UK Cyber Security Strategy is worse than useless?
The Labour Government has now published, without bothering to consult the general public, its first public UK Cyber Security Strategy …
Some obvious Spy Blog questions:
Does either the Office of Cyber Security or the Cyber Security Operations Centre
- have an elected Cabinet Minister directly responsible for it, and democratically accountable for its failures (or, in theory, responsible for its successes) ?
- have even a junior elected Minister directly responsible for it, and democratically accountable for its failures (or, in theory, responsible for its successes) ?
- have even a senior Civil Servant of Permanent Secretary rank directly responsible for it, and professionally accountable for its failures (or, in theory, responsible for its successes) ?
- have any independent budget to spend on Cyber Security ? If so, then how much ?
- replace any of the other existing bureaucratic agencies, offices, departments, quangos, non-departmental government bodies etc, ?
- have any planned strong statutory legal enforcement powers i.e. criminal prosecutions with fines and or prison sentences ?
- have any planned weak statutory legal enforcement powers e.g. like the Information Commissioner ?
- have the power to cancel or amend Government IT projects and IT contracts if they are fail the Cyber Security standards ?
- have the power to cancel or amend Government IT projects and IT contracts if they fail the Privacy and Liberty Proportionality criteria ?
- be easily and securely contactable by the general public via secure SSL/ TLS encrypted web response forms, or PGP encrypted emails or by (freephone) telephone ?
- be easily and securely contactable by the people who look after Critical National Infrastructure systems via secure SSL/ TLS encrypted web response forms, or PGP encrypted emails or by (freephone) telephone ?
- be easily and securely contactable by the general public or by Critical National Infrastructure people, most of whom work in the private sector, 24hours a day, 7days a week, including holidays ?
If, as we suspect, the answers to most of these questions is “no”, then this UK Cyber Security Strategy is worse than useless, and is just some more Must Be Seen To Be Doing Something political propaganda.
Source: Spy Blog


