trade-offs. We detail some of the positive work being done via public and private initiatives, such as Get Safe Online (GSOL), to raise awareness of the risks online. GSOL brings together government, industry and law enforcement to give people advice, guidance and the tools they need to be safe online. We highlight the importance of national and international co-operation to the threats and the Serious Organised Crime Agency (SOCA)'s role in ensuring this. We discuss how software and hardware can play a fundamental role in reducing the risk of security breaches, but caveat this by pointing out that technical solutions alone will not work. We end this section by highlighting a new initiative to improve the standing of UK research in this area.

  In Section 3, we look at the issue of IT governance and regulation. In terms of IT governance, we discuss initiatives that both industry and government are undertaking that appear to be impacting on the security threat. We discuss how security breaches that take place in this country can be instigated in another jurisdiction and the global nature of this issue. We therefore draw attention to some of the work being done internationally to ensure international law enforcement co-operation. When looking at regulations we discuss the fact that the regulatory framework is a mixture of international, EU, UK and industry regulations, which means that at times enforcing these can be challenging.

  We stress that over-regulation could affect our ability to create and maintain a flexible framework that keeps abreast of industry changes and could impact on the ability to provide innovative services and products.

  We end this section by discussing how cost and funding, timely assessments, technical ability and end use of systems are the main barriers to developing security systems and standards. We briefly discuss how these problems can be overcome.

  In Section 4, we look at crime prevention. We highlight the various activities through which the Government delivers crime prevention and discuss some of the current changes to legislation which will ensure that UK criminal law continues to meet the challenge of e-crime. We end this section by giving a flavour of the international actions on e-crime.

INTRODUCTION

  The Government is working collaboratively to protect private individuals from Internet security threats. Reflecting this joined up approach, this evidence is submitted by Home Office and DTI Ministers and encompasses work being undertaken by the key Departments and Agencies. These are:

    —  Home Office—responsible for public protection, including in this context policy on criminal law and policing;

    —  the Department of Trade and Industry (DTI) responsible for promoting the business and consumer benefits of the information age and the regulatory framework for service providers;

    —  the Serious Organised Crime Agency (SOCA), an intelligence-led agency with law enforcement powers, created to reduce the harm caused by organised crime to the UK; and

    —  the Cabinet Office responsible for the co-ordination of security policy overall and the delivery of the Government's information assurance strategy.

  Together, the efforts of these Departments and Agencies should help to create a culture of security online which maximises the benefits of using the internet, minimises the risks and tackles organised crime's exploitation of it.

  This submission also recognises that changing the way in which individuals think about and use the Internet is a challenge, and Government, users and industry, all have a role to play. We therefore discuss the ways in which we work to ensure we deliver the right combination of informed users, appropriate regulation and relevant technology to promote a culture of security. We appreciate that without all three there is a danger that individuals will not understand and address the risks and that industry will put innovation above safety.

  This submission also seeks to demonstrate how we actively support awareness raising through joint industry/government projects such as the Get Safe On Line initiative.

  This submission deals only with security issues in the sense of users' control of their technology or their personal information being compromised, rather than wider internet safety issues such as child protection or content regulation where there are many developments and a strong track record of Government and industry working together to develop self-regulatory solutions to issues like illegal images of child abuse. For consistency, we describe this as "e-crime".

SECTION 1: DEFINING THE PROBLEM

1.  What is the nature of the security threat to private individuals? What new threats and trends are emerging and how are they identified?

  The last 3-4 years has seen the emergence of virtual organised crime groups (OCGs) who are organised and operate exclusively via the Internet. Their membership is geographically dispersed and multinational. Their main goal is the exploitation of the Internet to steal personal data and identity information (commonly called "identity theft") to facilitate fraud. These groups are growing in size, number and sophistication.

  The UK has attracted the attention of these organised crime groups because of its relative affluence and speed of adoption of the Internet by individuals to buy goods and services online. There are 17 million Internet bank accounts in the UK and over £20 billion was spent online last year by UK customers. Attacking English-speaking countries may also pose fewer linguistic challenges than similar attacks on, for example, Japan.

  These groups seek to compromise the integrity of personal data using a variety of methods, targeting both individuals and enterprises which hold customer records. Attacks against individuals can be considered in two main categories: malicious software and "social engineering". Malicious software attacks are used to compromise home and small business machines. Once infected the malicious code is used to "harvest" personal data while the user is online. "Social engineering" refers to attacks, typically aimed at home users, which are intended to trick individuals into revealing sensitive personal information, such as bank login data and credit card details.

  In the past, attacks have tended to be large-scale and as a result attracted a higher profile. This tended to limit their effectiveness, because users were more likely to become aware of the threat and update their anti-virus software, and because their high rate of incidence made them more readily detectable by anti-virus companies. Attack patterns appear to be changing—malicious software is now typically distributed on a smaller scale, making it harder to detect. The software has become more sophisticated, and is often designed to disable or evade anti-virus systems, work in a phased approach to open back doors to systems and, increasingly, embed itself in the operating system to avoid detection. Some aspects of online behaviour are inherently more risky than others: "unofficial" file sharing sites offering music or video files are often used to mount malicious software attacks. Pirated software applications are inherently riskier than licensed versions and obviously more difficult to keep their security features up to date.

  Criminals are also targeting corporate networks to steal information, usually financial data, held on customer databases. Targets include e-Commerce sites, credit reference agencies and third party card processing agencies. Successful hacking attacks on these types of firm can yield huge amounts of personal information that can then be exploited by fraudsters. Globally, the worst reported incident is last year's hack of CardSystems Inc, a US credit/debit card processing company which resulted in the compromise of 40 million credit card accounts, with fraud confirmed on a minimum of 250,000 accounts.

  Although fraudulent transactions can be readily identified by banks and other financial institutions, it is difficult to assess what percentage of fraudulent activity is directly attributable to Internet attacks, as the exploitation of the Internet is one of several avenues used to obtain personal information. However, the financial services industry has made significant progress in identifying Internet attacks while they are underway, making effective mitigating action a realistic prospect in more situations than previously.

2.  What is the scale of the problem?

  There are many varying statistics referring to the scale of the problem. For example:

    —  one in every 52 emails in January and one in 28 emails in June 2005 were affected with malicious content (IBM);

    —  in 2004, total losses from online banking fraud were recorded for the first time and reached £12.2 million (APACS 2005). In 2005, online banking fraud grew to £23.3 million, an increase of 90 per cent from 2004;

    —  when asked which of a series of crimes individuals felt most at risk of in their everyday lives, 21 per cent identified Internet crime (higher than burglary 16 per cent, mugging 11 per cent or car theft 8 per cent) (GSOL survey Oct 2006);[1]

    —  the 2003-04 British Crime Survey found that 27 per cent of adults who used the Internet at home reported their computer had been affected by a virus (a third of those reported the computer had been damaged) in the previous 12 months. Two per cent of adults who used the Internet at home reported their computer had been accessed or files hacked into on their home computer in the previous 12 months.[2]

  These statistics must be set against the increasing level of transactional usage of the Internet by the general public and small businesses:

    —  the UK is now one of the leading e-commerce economies in the world. The volume of online card payments has increased five-fold over the last five years, reaching 310 million for a total of £22 billion. This accounts for five per cent of all personal card payments. There are over 17 million Internet bank accounts in the UK; and

    —  more than 50 per cent of small businesses conduct transactions over the Internet on a regular basis (APACs September 05).

  It should be noted that we are also seeing a significant shift in the Internet being used socially. A recent statistic from the IMRG (Interactive Media in Retail Group) indicates that the average web user spends more time online than watching television. Broadband "chat" now competes with daytime TV for the attention of women. This all means that people are spending more and more of their daily lives on the Internet.

3.  How are security breachers affecting the individual user detected and recorded?

  Not all personal users will be immediately aware that there has been a security breach. Increasingly, breaches are designed to run clandestinely on the machine and to evade firewall and anti-virus detection. On machines that do not have up to date protection, breaches are even less likely to come to light.

  Even where the user identifies they have been the victim of a breach, there is a great variation in response. According to the British Crime Survey, fewer than four in 10 of those who knew their computers were infected by a virus reported the incident at all. Of them, nine per cent reported to an ISP, 13 per cent to a website administrator and one per cent to the police.

  A number of private sector companies regularly comment on the changing nature and the extent of internet problems and industry bodies such as the the US-based SysAdmin, Audit, Network, Security (SANS) Institute do annual reviews of the key vulnerabilities. The DTI's biennial surveys measure the impact of information security breaches on UK business—not just those that arise from connection to the Internet—and the measures that are being taken to prevent damage.

4.  How well do users understand the nature of the threat?

  This is almost impossible to quantify, but see paragraph 6 for known information relating to the level of public awareness.

  However, the Office of Fair Trading has commissioned a wide-ranging market study into Internet Shopping[3] due to be published in spring 2007. The market study is exploring, through consumer research and stakeholder consultation, the scale of any mismatch between consumer fears and actual risks, as well as how these fears might be addressed.

SECTION 2: TACKLING THE PROBLEM

5.  What can and should be done to provide greater computer security to private individuals? What, if any, are the potential concerns and trade-offs?

  Both Government and industry have roles in ensuring that people are aware of the general risks online. Both also have a critical role to play in ensuring that the public are conducting online transactions with them safely. The nature of the Internet means that it is our collective responsibility to ensure that people are doing what they can to make themselves and their families safe online so that they can enjoy the real benefits of the Internet.

  Information, understanding and appropriate training are among the primary challenges in tackling the growing risk of Internet security threats, e-crime and online fraud. Simple, clear advice from one source is required to effectively improve the public's understanding of these threats and to encourage people to protect their personal information and electronic devices when online. Get Safe Online brings together Government, industry and law enforcement in a partnership to resource a campaign to give people the advice, guidance and the tools they need to be safe online (see next section).

  Increasingly computer retailers and manufacturers are providing additional security and safety software as part of a home computer package. Furthermore, many application software providers are incorporating more security features in their programs and organisations heavily reliant on online money transactions have for sometime offered free security products. However, although products are widely available and strongly marketed, there is reluctance amongst users to install and use them. The main reasons seem to be that installing packages is perceived by users: to be complex and cumbersome; to restrict choice by filtering sites/emails; to require regular time consuming security screening; costly (most work on the basis of monthly/annual subscription to receive regular updates). Even the take up of free programs offered via reputable organisations such as banks has been disappointingly low with only about five per cent of online customers using this service.

  We actively encourage users to assess risks and to put in place measures to mitigate those risks. For most users, off the shelf products provide the appropriate level of protection, however, in some circumstances such as banking online or registering tax returns more is required. In these cases, identity is the key issue and two factor authentication is becoming the preferred method of identifying the person or organisation you are interacting with. The Government is looking seriously at the whole issue of managing identity online. It is a key feature of Sir David Varney's work on transforming Government and the Chancellor of the Exchequer has asked Sir James Crosby to lead a piece of work on identity and the respective interests of the private and public sectors.

  The ISPs have a particular role in relation to the security of their customers and many offer security scanning and spam filtering services. We are in discussion with the ISPs as to how the industry might continue to make forward momentum in this area and demonstrate leadership in dealing with these problems.

6.  What is the level of public awareness of the threat to computer security and how effective are current initiatives in changing attitudes and raising that awareness?

  There are a range of public and private sector initiatives underway to raise public awareness of e-crime and the basic steps users can take to protect themselves. These include Get Safe On Line (GSOL), Bank Safe On Line, IT Safe and Fraud Alert. Between them they represent an important step forward in reducing the public's exposure to the risks of online fraud and data theft.

  The Get Safe Online[4] campaign launched in 2005 aims to raise awareness of the risks people face online and provide them with independent, authoritative advice, guidance and tools to help keep themselves and their families safe on the Internet. The campaign brings together several government departments and agencies (including the Cabinet Office, Home Office, DTI and SOCA) and involves some well-known UK and international private sector brand names including BT, Dell, eBay, HSBC, Lloyds TSB, MessageLabs, Microsoft, securetrading and Yell.com. Importantly, Get Safe Online has from the outset sought to measure public awareness to ensure that its messages are having an impact.

  The Get Safe Online website now has over 13,000 links to it. The 2005 campaign included road shows in 12 cities across the UK. Research was carried out before and after the campaign. The results showed that there was a very good level of awareness of the campaign and some indications of a shift in behaviour:

    —  three per cent of respondents were aware of the campaign or logo within one month of the launch of the campaign, and of these:

    —  62 per cent recognised the need to be careful when being online;

    —  52 per cent recognised it was their responsibility to stay safe;

    —  52 per cent understood the potential risks;

    —  40 per cent said that they had been prompted to find out more;

    —  awareness of threats such as key-logging and phishing[5] rose by 15 per cent and 12 per cent respectively;

    —  behaviour change had the greatest impact on backing-up data (75 per cent of those aware of the campaign did compared with 53 per cent of the non-aware).

  After the campaign, respondents were:

    —  more likely to have installed a firewall or anti-spy software;

    —  Significantly more likely to back up their data;

    —  significantly more likely to keep personal details private;

    —  more likely to use and update anti-virus and anti-spyware tools regularly.

  19 per cent of respondents felt less secure once aware of the risks whilst 24 per cent felt more secure through increased knowledge and reassurance that they were doing the right thing.

  A second phase of Get Safe Online activity was launched on 9 October 2006 and achieved a good level of national and local media coverage. Road shows were run in eight cities across the UK in shopping centres, libraries, community centres and town halls and providing training at UK Online centres.

  The main findings of the Get Safe Online Report October 200[6] are:

    —  Fear of e-crime is increasing. When asked whether they felt more at risk from bank card fraud, burglary, car theft and mugging, 21 per cent of people thought that Internet crime is the crime they are most likely to encounter. This is compared to 17 per cent who were most afraid of Internet crime a year ago.

    —  24 per cent of people have been deterred from Internet banking, more than a fifth (21 per cent) will not do their financial management online, 18 per cent will not shop online and one in six (17 per cent) have been put off using the Internet all together, as a result of concerns about e-crime.

    —  Three quarters of respondents look to people/organisations other than themselves to take responsibility for Internet safety. Over 40 per cent felt it should be the responsibility of the big online organisations to insure them against online fraud.

    —  Knowledge gap—72 per cent said they needed further information about online safety and 40 per cent were still not sure where to go for advice.

    —  A significant proportion of those surveyed (35 per cent) still go to friends and family first for advice about online safety, but encouragingly, a quarter are turning to websites like GSOL.

  The report indicates that there has been a shift in people accepting that it is primarily their own responsibility to make sure they are safe when online. A quarter thought it was their responsibility to make sure they are safe online, compared to only 15 per cent last year, but 41 per cent felt it was the job of big online organisations to protect them from online fraud.

7.  What factors may prevent private individuals from following appropriate security practices?

  Security is perceived as, at best, time-consuming and dull and, at worst, expensive and someone else's problem. Many people feel that it is too time-consuming to do anything about their Internet security and many of the technical terms used discourage users from investing their time.

  Get Safe Online aims to instil a sense of personal responsibility into PC users as well as offering advice and help to ensure they protect their personal details online. The campaign encourages people to use the same kind of common sense on the Internet that they would apply when out on the high street: "You wouldn't do this (ie give out your personal details) on the street—so why do it on the web?" was the strapline for the campaign.

  Another reason why PC users may be discouraged from taking adequate security measures is the cost of security products (Internet access can be relatively cheap whilst a firewall and anti-virus package can cost about £50).

  There is a move away from Internet connection via fixed computers with users increasingly accessing the Internet through mobile phones, games consoles and other devices. This leads to a new challenge in both making the technology secure and raising awareness of reasonable precautions that may be taken by users.

8.  What role do software and hardware design play in reducing the risk posed by security breaches? How much attention is paid to security in the design of new computer-based products?

  Hardware and software design is fundamental in reducing the risk posed by security breaches, and can also play a major role in highlighting the potential for, and the incidence and impact of, such breaches.

  It is probably fair to say that until recently security was not a key factor in designing many software or hardware products. In fast-moving industries like these, there is an inherent tension between getting a product to market and making sure it is a failsafe product. This problem becomes more challenging as products become even more complex and used in more situations.

  Bill Gates' memo to all Microsoft staff in 2001 indicating that the company had to turn round its performance on security was a turning point in this regard. There has been a shift towards software designers adopting engineering principles to review and identify vulnerable codes, which has resulted in employees being trained in developing more secure code to avoid future vulnerabilities.

  Although more secure coding will reduce software vulnerabilities is to be welcome, the increasing complexity of software will perhaps continue to give rise to new vulnerabilities There is also usually a time lag between the vulnerability being discovered and the software producer developing a "patch" that resolves the problem. During this time users are exposed to hackers exploiting the vulnerability.

  Another important development, in relation to hardware, is the collaborative effort of the ICT vendors to produce a Trusted Computing kernel to be incorporated in the next generation of PCs. This will enable applications to more easily utilise the inherent functionality of the PC to deploy security solutions.

  Again, it is important to note that technical solutions on their own do not work. Awareness raising, regulation and appropriate enforcement are vital in developing a secure Internet. Applications and hardware are tools with which to combat and reduce security threats, not a means of eradicating them.

9.  What is the standing of UK research in this area?

  We understand that the UK Research Councils will respond separately to this consultation. They will have a view on the standing of UK research. However we thought it useful to give a brief over view of a relatively new initiative, Innovation Platforms and Knowledge Transfer Networks (KTN),[7] aimed at strengthening the UK standing in this important area of research.

  Innovation platforms have been developed by the DTI Technology Strategy Board[8] to respond to a well defined societal challenge where Government Departments/Agencies, Research Councils, RDAs/DAs, business and the science base can work together. The first step towards an innovation platform in network security has been the establishment of a core group of partners. This core group provides policy oversight and has helped to develop a business and research community around network security.

  Future activities are expected from the DTI led Technology Programme. These will run alongside activities from other Government Departments, Research Councils and the DTI's own Cyber Security KTN to bring forward successful and co-ordinated innovative solutions in the area of online security.

  The area of Human Machine Interface[9] has been included in the list of technology priorities recently released for the Autumn 2006 and Spring 2007 competitions for Collaborative Research and Development (CR&D) projects in the Technology Programme. In order to strengthen network security there is a need to address human, as well as technological, vulnerabilities. The competition in Human Machine Interface in Network Security will be looking to support projects that address the challenge of effective communication of security to the non-specialist user and new systems and environmental design to reduce insider fraud. This is a "challenge-driven" approach, encouraging consortia to focus on achieving solutions to a societal challenge. Support will be in two stages—initially through supporting short feasibility studies, the best of which will be selected, leading to longer-term collaborative research and development projects, with the ability to make significant change.

  The Technology Strategy Board, Innovation Platforms and KTNs output and activity are aimed at stimulating innovation in areas such as security and informing government thinking.

  Foresight, another DTI research initiative has also carried out independent work in this area, see its 2004 project on Cyber Trust and Crime Prevention.[10]

SECTION 3: GOVERNANCE AND REGULATION

10.  How effective are initiatives on IT governance in reducing security threats?

  IT governance incorporates international, national and UK regulation as well as self-regulation. The online threat landscape[11] is complex with wave upon wave of threats to the user. Responding to the ever-changing threat from diverse sources and locations means the regulatory framework requires flexibility. As a consequence, the UK regulatory framework consists of self-regulation underpinned by supporting legislation.

  There are a number of industry initiatives impacting on the threat landscape. Most ISPs provide some form of email filtering to their consumers to reduce the impact of spam. Some larger ISPs offer security advice either online or via an advice line, some provide their consumers with security products free of charge or at reduced cost, others offer a range of links to security sites so that customers can purchase reputable products, most have contractual clauses that terminate the service on the grounds of unacceptable behaviour (commonly referred to as Acceptable Use Policy) and others are actively promoting public debate and awareness on security issues. Software providers are also involved in providing information, with some larger providers undertaking citizen programmes to raise security issues in schools and other public forums, circulating newsletters and security checklists.

  The DTI has long promoted information security as a key business enabler and stressed the importance of a risk management approach[12]—that is one that applies appropriate resources to real problems in a timely manner. To this end, the Government has worked with the British Standards Institute to develop and promote three standards on information security management. The two key standards are now international standards and are starting to make an impact globally. One is a guideline on information security management (ISO 17799) and the other is a management system standard which allows for third party assessment of compliance (ISO 27001). These standards will enable, in effect, tools for companies to address information risk as part of their corporate governance objective to manage risk and will, in many cases, lead to decisions being taken that will add to the security of customers of these companies.

  This year has seen the launch of the Institute of Information Security Professionals[13]—a development actively supported by DTI and the Cabinet Office. The Institute acts as an accreditation authority for the industry and it is anticipated that Membership and Fellowship of the Institute will be the internationally accepted gold standard "qualification" for information security professionals. By being able to recognise quality professionals working in the industry, individuals and companies will be more secure about the advice, services and products they provide or develop.

11.  How far do improvements in governance and regulation depend on international co-operation?

  The global nature and the pace of evolution of services put existing regulatory models and structures under real pressure to respond. Maintaining and improving governance and regulation can only be achieved through close working co-operation within the international community. In Europe, we have welcomed the creation of the European Network and Information Security Agency as a centre of expertise available for policy makers throughout Europe. It seeks to identify and spread best practice and has focused on the need for awareness raising at all levels of society. The World Summit on the Information Society is, through its work on Internet Governance, giving a global profile to the work to combat e-crime and deliver resilient services to users.

  The UK Government works closely with other governments and agencies in mitigating as many online risks as possible. Already we have a memorandum of understanding (MoU) with countries such as the USA and Australia. We are constantly looking at ways of improving co-operation by increasing the number of MoUs in operation or by developing more tailored ways of working together to improve security. We actively participate in Organisation for Economic Co-operation and Development (OECD) initiatives in this area.

  From a consumer perspective, the Office of Fair Trading has developed good working relations with enforcers in other countries. Whilst the basis of this work is generally informal, the UK also participates in the International Consumer Protection and Enforcement Network (ICPEN) and the London Action Plan of anti-spam authorities, which spans 5 continents. Greater co-ordination between enforcers at both a national and international level is likely to lead to greater compliance and more effective enforcement.

12.  Is the regulatory framework for Internet services adequate?

  The regulatory framework is a mixture of international, EU and UK regulation and industry self-regulation. Whilst traditional regulation is difficult, the industry has a history of self-regulation in a number of areas. The recent Ofcom report "Online Protection: A survey of consumer, industry and regulatory mechanisms and systems",[14] provides evidence for this approach and suggests that where the industry self-regulates or co-regulates with an ombudsman of the Government there is a higher level of consumer protection.

  However, there is a more general issue in developing regulatory frameworks for environments such as the Internet. Over-regulation and the lack of ability to foresee technological change may affect our ability to create a flexible framework that keeps abreast of industry changes. Over-regulation may also stifle the Internet's unique ability to provide innovative services and products to meet user needs/demands or drive business offshore. The Government and other stakeholders are contributing to the debate around the revision of the overarching framework applying the regulation of electronic communications. The Commission have indicated that the security of networks and the problems impacting directly on consumers will need to be addressed in this process.

  The remit of the Office of Fair Trading's fact-finding market study is limited to consumer protection rather than general security issues. Within this remit, early evidence suggests that the regulations are generally considered by a range of stakeholders (businesses, trade bodies, consumer groups and public sector organisations) to be broadly "fit for purpose". However, the picture appears more complicated when looking in detail at the four "case study" sectors (music, airline tickets, electrical and online auctions), each of which raises specific regulatory issues.

13.  What, if any, are the barriers to developing information security systems and standards and how can they be overcome?

  The DTI industry survey has shown that the level of investment in information security is rising but that there is still a significant skills gap and lack of awareness of the changing nature of the problem. It is by no means clear that there are significant barriers to the development of security standards—indeed there is an enormous amount of activity—but rather that the standards are not being applied in an effective manner. This relates to the skills gap identified in the DTI survey.

  At both national and international levels, a number of security standards are being developed. Within Europe (ETSI, CEN, CENELEC) this process is voluntary, and supported by organisations. Only limited funds are made available by the European Commission or national Governments and as such it is very much driven by those who have an interest and the time to undertake the work. The same holds for worldwide standards (where IETF, W3C, ITU are prominent).

  Standard setting requires expertise in technical areas. There is a limited supply of technical experts and they are spread thinly. The recently launched Institute of Information Security Professionals will help in raising the standing of the profession and should attract more engineers to specialise in it in the medium-term. The low levels of engineering postgraduates is an ongoing issue that has been taxing UK educationalists for a number of years and there are no easy solutions to this problem.

  Schemes such as the Common Criteria and Claims Tested Mark provide some level of standardisation, however both schemes have problems. The Common Criteria takes time to test a product and is relatively costly. The Claims Tested Mark costs less and the process takes only weeks to complete but it only tests the claims of the manufacturer or provider of the service. In both cases, the mark awarded lasts for a number of years during which time products are updated and claims become outdated. The results are therefore a snapshot of the security at a given time and, more importantly, in isolation. Product assurance is a positive move in improving online security, however it is only effective if used appropriately.

SECTION 4: CRIME PREVENTION

14.  How effective is Government crime prevention policy in this area? Are enforcement agencies adequately equipped to tackle these threats?

  Much of the Government's crime prevention activity in this area is delivered through Get Safe Online, as detailed above. However, there are a number of other activities, including:

    —  the ITSafe website[15] funded by the Home Office and the Cabinet Office provides home users and small businesses with alerts and advice drawn from NISCC[16] and a number of other sources on protecting computers, mobile phones and other devices from malicious attack;

    —  a number of local police forces provide advice on their websites;[17]

    —  the DTI provides advice to small businesses through its website[18] and through business link service.[19]

  Responding to the majority of crime relating to breaches of personal Internet security falls to local police forces. The total funding available to forces continues to rise and decisions on how to allocate those resources rest with Chief Constables. Since 2002, every police force in England and Wales has had its own computer crime unit of properly trained and equipped staff. These units have grown significantly in size over that period and the Home Office issued good practice guidance for managing them in 2004.

  In addition, the Serious Organised Crime Agency (SOCA) has e-crime and fraud (including online fraud) among its priorities. SOCA is an intelligence-led agency with law enforcement powers, created to reduce the harm caused by organised crime to the UK. It was formed in April from a number of agencies, including the National Crime Squad and within that the National High Tech Crime Unit. SOCA has an e-crime directorate responsible for minimising the harm to the UK caused by e-crime and criminals' use of technology.

  National and international co-operation is also a key element of the response to the threats. Police forces, HM Revenue and Customs and other agencies have interests in this area, and the various law enforcement interests are brought together in the National e-crime Strategy Group. SOCA is building on its inherited activities to develop a range of bilateral and multilateral partnerships with domestic and overseas law enforcement agencies to extend the reach of UK law enforcement's response to e-crime.

15.  Is the legislative framework in UK criminal law adequate to meet the challenge of cyber-crime?

  The Government is committed to ensuring that actions should be legal or illegal according to their merits, rather than the medium used, ie what is illegal offline should be illegal online and vice versa. As such, all legislation criminalises offences regardless of the means used to commit the offence.

  Where there is a need to revise legislation to take account of new criminal techniques we seek to do so. We liaise regularly with the prosecution and law enforcement authorities to ensure the criminal law remains fit for purpose, but are not aware of significant legislative gaps that hinder the agencies.

  For example, although the law relating to e-crime is generally fit for purpose, we have recently put before Parliament changes to the Computer Misuse Act 1990 to strengthen it. The changes will:

    —  Broaden the definition of the section 3 offence to clarify that that all means of interference with a computer system are criminalised—in particular ensuring that adequate provision is made to criminalise all forms of denial of service (DoS) attacks.

    —  Increase the maximum penalty for the section 1 offence of unauthorised access to computer material to two years to better reflect the seriousness of these offences as more and more sensitive systems and information have external connections and also ensure that the offence is extraditable. We are similarly proposing to increase the maximum penalty for the section 3 offence of unauthorised modification of computer material to 10 years.

    —  Create a new offence of making, adapting or supplying articles for use in computer misuse offences to discourage the market in the production and distribution of hacking tools (devices which can be utilised in the subsequent commission of offences of illegal access and systems and data interference). The new offence will allow us to will give effect to Article 6 of the Cybercrime Convention.

  Another example is the Fraud Bill. It will create a general offence of fraud (rather than focusing on specific acts as previous fraud statutes have done and deals with them in a technology neutral way), with three different ways of committing it—a person will be guilty of the general offence if he is dishonest and either:

    1.  makes a false representation (including a false representation to a machine); or

    2.  fails to disclose information; or

    3.  abuses a position of trust.

  This will cover the full variety of fraudulent behaviour and should ensure that the offence continues to be relevant as methods of crime and technology change and develop. The bill also brings forward other new offences which will assist in combating e-crime—these include:

    1.  an offence of obtaining services dishonestly—this will plug a legal loophole whereby, for example, fraudsters obtain services over the Internet, but are not subject to the current law of fraud as they have not deceived a person;

    2.  various offences of possessing, manufacturing or supplying equipment, such as a computer programme that can generate genuine credit card numbers, to be used to commit or facilitate fraud.

16.  How effectively does the UK participate in international actions on cyber-crime?

  The UK is an active international player in relation to e-crime, both operationally and strategically.

  UK law enforcement has strong links with operational colleagues overseas bilaterally, as well as through Europol, Interpol and the G8 contact network. International activity has tended to be focused through the National High Tech Crime Unit (now SOCA e-crime) and the Metropolitan Police Service and there are regular examples of successful investigations where UK law enforcement has been assisted by overseas colleagues or vice versa.

  At the political level, the UK is actively involved in setting the agenda on e-crime in various fora within Europe, the G8 and the Commonwealth and elsewhere. For example, the UK has been a driving in helping develop a common global approach to e-crime legislation through the Council of Europe Cybercrime Convention and placed e-crime high on its JHA agenda during last year's presidencies of the EU and the G8.


1   www.getsafeonline.org/media/GSO_Cyber_Report_2006.pdf Back

2   www.homeoffice.gov.uk/rds/pdfs06/rdsolr0906.pdf Back

3   http://www.oft.gov.uk/news/press+releases/2006/81-06.htm Back

4   www.getsafeonline.org Back

5   Phishing a type of fraud that tricks users into visiting malicious websites, typically through "spoofed" emails from well known banks, online retailers and credit card companies. Ofcom Online Protection Report June 2006. Back

6   www.getsafeonline.org/media/GSO_Cyber_Report_2006.pdf Back

7   http://www.ktnetworks.co.uk/epicentric_portal/site/cys/ Back

8   http://www.dti.gov.uk/innovation/tech-priorities-uk/tsb/index.html Back

9   The human-machine interface (HMI) is where people and technology meet. This people-technology intercept can be as simple as the grip on a hand tool or as complex as the flight deck of a jumbo jet (definition used by International Engineering Consortium). Back

10   http://www.foresight.gov.uk/previous_projects/cyber_trust_and_crime_prevention/index.html Back

11   For example, many home users have antivirus software and firewalls, which limit the chances of malware being downloaded accidentally, so increasingly phishing attacks are taking the form of directing users to websites via embedded hyperlinks. Back

12   Risk management is simply a practice of systematically selecting cost effective approaches for minimising the effect of threat realisation to the organisation. Dorfman, Mark S (1997). Introduction to Risk Management and Insurance (6th ed) Prentice Hall. Back

13   http://www.instisp.org/ Back

14   www.ofcom.org.uk/research/technology/onlineprotection/ Page 4, paragraph 1.7. Back

15   www.itsafe.gov.uk Back

16   www.niscc.gov.uk Back

17   eg: www.met.police.uk/crimeprevention/computer, www.sussex.police.uk/comp_crime/comp_crime Back

18   www.dti.gov.uk/sectors/infosec/ Back

19   www.businesslink.gov.uk Back


 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007