Overtis identifies security weaknesses in national children's database
Government warned by data security experts to tighten security on ContactPoint, the national children’s database before a serious breach occurs
...
"Why the government has created this security headache in the first place, particularly when their track record on data handling raises serious questions, is something of a mystery. Risk management would suggest a far safer approach is to only catalogue the details of children who have received services," said Richard Walters, Product Director, Overtis Systems. "Government spokespersons have stated that information from the database cannot be copied onto removable media but there has been no mention of endpoint security. The endpoint will almost inevitably turn out to be the weak link in the chain, with targeted malware a very real concern. Without comprehensive security at the endpoint, between the user and the data, it is relatively simple to copy data out of any application. In a Windows environment and with a little knowledge we’d even go so far as to say a child could do it".
Source:
Pro Security Zone
via:
Glyn Moody