13
1 Algemene Rekenkamer | Postbus 20015 | 2500 EA Den Haag Data security and positions with access to confidential information

1 Algemene Rekenkamer | Postbus 20015 | 2500 EA Den Haag Data security and positions with access to confidential information

Embed Size (px)

Citation preview

1

Algemene Rekenkamer | Postbus 20015 | 2500 EA Den Haag

Data security and positions with access to confidentialinformation

2

Agenda

• About the audit• Audit findings• Control space of E-Government:

• Report• Cases

Data security and positions with access to confidential information| February 18th 2013

3

About the audit

• Part of the 2011 audit into the state of central government accounts

• We performed audits at all the ministries and one departmental agency into Information Security ( IS):• Quality of data protection policy; • Protection of data systems.

• We examined Positions with access to Confidential Information at all the ministries. ( PCI)

• Audit start: October 2011• Audit publication: May 2012

Data security and positions with access to confidential information| February 18th 2013

4

Audit findings IS - Quality of data protection policy

• Most ministries and departmental agencies score badly in the following two respects:• It is not clear who is responsible for which data systems and

data chains.• No regular reviews of data protection policy have been

planned or performed.

Data security and positions with access to confidential information| February 18th 2013

5

Audit findings IS - Protection of data systems

• Poor scores in the two following areas in particular:• No clear picture of the security risks associated with data

systems;• The overall package of reliability requirements and security

measures is not reviewed at regular intervals.

Data security and positions with access to confidential information| February 18th 2013

6

7

Audit findings PCI - results

8

Control space of E-Government – The form

Data security and positions with access to confidential information| February 18th 2013

9

Control space of E-Government – Case IS: Quality of data protection policy

Data security and positions with access to confidential information| February 18th 2013

10

Control space of E-Government – Case PCI: Positions with access to confidential information

Data security and positions with access to confidential information| February 18th 2013

11

Control space of E-Government – Headline

Data security and positions with access to confidential information| February 18th 2013

12

Let’s see how this looks like….

Data security and positions with access to confidential information| February 18th 2013

13

Algemene Rekenkamer | Postbus 20015 | 2500 EA Den Haag

www.rekenkamer.nl

@rekenkamer

www.linkedin.com/company/algemene-rekenkamer