Memorandum by the Government (Home Office
and the Department of Trade and Industry)
Security issues affecting private individuals when
using communicating computer-based devices, either connecting
directly to the Internet or employing other forms of inter-connectivity
SUMMARY
THE INTRODUCTION
SETS OUT
OUR APPROACH
TO THE
WRITTEN EVIDENCE
AND HIGHLIGHTS
SOME OF
THE KEY
ISSUES AROUND
SECURITY ISSUES
AFFECTING PRIVATE
INDIVIDUALS WHEN
USING THE
INTERNET.
In Section 1, we define what we know about the problem
of security threats to private individuals by discussing the emergence
of virtual organised crime groups who are organised and operate
exclusively via the Internet. We highlight some of the methods
used by the groups to exploit the Internet and give some statistics
to demonstrate the scale of the problem. We end this section by
discussing research which suggests that users do not understand
the nature of online threats.
In Section 2, we discuss how we are currently
tackling the problem of security issues affecting private individuals.
We highlight the potential concerns/trade-offs. We detail some
of the positive work being done via public and private initiatives,
such as Get Safe Online (GSOL), to raise awareness of the risks
online. GSOL brings together government, industry and law enforcement
to give people advice, guidance and the tools they need to be
safe online. We highlight the importance of national and international
co-operation to the threats and the Serious Organised Crime Agency
(SOCA)'s role in ensuring this. We discuss how software and hardware
can play a fundamental role in reducing the risk of security breaches,
but caveat this by pointing out that technical solutions alone
will not work. We end this section by highlighting a new initiative
to improve the standing of UK research in this area.
In Section 3, we look at the issue of IT governance
and regulation. In terms of IT governance, we discuss initiatives
that both industry and government are undertaking that appear
to be impacting on the security threat. We discuss how security
breaches that take place in this country can be instigated in
another jurisdiction and the global nature of this issue. We therefore
draw attention to some of the work being done internationally
to ensure international law enforcement co-operation. When looking
at regulations we discuss the fact that the regulatory framework
is a mixture of international, EU, UK and industry regulations,
which means that at times enforcing these can be challenging.
We stress that over-regulation could affect
our ability to create and maintain a flexible framework that keeps
abreast of industry changes and could impact on the ability to
provide innovative services and products.
We end this section by discussing how cost and
funding, timely assessments, technical ability and end use of
systems are the main barriers to developing security systems and
standards. We briefly discuss how these problems can be overcome.
In Section 4, we look at crime prevention. We
highlight the various activities through which the Government
delivers crime prevention and discuss some of the current changes
to legislation which will ensure that UK criminal law continues
to meet the challenge of e-crime. We end this section by giving
a flavour of the international actions on e-crime.
INTRODUCTION
The Government is working collaboratively to
protect private individuals from Internet security threats. Reflecting
this joined up approach, this evidence is submitted by Home Office
and DTI Ministers and encompasses work being undertaken by the
key Departments and Agencies. These are:
Home Officeresponsible for
public protection, including in this context policy on criminal
law and policing;
the Department of Trade and Industry
(DTI) responsible for promoting the business and consumer benefits
of the information age and the regulatory framework for service
providers;
the Serious Organised Crime Agency
(SOCA), an intelligence-led agency with law enforcement powers,
created to reduce the harm caused by organised crime to the UK;
and
the Cabinet Office responsible for
the co-ordination of security policy overall and the delivery
of the Government's information assurance strategy.
Together, the efforts of these Departments and
Agencies should help to create a culture of security online which
maximises the benefits of using the internet, minimises the risks
and tackles organised crime's exploitation of it.
This submission also recognises that changing
the way in which individuals think about and use the Internet
is a challenge, and Government, users and industry, all have a
role to play. We therefore discuss the ways in which we work to
ensure we deliver the right combination of informed users, appropriate
regulation and relevant technology to promote a culture of security.
We appreciate that without all three there is a danger that individuals
will not understand and address the risks and that industry will
put innovation above safety.
This submission also seeks to demonstrate how
we actively support awareness raising through joint industry/government
projects such as the Get Safe On Line initiative.
This submission deals only with security issues
in the sense of users' control of their technology or their personal
information being compromised, rather than wider internet safety
issues such as child protection or content regulation where there
are many developments and a strong track record of Government
and industry working together to develop self-regulatory solutions
to issues like illegal images of child abuse. For consistency,
we describe this as "e-crime".
SECTION 1: DEFINING
THE PROBLEM
1. What is the nature of the security threat
to private individuals? What new threats and trends are emerging
and how are they identified?
The last 3-4 years has seen the emergence of
virtual organised crime groups (OCGs) who are organised and operate
exclusively via the Internet. Their membership is geographically
dispersed and multinational. Their main goal is the exploitation
of the Internet to steal personal data and identity information
(commonly called "identity theft") to facilitate fraud.
These groups are growing in size, number and sophistication.
The UK has attracted the attention of these
organised crime groups because of its relative affluence and speed
of adoption of the Internet by individuals to buy goods and services
online. There are 17 million Internet bank accounts in the UK
and over £20 billion was spent online last year by UK customers.
Attacking English-speaking countries may also pose fewer linguistic
challenges than similar attacks on, for example, Japan.
These groups seek to compromise the integrity
of personal data using a variety of methods, targeting both individuals
and enterprises which hold customer records. Attacks against individuals
can be considered in two main categories: malicious software and
"social engineering". Malicious software attacks are
used to compromise home and small business machines. Once infected
the malicious code is used to "harvest" personal data
while the user is online. "Social engineering" refers
to attacks, typically aimed at home users, which are intended
to trick individuals into revealing sensitive personal information,
such as bank login data and credit card details.
In the past, attacks have tended to be large-scale
and as a result attracted a higher profile. This tended to limit
their effectiveness, because users were more likely to become
aware of the threat and update their anti-virus software, and
because their high rate of incidence made them more readily detectable
by anti-virus companies. Attack patterns appear to be changingmalicious
software is now typically distributed on a smaller scale, making
it harder to detect. The software has become more sophisticated,
and is often designed to disable or evade anti-virus systems,
work in a phased approach to open back doors to systems and, increasingly,
embed itself in the operating system to avoid detection. Some
aspects of online behaviour are inherently more risky than others:
"unofficial" file sharing sites offering music or video
files are often used to mount malicious software attacks. Pirated
software applications are inherently riskier than licensed versions
and obviously more difficult to keep their security features up
to date.
Criminals are also targeting corporate networks
to steal information, usually financial data, held on customer
databases. Targets include e-Commerce sites, credit reference
agencies and third party card processing agencies. Successful
hacking attacks on these types of firm can yield huge amounts
of personal information that can then be exploited by fraudsters.
Globally, the worst reported incident is last year's hack of CardSystems
Inc, a US credit/debit card processing company which resulted
in the compromise of 40 million credit card accounts, with fraud
confirmed on a minimum of 250,000 accounts.
Although fraudulent transactions can be readily
identified by banks and other financial institutions, it is difficult
to assess what percentage of fraudulent activity is directly attributable
to Internet attacks, as the exploitation of the Internet is one
of several avenues used to obtain personal information. However,
the financial services industry has made significant progress
in identifying Internet attacks while they are underway, making
effective mitigating action a realistic prospect in more situations
than previously.
2. What is the scale of the problem?
There are many varying statistics referring
to the scale of the problem. For example:
one in every 52 emails in January
and one in 28 emails in June 2005 were affected with malicious
content (IBM);
in 2004, total losses from online
banking fraud were recorded for the first time and reached £12.2
million (APACS 2005). In 2005, online banking fraud grew to £23.3
million, an increase of 90 per cent from 2004;
when asked which of a series of crimes
individuals felt most at risk of in their everyday lives, 21 per
cent identified Internet crime (higher than burglary 16 per cent,
mugging 11 per cent or car theft 8 per cent) (GSOL survey Oct
2006);[1]
the 2003-04 British Crime Survey
found that 27 per cent of adults who used the Internet at home
reported their computer had been affected by a virus (a third
of those reported the computer had been damaged) in the previous
12 months. Two per cent of adults who used the Internet at home
reported their computer had been accessed or files hacked into
on their home computer in the previous 12 months.[2]
These statistics must be set against the increasing
level of transactional usage of the Internet by the general public
and small businesses:
the UK is now one of the leading
e-commerce economies in the world. The volume of online card payments
has increased five-fold over the last five years, reaching 310
million for a total of £22 billion. This accounts for five
per cent of all personal card payments. There are over 17 million
Internet bank accounts in the UK; and
more than 50 per cent of small businesses
conduct transactions over the Internet on a regular basis (APACs
September 05).
It should be noted that we are also seeing a
significant shift in the Internet being used socially. A recent
statistic from the IMRG (Interactive Media in Retail Group) indicates
that the average web user spends more time online than watching
television. Broadband "chat" now competes with daytime
TV for the attention of women. This all means that people are
spending more and more of their daily lives on the Internet.
3. How are security breachers affecting the
individual user detected and recorded?
Not all personal users will be immediately aware
that there has been a security breach. Increasingly, breaches
are designed to run clandestinely on the machine and to evade
firewall and anti-virus detection. On machines that do not have
up to date protection, breaches are even less likely to come to
light.
Even where the user identifies they have been
the victim of a breach, there is a great variation in response.
According to the British Crime Survey, fewer than four in 10 of
those who knew their computers were infected by a virus reported
the incident at all. Of them, nine per cent reported to an ISP,
13 per cent to a website administrator and one per cent to the
police.
A number of private sector companies regularly
comment on the changing nature and the extent of internet problems
and industry bodies such as the the US-based SysAdmin, Audit,
Network, Security (SANS) Institute do annual reviews of the key
vulnerabilities. The DTI's biennial surveys measure the impact
of information security breaches on UK businessnot just
those that arise from connection to the Internetand the
measures that are being taken to prevent damage.
4. How well do users understand the nature
of the threat?
This is almost impossible to quantify, but see
paragraph 6 for known information relating to the level of public
awareness.
However, the Office of Fair Trading has commissioned
a wide-ranging market study into Internet Shopping[3]
due to be published in spring 2007. The market study is exploring,
through consumer research and stakeholder consultation, the scale
of any mismatch between consumer fears and actual risks, as well
as how these fears might be addressed.
SECTION 2: TACKLING
THE PROBLEM
5. What can and should be done to provide
greater computer security to private individuals? What, if any,
are the potential concerns and trade-offs?
Both Government and industry have roles in ensuring
that people are aware of the general risks online. Both also have
a critical role to play in ensuring that the public are conducting
online transactions with them safely. The nature of the Internet
means that it is our collective responsibility to ensure that
people are doing what they can to make themselves and their families
safe online so that they can enjoy the real benefits of the Internet.
Information, understanding and appropriate training
are among the primary challenges in tackling the growing risk
of Internet security threats, e-crime and online fraud. Simple,
clear advice from one source is required to effectively improve
the public's understanding of these threats and to encourage people
to protect their personal information and electronic devices when
online. Get Safe Online brings together Government, industry and
law enforcement in a partnership to resource a campaign to give
people the advice, guidance and the tools they need to be safe
online (see next section).
Increasingly computer retailers and manufacturers
are providing additional security and safety software as part
of a home computer package. Furthermore, many application software
providers are incorporating more security features in their programs
and organisations heavily reliant on online money transactions
have for sometime offered free security products. However, although
products are widely available and strongly marketed, there is
reluctance amongst users to install and use them. The main reasons
seem to be that installing packages is perceived by users: to
be complex and cumbersome; to restrict choice by filtering sites/emails;
to require regular time consuming security screening; costly (most
work on the basis of monthly/annual subscription to receive regular
updates). Even the take up of free programs offered via reputable
organisations such as banks has been disappointingly low with
only about five per cent of online customers using this service.
We actively encourage users to assess risks
and to put in place measures to mitigate those risks. For most
users, off the shelf products provide the appropriate level of
protection, however, in some circumstances such as banking online
or registering tax returns more is required. In these cases, identity
is the key issue and two factor authentication is becoming the
preferred method of identifying the person or organisation you
are interacting with. The Government is looking seriously at the
whole issue of managing identity online. It is a key feature of
Sir David Varney's work on transforming Government and the Chancellor
of the Exchequer has asked Sir James Crosby to lead a piece of
work on identity and the respective interests of the private and
public sectors.
The ISPs have a particular role in relation
to the security of their customers and many offer security scanning
and spam filtering services. We are in discussion with the ISPs
as to how the industry might continue to make forward momentum
in this area and demonstrate leadership in dealing with these
problems.
6. What is the level of public awareness of
the threat to computer security and how effective are current
initiatives in changing attitudes and raising that awareness?
There are a range of public and private sector
initiatives underway to raise public awareness of e-crime and
the basic steps users can take to protect themselves. These include
Get Safe On Line (GSOL), Bank Safe On Line, IT Safe and Fraud
Alert. Between them they represent an important step forward in
reducing the public's exposure to the risks of online fraud and
data theft.
The Get Safe Online[4]
campaign launched in 2005 aims to raise awareness of the risks
people face online and provide them with independent, authoritative
advice, guidance and tools to help keep themselves and their families
safe on the Internet. The campaign brings together several government
departments and agencies (including the Cabinet Office, Home Office,
DTI and SOCA) and involves some well-known UK and international
private sector brand names including BT, Dell, eBay, HSBC, Lloyds
TSB, MessageLabs, Microsoft, securetrading and Yell.com. Importantly,
Get Safe Online has from the outset sought to measure public awareness
to ensure that its messages are having an impact.
The Get Safe Online website now has over 13,000
links to it. The 2005 campaign included road shows in 12 cities
across the UK. Research was carried out before and after the campaign.
The results showed that there was a very good level of awareness
of the campaign and some indications of a shift in behaviour:
three per cent of respondents were
aware of the campaign or logo within one month of the launch of
the campaign, and of these:
62 per cent recognised the need to
be careful when being online;
52 per cent recognised it was their
responsibility to stay safe;
52 per cent understood the potential
risks;
40 per cent said that they had been
prompted to find out more;
awareness of threats such as key-logging
and phishing[5]
rose by 15 per cent and 12 per cent respectively;
behaviour change had the greatest
impact on backing-up data (75 per cent of those aware of the campaign
did compared with 53 per cent of the non-aware).
After the campaign, respondents were:
more likely to have installed a firewall
or anti-spy software;
Significantly more likely to back
up their data;
significantly more likely to keep
personal details private;
more likely to use and update anti-virus
and anti-spyware tools regularly.
19 per cent of respondents felt less secure
once aware of the risks whilst 24 per cent felt more secure through
increased knowledge and reassurance that they were doing the right
thing.
A second phase of Get Safe Online activity was
launched on 9 October 2006 and achieved a good level of national
and local media coverage. Road shows were run in eight cities
across the UK in shopping centres, libraries, community centres
and town halls and providing training at UK Online centres.
The main findings of the Get Safe Online Report
October 200[6]
are:
Fear of e-crime is increasing. When
asked whether they felt more at risk from bank card fraud, burglary,
car theft and mugging, 21 per cent of people thought that Internet
crime is the crime they are most likely to encounter. This is
compared to 17 per cent who were most afraid of Internet crime
a year ago.
24 per cent of people have been deterred
from Internet banking, more than a fifth (21 per cent) will not
do their financial management online, 18 per cent will not shop
online and one in six (17 per cent) have been put off using the
Internet all together, as a result of concerns about e-crime.
Three quarters of respondents look
to people/organisations other than themselves to take responsibility
for Internet safety. Over 40 per cent felt it should be the responsibility
of the big online organisations to insure them against online
fraud.
Knowledge gap72 per cent said
they needed further information about online safety and 40 per
cent were still not sure where to go for advice.
A significant proportion of those
surveyed (35 per cent) still go to friends and family first for
advice about online safety, but encouragingly, a quarter are turning
to websites like GSOL.
The report indicates that there has been a shift
in people accepting that it is primarily their own responsibility
to make sure they are safe when online. A quarter thought it was
their responsibility to make sure they are safe online, compared
to only 15 per cent last year, but 41 per cent felt it was the
job of big online organisations to protect them from online fraud.
7. What factors may prevent private individuals
from following appropriate security practices?
Security is perceived as, at best, time-consuming
and dull and, at worst, expensive and someone else's problem.
Many people feel that it is too time-consuming to do anything
about their Internet security and many of the technical terms
used discourage users from investing their time.
Get Safe Online aims to instil a sense of personal
responsibility into PC users as well as offering advice and help
to ensure they protect their personal details online. The campaign
encourages people to use the same kind of common sense on the
Internet that they would apply when out on the high street: "You
wouldn't do this (ie give out your personal details) on the streetso
why do it on the web?" was the strapline for the campaign.
Another reason why PC users may be discouraged
from taking adequate security measures is the cost of security
products (Internet access can be relatively cheap whilst a firewall
and anti-virus package can cost about £50).
There is a move away from Internet connection
via fixed computers with users increasingly accessing the Internet
through mobile phones, games consoles and other devices. This
leads to a new challenge in both making the technology secure
and raising awareness of reasonable precautions that may be taken
by users.
8. What role do software and hardware design
play in reducing the risk posed by security breaches? How much
attention is paid to security in the design of new computer-based
products?
Hardware and software design is fundamental
in reducing the risk posed by security breaches, and can also
play a major role in highlighting the potential for, and the incidence
and impact of, such breaches.
It is probably fair to say that until recently
security was not a key factor in designing many software or hardware
products. In fast-moving industries like these, there is an inherent
tension between getting a product to market and making sure it
is a failsafe product. This problem becomes more challenging as
products become even more complex and used in more situations.
Bill Gates' memo to all Microsoft staff in 2001
indicating that the company had to turn round its performance
on security was a turning point in this regard. There has been
a shift towards software designers adopting engineering principles
to review and identify vulnerable codes, which has resulted in
employees being trained in developing more secure code to avoid
future vulnerabilities.
Although more secure coding will reduce software
vulnerabilities is to be welcome, the increasing complexity of
software will perhaps continue to give rise to new vulnerabilities
There is also usually a time lag between the vulnerability being
discovered and the software producer developing a "patch"
that resolves the problem. During this time users are exposed
to hackers exploiting the vulnerability.
Another important development, in relation to
hardware, is the collaborative effort of the ICT vendors to produce
a Trusted Computing kernel to be incorporated in the next generation
of PCs. This will enable applications to more easily utilise the
inherent functionality of the PC to deploy security solutions.
Again, it is important to note that technical
solutions on their own do not work. Awareness raising, regulation
and appropriate enforcement are vital in developing a secure Internet.
Applications and hardware are tools with which to combat and reduce
security threats, not a means of eradicating them.
9. What is the standing of UK research in
this area?
We understand that the UK Research Councils
will respond separately to this consultation. They will have a
view on the standing of UK research. However we thought it useful
to give a brief over view of a relatively new initiative, Innovation
Platforms and Knowledge Transfer Networks (KTN),[7]
aimed at strengthening the UK standing in this important area
of research.
Innovation platforms have been developed by
the DTI Technology Strategy Board[8]
to respond to a well defined societal challenge where Government
Departments/Agencies, Research Councils, RDAs/DAs, business and
the science base can work together. The first step towards an
innovation platform in network security has been the establishment
of a core group of partners. This core group provides policy oversight
and has helped to develop a business and research community around
network security.
Future activities are expected from the DTI
led Technology Programme. These will run alongside activities
from other Government Departments, Research Councils and the DTI's
own Cyber Security KTN to bring forward successful and co-ordinated
innovative solutions in the area of online security.
The area of Human Machine Interface[9]
has been included in the list of technology priorities recently
released for the Autumn 2006 and Spring 2007 competitions for
Collaborative Research and Development (CR&D) projects in
the Technology Programme. In order to strengthen network security
there is a need to address human, as well as technological, vulnerabilities.
The competition in Human Machine Interface in Network Security
will be looking to support projects that address the challenge
of effective communication of security to the non-specialist user
and new systems and environmental design to reduce insider fraud.
This is a "challenge-driven" approach, encouraging consortia
to focus on achieving solutions to a societal challenge. Support
will be in two stagesinitially through supporting short
feasibility studies, the best of which will be selected, leading
to longer-term collaborative research and development projects,
with the ability to make significant change.
The Technology Strategy Board, Innovation Platforms
and KTNs output and activity are aimed at stimulating innovation
in areas such as security and informing government thinking.
Foresight, another DTI research initiative has
also carried out independent work in this area, see its 2004 project
on Cyber Trust and Crime Prevention.[10]
SECTION 3: GOVERNANCE
AND REGULATION
10. How effective are initiatives on IT governance
in reducing security threats?
IT governance incorporates international, national
and UK regulation as well as self-regulation. The online threat
landscape[11]
is complex with wave upon wave of threats to the user. Responding
to the ever-changing threat from diverse sources and locations
means the regulatory framework requires flexibility. As a consequence,
the UK regulatory framework consists of self-regulation underpinned
by supporting legislation.
There are a number of industry initiatives impacting
on the threat landscape. Most ISPs provide some form of email
filtering to their consumers to reduce the impact of spam. Some
larger ISPs offer security advice either online or via an advice
line, some provide their consumers with security products free
of charge or at reduced cost, others offer a range of links to
security sites so that customers can purchase reputable products,
most have contractual clauses that terminate the service on the
grounds of unacceptable behaviour (commonly referred to as Acceptable
Use Policy) and others are actively promoting public debate and
awareness on security issues. Software providers are also involved
in providing information, with some larger providers undertaking
citizen programmes to raise security issues in schools and other
public forums, circulating newsletters and security checklists.
The DTI has long promoted information security
as a key business enabler and stressed the importance of a risk
management approach[12]that
is one that applies appropriate resources to real problems in
a timely manner. To this end, the Government has worked with the
British Standards Institute to develop and promote three standards
on information security management. The two key standards are
now international standards and are starting to make an impact
globally. One is a guideline on information security management
(ISO 17799) and the other is a management system standard which
allows for third party assessment of compliance (ISO 27001). These
standards will enable, in effect, tools for companies to address
information risk as part of their corporate governance objective
to manage risk and will, in many cases, lead to decisions being
taken that will add to the security of customers of these companies.
This year has seen the launch of the Institute
of Information Security Professionals[13]a
development actively supported by DTI and the Cabinet Office.
The Institute acts as an accreditation authority for the industry
and it is anticipated that Membership and Fellowship of the Institute
will be the internationally accepted gold standard "qualification"
for information security professionals. By being able to recognise
quality professionals working in the industry, individuals and
companies will be more secure about the advice, services and products
they provide or develop.
11. How far do improvements in governance
and regulation depend on international co-operation?
The global nature and the pace of evolution
of services put existing regulatory models and structures under
real pressure to respond. Maintaining and improving governance
and regulation can only be achieved through close working co-operation
within the international community. In Europe, we have welcomed
the creation of the European Network and Information Security
Agency as a centre of expertise available for policy makers throughout
Europe. It seeks to identify and spread best practice and has
focused on the need for awareness raising at all levels of society.
The World Summit on the Information Society is, through its work
on Internet Governance, giving a global profile to the work to
combat e-crime and deliver resilient services to users.
The UK Government works closely with other governments
and agencies in mitigating as many online risks as possible. Already
we have a memorandum of understanding (MoU) with countries such
as the USA and Australia. We are constantly looking at ways of
improving co-operation by increasing the number of MoUs in operation
or by developing more tailored ways of working together to improve
security. We actively participate in Organisation for Economic
Co-operation and Development (OECD) initiatives in this area.
From a consumer perspective, the Office of Fair
Trading has developed good working relations with enforcers in
other countries. Whilst the basis of this work is generally informal,
the UK also participates in the International Consumer Protection
and Enforcement Network (ICPEN) and the London Action Plan of
anti-spam authorities, which spans 5 continents. Greater co-ordination
between enforcers at both a national and international level is
likely to lead to greater compliance and more effective enforcement.
12. Is the regulatory framework for Internet
services adequate?
The regulatory framework is a mixture of international,
EU and UK regulation and industry self-regulation. Whilst traditional
regulation is difficult, the industry has a history of self-regulation
in a number of areas. The recent Ofcom report "Online Protection:
A survey of consumer, industry and regulatory mechanisms and systems",[14]
provides evidence for this approach and suggests that where the
industry self-regulates or co-regulates with an ombudsman of the
Government there is a higher level of consumer protection.
However, there is a more general issue in developing
regulatory frameworks for environments such as the Internet. Over-regulation
and the lack of ability to foresee technological change may affect
our ability to create a flexible framework that keeps abreast
of industry changes. Over-regulation may also stifle the Internet's
unique ability to provide innovative services and products to
meet user needs/demands or drive business offshore. The Government
and other stakeholders are contributing to the debate around the
revision of the overarching framework applying the regulation
of electronic communications. The Commission have indicated that
the security of networks and the problems impacting directly on
consumers will need to be addressed in this process.
The remit of the Office of Fair Trading's fact-finding
market study is limited to consumer protection rather than general
security issues. Within this remit, early evidence suggests that
the regulations are generally considered by a range of stakeholders
(businesses, trade bodies, consumer groups and public sector organisations)
to be broadly "fit for purpose". However, the picture
appears more complicated when looking in detail at the four "case
study" sectors (music, airline tickets, electrical and online
auctions), each of which raises specific regulatory issues.
13. What, if any, are the barriers to developing
information security systems and standards and how can they be
overcome?
The DTI industry survey has shown that the level
of investment in information security is rising but that there
is still a significant skills gap and lack of awareness of the
changing nature of the problem. It is by no means clear that there
are significant barriers to the development of security standardsindeed
there is an enormous amount of activitybut rather that
the standards are not being applied in an effective manner. This
relates to the skills gap identified in the DTI survey.
At both national and international levels, a
number of security standards are being developed. Within Europe
(ETSI, CEN, CENELEC) this process is voluntary, and supported
by organisations. Only limited funds are made available by the
European Commission or national Governments and as such it is
very much driven by those who have an interest and the time to
undertake the work. The same holds for worldwide standards (where
IETF, W3C, ITU are prominent).
Standard setting requires expertise in technical
areas. There is a limited supply of technical experts and they
are spread thinly. The recently launched Institute of Information
Security Professionals will help in raising the standing of the
profession and should attract more engineers to specialise in
it in the medium-term. The low levels of engineering postgraduates
is an ongoing issue that has been taxing UK educationalists for
a number of years and there are no easy solutions to this problem.
Schemes such as the Common Criteria and Claims
Tested Mark provide some level of standardisation, however both
schemes have problems. The Common Criteria takes time to test
a product and is relatively costly. The Claims Tested Mark costs
less and the process takes only weeks to complete but it only
tests the claims of the manufacturer or provider of the service.
In both cases, the mark awarded lasts for a number of years during
which time products are updated and claims become outdated. The
results are therefore a snapshot of the security at a given time
and, more importantly, in isolation. Product assurance is a positive
move in improving online security, however it is only effective
if used appropriately.
SECTION 4: CRIME
PREVENTION
14. How effective is Government crime prevention
policy in this area? Are enforcement agencies adequately equipped
to tackle these threats?
Much of the Government's crime prevention activity
in this area is delivered through Get Safe Online, as detailed
above. However, there are a number of other activities, including:
the ITSafe website[15]
funded by the Home Office and the Cabinet Office provides home
users and small businesses with alerts and advice drawn from NISCC[16]
and a number of other sources on protecting computers, mobile
phones and other devices from malicious attack;
a number of local police forces provide
advice on their websites;[17]
the DTI provides advice to small
businesses through its website[18]
and through business link service.[19]
Responding to the majority of crime relating
to breaches of personal Internet security falls to local police
forces. The total funding available to forces continues to rise
and decisions on how to allocate those resources rest with Chief
Constables. Since 2002, every police force in England and Wales
has had its own computer crime unit of properly trained and equipped
staff. These units have grown significantly in size over that
period and the Home Office issued good practice guidance for managing
them in 2004.
In addition, the Serious Organised Crime Agency
(SOCA) has e-crime and fraud (including online fraud) among its
priorities. SOCA is an intelligence-led agency with law enforcement
powers, created to reduce the harm caused by organised crime to
the UK. It was formed in April from a number of agencies, including
the National Crime Squad and within that the National High Tech
Crime Unit. SOCA has an e-crime directorate responsible for minimising
the harm to the UK caused by e-crime and criminals' use of technology.
National and international co-operation is also
a key element of the response to the threats. Police forces, HM
Revenue and Customs and other agencies have interests in this
area, and the various law enforcement interests are brought together
in the National e-crime Strategy Group. SOCA is building on its
inherited activities to develop a range of bilateral and multilateral
partnerships with domestic and overseas law enforcement agencies
to extend the reach of UK law enforcement's response to e-crime.
15. Is the legislative framework in UK criminal
law adequate to meet the challenge of cyber-crime?
The Government is committed to ensuring that
actions should be legal or illegal according to their merits,
rather than the medium used, ie what is illegal offline should
be illegal online and vice versa. As such, all legislation criminalises
offences regardless of the means used to commit the offence.
Where there is a need to revise legislation
to take account of new criminal techniques we seek to do so. We
liaise regularly with the prosecution and law enforcement authorities
to ensure the criminal law remains fit for purpose, but are not
aware of significant legislative gaps that hinder the agencies.
For example, although the law relating to e-crime
is generally fit for purpose, we have recently put before Parliament
changes to the Computer Misuse Act 1990 to strengthen it. The
changes will:
Broaden the definition of the section
3 offence to clarify that that all means of interference with
a computer system are criminalisedin particular ensuring
that adequate provision is made to criminalise all forms of denial
of service (DoS) attacks.
Increase the maximum penalty for
the section 1 offence of unauthorised access to computer material
to two years to better reflect the seriousness of these offences
as more and more sensitive systems and information have external
connections and also ensure that the offence is extraditable.
We are similarly proposing to increase the maximum penalty for
the section 3 offence of unauthorised modification of computer
material to 10 years.
Create a new offence of making, adapting
or supplying articles for use in computer misuse offences to discourage
the market in the production and distribution of hacking tools
(devices which can be utilised in the subsequent commission of
offences of illegal access and systems and data interference).
The new offence will allow us to will give effect to Article 6
of the Cybercrime Convention.
Another example is the Fraud Bill. It will create
a general offence of fraud (rather than focusing on specific acts
as previous fraud statutes have done and deals with them in a
technology neutral way), with three different ways of committing
ita person will be guilty of the general offence if he
is dishonest and either:
1. makes a false representation (including
a false representation to a machine); or
2. fails to disclose information; or
3. abuses a position of trust.
This will cover the full variety of fraudulent
behaviour and should ensure that the offence continues to be relevant
as methods of crime and technology change and develop. The bill
also brings forward other new offences which will assist in combating
e-crimethese include:
1. an offence of obtaining services dishonestlythis
will plug a legal loophole whereby, for example, fraudsters obtain
services over the Internet, but are not subject to the current
law of fraud as they have not deceived a person;
2. various offences of possessing, manufacturing
or supplying equipment, such as a computer programme that can
generate genuine credit card numbers, to be used to commit or
facilitate fraud.
16. How effectively does the UK participate
in international actions on cyber-crime?
The UK is an active international player in
relation to e-crime, both operationally and strategically.
UK law enforcement has strong links with operational
colleagues overseas bilaterally, as well as through Europol, Interpol
and the G8 contact network. International activity has tended
to be focused through the National High Tech Crime Unit (now SOCA
e-crime) and the Metropolitan Police Service and there are regular
examples of successful investigations where UK law enforcement
has been assisted by overseas colleagues or vice versa.
At the political level, the UK is actively involved
in setting the agenda on e-crime in various fora within Europe,
the G8 and the Commonwealth and elsewhere. For example, the UK
has been a driving in helping develop a common global approach
to e-crime legislation through the Council of Europe Cybercrime
Convention and placed e-crime high on its JHA agenda during last
year's presidencies of the EU and the G8.
1 www.getsafeonline.org/media/GSO_Cyber_Report_2006.pdf Back
2
www.homeoffice.gov.uk/rds/pdfs06/rdsolr0906.pdf Back
3
http://www.oft.gov.uk/news/press+releases/2006/81-06.htm Back
4
www.getsafeonline.org Back
5
Phishing a type of fraud that tricks users into visiting malicious
websites, typically through "spoofed" emails from well
known banks, online retailers and credit card companies. Ofcom
Online Protection Report June 2006. Back
6
www.getsafeonline.org/media/GSO_Cyber_Report_2006.pdf Back
7
http://www.ktnetworks.co.uk/epicentric_portal/site/cys/ Back
8
http://www.dti.gov.uk/innovation/tech-priorities-uk/tsb/index.html Back
9
The human-machine interface (HMI) is where people and technology
meet. This people-technology intercept can be as simple as the
grip on a hand tool or as complex as the flight deck of a jumbo
jet (definition used by International Engineering Consortium). Back
10
http://www.foresight.gov.uk/previous_projects/cyber_trust_and_crime_prevention/index.html Back
11
For example, many home users have antivirus software and firewalls,
which limit the chances of malware being downloaded accidentally,
so increasingly phishing attacks are taking the form of directing
users to websites via embedded hyperlinks. Back
12
Risk management is simply a practice of systematically selecting
cost effective approaches for minimising the effect of threat
realisation to the organisation. Dorfman, Mark S (1997). Introduction
to Risk Management and Insurance (6th ed) Prentice Hall. Back
13
http://www.instisp.org/ Back
14
www.ofcom.org.uk/research/technology/onlineprotection/ Page 4,
paragraph 1.7. Back
15
www.itsafe.gov.uk Back
16
www.niscc.gov.uk Back
17
eg: www.met.police.uk/crimeprevention/computer, www.sussex.police.uk/comp_crime/comp_crime Back
18
www.dti.gov.uk/sectors/infosec/ Back
19
www.businesslink.gov.uk Back
|