I mentioned vetting in my previous post and I'd like to expand on the vetting of staff, contractors and temporary workers.
I have been through some pretty heavy vetting. I'm glad to say I passed but not without a warning or two - a sign of a mis-spent youth. The vetting process was quite in-depth and included background checks, reference interviews and a face-to-face interview.
During my vetting, I was completely honest and advised my references to be just as honest. I have encountered some managers advising their staff to be less so, particularly in certain areas. This was especially apparent when working in the private sector, providing services to HMG. If consultants did not pass their vetting, they were unable to work on ANY projects for HMG therefore the pressure to pass the checks was quite high. Don't get me wrong, I don't think the people that were lying were any higher risk to security than those that didn't, if I did, I would have spoken up but the vetting scheme requires complete honesty in order that you don't leave yourself open for blackmail, those that lie have this vulnerability.
Why do they lie? It is apparent that, depending on the area you are being vetted for, the tolerance levels for certain behaviours is higher, or lower, than others. Some areas would have no tolerance for alcohol abuse where others may take a softer approach. Some areas my be more tolerant of a past instance of employee theft where others may not.
What does this mean? To put it succinctly, there are a number of people working for HMG either directly or via contract, that hold high levels of clearance, that are (slightly) vulnerable to blackmail.
I am acutely aware that those that are likely to disclose information would also lie to protect themselves and to achieve clearance and it is obvious, at least in my experience, that the vetting staff are not trained to spot obvious body language tells that would indicate a less honest answer.
The alternatives are unpaletable. I understand anecdotally that in the US, vetting is accompanied by a lie detector test. I do not believe that would be acceptable in the UK and would certainly be rejected by many. I am also aware that it is possible to be trained to defeat the lie detector just as easily as one can be trained not to provide body language tells. If we were to rely on further reference interviews, the costs would soon increase - vetting is not a cheap process and I'm sure the vetting agencies are under pressure to keep costs down and if one reference will lie for you, I'm sure many others would also.
The bottom line is that many potentially good candidates are put off by the draconian requirements for vetting and some previous behaviour will preclude a candidate from attaining the highest level of clearance where other candidates who are prepared to lie are achieving clearance, leaving them open to blackmail. I elieve the system is broken and there is no easy fix.
Showing posts with label vetting. Show all posts
Showing posts with label vetting. Show all posts
Wednesday, 3 August 2011
Sunday, 10 July 2011
A new approach...
It's been a good while since my last post. I've started a new job, for the first time in a long time, I'm in the private sector and I've been dedicating my efforts into getting up to speed and changing my mindset to address the security issues for an entirely new way of thinking and working.
I've still got plenty to comment on concerning the state of information security within the public sector and the controlling bodies, more of that to come....
Back to my new role. The company I'm now working for are investigating the possibility of utilising cloud resources. Coming from the environment that I have, my immediate reaction was to balk at the prospect but, following the practices I have learnt over the years, applied a suitable risk calculation to the whole idea and it all boils down to whether you feel you can trust your cloud service provider. The benefits are immense - we are considering outsourcing our email to a cloud service which dramatically reduces the cost of the current clustered Microsoft Exchange environment and increases the availability over what is currently achieved via the in-house solution. The ability to scale up (or down) at very short notice delivers considerably more flexibility than is currently possible.
Granted, there are additional requirements on the company to ensure confidentiality of information. For cloud services, it will be imperative to implement two factor authentication, along with all the headaches and potential pitfalls (Re: RSA) that they come with.
The move to cloud services is now primarily seen as a change management project. User acceptance or more likely, the loss of Microsoft Outlook may not be as high as could be hoped and managing the perceived loss will be a primary consideration.
As I alluded to before, the issue of trust of a service provider is the stumbling block. As we meet the various service provides concerned, they become familiar and a trust relationship is built. We want to trust them and naturally, they want us to trust them. Alongside the new-found trust we have developed, is an implied trust of ALL the employees of those companies. Some of the companies we are engaged with have an employee vetting scheme. I have been the subject of vetting and I'm not impressed. Vetting is hugely effective at weeding out potential employees who have been caught misbehaving but fails dramatically when attempting to identify the luckier, or more efficient, dishonest employee. The issue of trust must be an informed decision and ultimately, it falls upon the business to make the final decision, my responsibility stops at providing full information to the board so that the decision may be an informed one.
I've still got plenty to comment on concerning the state of information security within the public sector and the controlling bodies, more of that to come....
Back to my new role. The company I'm now working for are investigating the possibility of utilising cloud resources. Coming from the environment that I have, my immediate reaction was to balk at the prospect but, following the practices I have learnt over the years, applied a suitable risk calculation to the whole idea and it all boils down to whether you feel you can trust your cloud service provider. The benefits are immense - we are considering outsourcing our email to a cloud service which dramatically reduces the cost of the current clustered Microsoft Exchange environment and increases the availability over what is currently achieved via the in-house solution. The ability to scale up (or down) at very short notice delivers considerably more flexibility than is currently possible.
Granted, there are additional requirements on the company to ensure confidentiality of information. For cloud services, it will be imperative to implement two factor authentication, along with all the headaches and potential pitfalls (Re: RSA) that they come with.
The move to cloud services is now primarily seen as a change management project. User acceptance or more likely, the loss of Microsoft Outlook may not be as high as could be hoped and managing the perceived loss will be a primary consideration.
As I alluded to before, the issue of trust of a service provider is the stumbling block. As we meet the various service provides concerned, they become familiar and a trust relationship is built. We want to trust them and naturally, they want us to trust them. Alongside the new-found trust we have developed, is an implied trust of ALL the employees of those companies. Some of the companies we are engaged with have an employee vetting scheme. I have been the subject of vetting and I'm not impressed. Vetting is hugely effective at weeding out potential employees who have been caught misbehaving but fails dramatically when attempting to identify the luckier, or more efficient, dishonest employee. The issue of trust must be an informed decision and ultimately, it falls upon the business to make the final decision, my responsibility stops at providing full information to the board so that the decision may be an informed one.
Tuesday, 15 February 2011
£63 million for the police to fight Cybercrime
So, the police are going be allocated £63 million from the £650 million made available to 'beef up' Britains cyber defences.
My question is: Is this an appropriate organisation to be tasked with this role? I suspect it is not. Now the money has fallen into the police budget, it will offset other spending cuts applied by the government austerity measures. In short, those police personnel that would have been made redundant may now find themselves assigned to cyber defence work, whether they are suitable or not.
I believe the full £650 million should have been assigned to a new organisation tasked with cyber security, with the sole purpose of blocking cyber attacks and, wherever possible, identification and prosecution of offenders. With the police having the funding assigned to them, there is an imperative to retain and retrain staff for the role rather than employing suitably trained and experienced personnel who are ready to commence the tasks required.
A full UK Cyber Defence Organisation could be provided with the authority and access to identify those organisations that are actively being exploited with a view to contacting them directly and perhaps even offering a commercial service to allow said organisations to employ them to secure their systems against such further attacks.
Naturally, such an organisation would require an unprecedented level of access to Internet traffic and there would be immediate privacy concerns over what is viewed by them but surely, it would be better for this to be in the hands of an independent service rather than the police who will have other issues to deal with and might want to leverage the access afforded to facilitate additional investigations, drawing further resources away from the primary objective.
It's not an easy task and the levels of funding being suggested are appropriate to tackle the task at hand but in no way adequate to completely irradicate the threat - no level of funding could be.
I will watch closely how the remaining 90% of the £650 million will be distributed. I'm sure the MoD will be allocated a portion of the funding and the same issues will apply with regards to redeployment of staff, retraining and scope creep. I'm sure that CESG will receive a good dollop and, while I respect the ability of CESG and the issues of conflicting priorities will be lessened, there is the ever-present issue that CESG has an incredibly hard time retaining suitably cleared and experienced staff who, once they have attained the clearance and received the training that CESG provides, are tempted away to high-paying consultancy and contract positions, often returning to their previous job but costing CESG up to ten times as much. Many of the issues at CESG are down to their stringent vetting requirements but that is a post for another day!
My question is: Is this an appropriate organisation to be tasked with this role? I suspect it is not. Now the money has fallen into the police budget, it will offset other spending cuts applied by the government austerity measures. In short, those police personnel that would have been made redundant may now find themselves assigned to cyber defence work, whether they are suitable or not.
I believe the full £650 million should have been assigned to a new organisation tasked with cyber security, with the sole purpose of blocking cyber attacks and, wherever possible, identification and prosecution of offenders. With the police having the funding assigned to them, there is an imperative to retain and retrain staff for the role rather than employing suitably trained and experienced personnel who are ready to commence the tasks required.
A full UK Cyber Defence Organisation could be provided with the authority and access to identify those organisations that are actively being exploited with a view to contacting them directly and perhaps even offering a commercial service to allow said organisations to employ them to secure their systems against such further attacks.
Naturally, such an organisation would require an unprecedented level of access to Internet traffic and there would be immediate privacy concerns over what is viewed by them but surely, it would be better for this to be in the hands of an independent service rather than the police who will have other issues to deal with and might want to leverage the access afforded to facilitate additional investigations, drawing further resources away from the primary objective.
It's not an easy task and the levels of funding being suggested are appropriate to tackle the task at hand but in no way adequate to completely irradicate the threat - no level of funding could be.
I will watch closely how the remaining 90% of the £650 million will be distributed. I'm sure the MoD will be allocated a portion of the funding and the same issues will apply with regards to redeployment of staff, retraining and scope creep. I'm sure that CESG will receive a good dollop and, while I respect the ability of CESG and the issues of conflicting priorities will be lessened, there is the ever-present issue that CESG has an incredibly hard time retaining suitably cleared and experienced staff who, once they have attained the clearance and received the training that CESG provides, are tempted away to high-paying consultancy and contract positions, often returning to their previous job but costing CESG up to ten times as much. Many of the issues at CESG are down to their stringent vetting requirements but that is a post for another day!
Labels:
budget,
CESG,
exploit,
Information,
infosec,
internet,
MoD,
police,
security,
training,
vetting,
vulnerability
Subscribe to:
Posts (Atom)