ATO admits staff have lost data, sent porn e-mails

The Australian Tax Office CIO Bill Gibson admits that staff have leaked information, lost CDs and been fired for sending porn by e-mail.

The security culture at the Australian Tax Office has generally been given the thumbs up in a review by PriceWaterhouseCoopers, released today (pdf) — but the organisation discovered serious holes in the ATO's security practices.

Roughly 60 percent of the ATO's 22,000 staff took part in a survey, which reviewed the ATO's security practices, technologies and policies, which CIO Bill Gibson said was inspired by fears that it could face a breach similar to the UK's HMRC, which affected 25 million citizens.

"In October 2007, in the UK, there was the loss of password protected CDs by the HMRC that contained a lot of sensitive information about citizens in the UK. There were a number of other incidents which heightened our sensitivity to ensuring that we are appropriately safeguarding the information we hold," Gibson told ZDNet.com.au in a telephone interview today.

Read This:

Video interview

Bill Gibson, CIO of the Australian Tax office, spoke to ZDNet.com.au about why he doesn't completely trust open source software; how the ATO handles security and why competing vendors will have to learn to work together.
Read More »

Those other incidents included one staff member losing a briefcase containing "some taxpayer information on two individuals" as well as a lost disc, said Gibson.

"[The briefcase] had been stolen from within a hotel. We have procedures that we activate if any information is compromised ... It's unfortunate that these things happen.

"The other event, which drove home to us the need to be comfortable in how we're dealing with these things was a disc misplaced in one of our offices," said Gibson.

The disc, which Gibson said was subsequently "found and handed back in", contained "some information about taxpayers".

The review found potentially serious holes in the way information is handled when shared between contractors and other government departments, which included "classified information" being transferred using "low grade encryption".

Some ATO staff also lacked knowledge of approved secure transfer channels, the study revealed.

"The area that we have more of a concern about are those things that are associated with ad hoc data transfers. For example, a request from an agency to access information," he said.

These transfers are usually governed by an official agreement between the agencies, which stipulates how each party should handle sensitive information.

The review found that information was handed to outsiders without any assurance it would be adequately protected.

"We're looking closely at the agreements we have with those agencies," Gibson said. "We clearly need to enhance our education and awareness program".

To better deal with data transfers between agencies, the ATO has introduced fingerprint reading USB drives, which keep the information encrypted until properly authenticated.

"If there is a need for us to physically take information to another entity, we will only do so on one of these USB keys. The key can be unlocked through the use of finger or thumbprint — otherwise it's rendered unusable," he said.

The review also highlighted problems with staff circumventing the e-mail marking classifications being sent from government organisations, which were designed to prevent data leakage.

The review found staff would choose to tag classification levels based on convenience rather than policy — with over-classification of hard copy information to restrict access, and in other cases, under-classification to simplify transfers to other locations.

"We're now doing 100 percent scans that involve all outbound e-mail traffic from the ATO and we have some sophisticated automation that detects what is information that is inappropriately classified.

"That might be pornographic or other materials. We have strong policies that do not condone this in any way. We have in the past had examples where staff have breached these guidelines — more around social acceptability — that we will class as a code of conduct issue, which can result in a range of sanctions and we have dismissed staff on that basis," added Gibson.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

First off, Bitcoin is not a virus. Second off, the only way to generate Bitcoins, is by using a Bitcoin miner. More information on this h...

4 minutes ago by rizowski on ABC's Bitcoin miner tackled in minutes

Vic councils tender for VMware partner - ZDNet Australia: Vic councils tender for VMware partnerZDNet Australia#... http://t.co/V9rukN7Q

Cybercrime golden age over in two years?
http://t.co/qdeIhHXP #techwd #Tech_ar #reversing

US, Australia team up on #cybersecurity http://t.co/AKDgHpmB

Microsoft's So.cl network launched amid Facebook press http://t.co/MkUizROL

Students create "v'ideo parties" with MSFT new social service http://t.co/uH9ffvLa

RT @zdnetaustralia: Melbourne City Council pulls parking fine cameras. Turns out Melbournites park too close together: http://t.co/pqbJbeJy

Vic councils tender for VMware partner - ZDNet Australia http://t.co/eTTZFXVG #australia #technews

@Microsoft So.cl combines search and social media, designed to aid students networking and sharing information ZDNet http://t.co/zQW8Zecr

Google's Chrome vs. Microsoft's IE: How's that halo effect? http://t.co/xz2YGQMU

When an operating system is sold it should not launch until an approved security service is purchased online with a list of approved supp...

46 minutes ago by Kevin Cobley on National Botnet Network coming: Earthwave

Windows Phone: Photography the key to its success? http://t.co/14swIy1J

National Botnet Network coming: Earthwave http://t.co/BsCUwtGW via @zdnetaustralia

Windows Phone: Photography the key to its success? http://t.co/CBVdS9f7

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

Windows Phone: Photography the key to its success?: I tend to do a bit of digital photography when I go on trips... http://t.co/lAYofzgi

CASE STUDY: using #msdyncrm to cope with growing number of client comms http://t.co/qA1SxZLO #personalinjury #legaluk #solicitors #lawyers

Windows Phone: Photography the key to its success? - ZDNet (blog): ZDNet (blog)Windows Phone: Photography the ke... http://t.co/HPArdCe0

One of Windows Server 2012's secret weapons: Hyper-V Replica http://t.co/F8nJ7xK6

“@ZDNet: One of Windows Server 2012's secret weapons: Hyper-V Replica http://t.co/oAE1ifmp”....a DR solution, that is for the little guys.

TechnologyOne keeps profits growing: http://t.co/A7J5uDlT

“@btviewpoint: #Cybercrime golden age over in two years? - #Security - #News - http://t.co/ZEmny2dI

“@ZDNet: Can Windows 8 tablet be priced low enough to compete with iPad, Kindle Fire? http://t.co/b7n4Wb7C” .....unlikely, and disappointing

#Cybercrime golden age over in two years? - #Security - #News - http://t.co/Mvc37WAr

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

United States, Australia team up on cybersecurity http://t.co/41IYTcDx

$50m to Medicare locals for eHealth http://t.co/VM5ts5lf

RT @adrianbritton: Goodbye Friending #Facebook: We only part to meet again http://t.co/gXZEKtEE #socialmedia

RT @stilgherrian: RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

Microsoft admits Vista was 'cheesy' http://t.co/Yd6fSLyx

We Are Specialty Supply Miu Miu Handbags, Miu Miu Pocketbook, Miu Miu Sunglasses And So On. Miu Miu Car-boot sale Online Strapping Reduct...

4 hours ago by ExedegamEmodo on Reservoir blogs: Fan fakes Tarantino diary

RT @stilgherrian: RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

RT @stilgherrian: RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

4 hours ago by forporoExpoxy on Reservoir blogs: Fan fakes Tarantino diary

Goods Shopping Location Diminish Of Japan's Largest Overseas Train Brands. Coach Outlet Recover 89% Off.We Entertain Stuffed Items Such A...

4 hours ago by MentIdott on Reservoir blogs: Fan fakes Tarantino diary

Our Stow away Tender Exercise Bags Of The Cheapest Quotation, 50-75% OFF. Secured Shipping To Japan. Detailed Inferior Instructor Handbag...

4 hours ago by Hieffiftsoinc on Reservoir blogs: Fan fakes Tarantino diary

http://t.co/gNQkl0gd

1963年ナイキの創業者フィル・ナイトが訪日、オニツカ(現アシックス)の経営陣を訪問。 最新の機...

4 hours ago by Scafthapthinc on Reservoir blogs: Fan fakes Tarantino diary

4 hours ago by antaftilk on Reservoir blogs: Fan fakes Tarantino diary

Our Aggregate Wholesale Trainer Bags Of The Cheapest Consequence, 50-75% OFF. Self-indulgent Shipping To Japan. Exquisite Worthless Drill...

5 hours ago by meltygypent on Reservoir blogs: Fan fakes Tarantino diary

Celine belongings,Celine case,purse Celine,CELINE Celine is synonymous with je sais quoi and faultlessness prevalent since founding in 19...

5 hours ago by dendyBymNTedo on Reservoir blogs: Fan fakes Tarantino diary

Global mobile phone sales take a hit; Nokia yields to Apple, Samsung http://t.co/95pDxClp

5 hours ago by Fedaupdat on Reservoir blogs: Fan fakes Tarantino diary

Global mobile phone sales take a hit; Nokia yields to Apple, Samsung - ZDNet (blog): Global mobile phone sales t... http://t.co/GtLqWFz1

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

6 hours ago by anonymuos on Microsoft admits Vista was 'cheesy'

Gotta agree. For our Burnie, Tas. internet, we have a 1.5MB download speed adls connection through exetel using testra copper line. ADS...

6 hours ago by brozza on Broadband Speedtest

Well the message certainly is clear. Never do anything because something might happen. Seriously it seems to me "Earthwave" just want to...

8 hours ago by Hubert Cumberdale on National Botnet Network coming: Earthwave

you really think it's going to be such a grim future? looking at South Korea, Japan, even Czech Republic - I haven't seen either emit mo...

10 hours ago by romant on National Botnet Network coming: Earthwave

No... they'll just blame the NBN for that too ;-)

10 hours ago by Beta on National Botnet Network coming: Earthwave

It seems that some of the people who set up ACCAN (not staff members) took the view that it would somehow be against their view of 'consu...

11 hours ago by socrates on ACCAN gets govt tick amid industry criticism

Don't laugh, Mr Turnbull is dumb enough to try and use this against the NBN. I'm sure the noallitions magical FTTN will be impervious to ...

11 hours ago by Jingles on National Botnet Network coming: Earthwave

OMG, the sky will fall if we get NBN - it must be cancelled immediately! Sorry; was just channelling Malcolm Turnbull there for a moment...

11 hours ago by socrates on National Botnet Network coming: Earthwave

Thats just stupid.. what else is the NBN going to get blamed for? People die crossing the road, are you going to ban cars or police it b...

12 hours ago by fibretech on National Botnet Network coming: Earthwave

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar