Security hike likely after computer crash
Government is looking at introducing international computer standards to prevent another crash like the one which wiped out half of the Trademark Registry.revealed on Saturday that a computer crash ? and the failure of a back-up file ? resulted in the loss of half the 37,000 trademarks on the Registry.
Staff at the Registrar General?s office have had to go back to paper files and manually input all information since 1999, which has resulted in the registry being out of operation for about a month.
The embarrassing crash has meant lawyers who register trademarks have been unable to search the register.
Government?s E-commerce consultant Nigel Hickson said yesterday that the Information Technology Office (ITO) is preparing a report for the Information Technology Secretariat ? which reports to Telecommunications Minister Renee Webb ? on improving computer security.
One standard that may be introduced is the International Standards Organisation 17799.
This will spell out how often back-up checks should be made on information as well as getting access to them.
Separately, Bermuda security company QuoVadis has prepared a report on Government?s e-commerce portal which recommends introducing strict checks and standards for computers similar to those used by the US federal government.
The US standards will be for Government?s e-portal ? where members of the public can inter-act with Government departments ? but the security recommendations could apply to all Government computers.
Mr. Hickson told yesterday said the new standards being considered were not a reaction to this month?s crash of the Trademark Registry, and that the ITO office had been asked several months ago to come up with new standards.
?Clearly, it is a significant disappointment as the Registrar General said in the newspaper on Saturday,? he said. ?It is just lucky that we were able to work so closely with the business community to help get it back together again.
?It is disappointing and we need to ensure we have appropriate standards in place in the future to try to ensure that what happened doesn?t happen again. But no system is foolproof.
?Back-up is done on a regular basis, but it probably wasn?t monitored in the way it could have been (at the Trademark Registry) and if we have standards we can make sure they are adhered to.?
QuoVadis vice president Stephen Davidson said yesterday: ?As part of the new Portal project, the Government retained QuoVadis to advise on a security action plan ? similar to America?s FISMA of the UK?s BS 7799 ? to increase the effectiveness of IT security across Government?s many computer systems.
?If implemented, the plan will clearly document the acceptable standards for security and availability for all Government systems ? whether operated centrally, by departments, or by third parties. It will encourage a focus on security from the planning stages of a system right through its operational life with ongoing monitoring and periodic reviews to ensure security is functioning as planned.
?Among other things, this should require that every system has a tested continuity plan for backup and recovery, as well as a change management process to verify that modifications don?t have unexpected consequences.
?Every system should have a security plan that lays out a schedule of critical security events such as those times of the year when they verify the back-up is working.
?We suggest that our customers test monthly, and the US Government standard is that they have got to be certified annually. The certification is much more than a back-up check.?
He noted that Government may have greater challenges than many companies because it uses a variety of technologies.
