EC's Reding: Europe needs a 'Mr. Cyber Security'

By Scott M. Fulton, III | Published April 27, 2009, 4:22 PM

After an apparent victory in her efforts to prevent the UK from establishing a central database for private citizen communications, European Commissioner for Information Society and Media Viviane Reding said she wants her government to create a post for a point-man for the continent's cybersecurity.

"Although the EU has created an agency for network and information security, called ENISA, this instrument remains mainly limited to being a platform to exchange information and is not, in the short term, going to become the European headquarters of defense against cyber attacks. I am not happy with that," stated Comm. Reding (PDF available here). "I believe Europe must do more for the security of its communication networks. Europe needs a 'Mister Cyber Security' as we have a 'Mister Foreign Affairs,' a security tsar with authority to act immediately if a cyber attack is underway, a Cyber Cop in charge of the coordination of our forces and of developing tactical plans to improve our level of resilience. I will keep fighting for this function to be established as soon as possible."

The news comes as Reding meets with other government leaders in Estonia this week, to debate not only a pan-European policy for Internet security, but also the broader topic -- one that's near and dear to her heart -- of the establishment of some form of Internet governance, a topic she'll have more to speak about next week.

In the meantime, the UK Home Office decided this morning to back down from its plans to establish a central database for logging communications between private citizens -- a database which would have been contributed to by the country's Internet service providers. This after the EC issued a formal warning to the British government last week that it could go so far as to take it to court in Brussels, to protect against the possibility of any individual misusing such a database for unauthorized purposes.

In a communiqué issued this morning by the British Home Office (PDF available here), Home Secretary Jacqui Smith essentially echoed some of the language of Comm. Reding's earlier statement: "For the police, the security and intelligence agencies, and other public authorities like the emergency services, being able to use the details about a communication -- not its content, but when, how and to whom it was made -- can make all the difference in their work to protect the public," states Sec. Smith. "It is no exaggeration to say that information gathered in this way can mean the difference between life and death. However, rapid technological changes in the communications industry could have a profound effect on the use of communications data for these and other purposes. The capability and protection we have come to expect could be undermined."

UK Security and Counter-terrorism Minister Vernon Coaker (L - Gedling) had suggested that the creation of a database was necessary in order to comply with an EU directive mandating that personally identifiable information be kept on hand for 12 months. Some saw that as a way of sneaking in new government oversight, while passing the blame onto a higher authority. Although this morning's communiqué cited the European Convention on Human Rights, Article 8(1) ("Everyone has the right to respect for his private and family life, his home and his correspondence"), it then went on to say that the government ensures that the content of private communication may only be accessed by authorities under certain emergency circumstances.

Amid those circumstances, it listed maintaining the economic well-being of the UK in such instances where national security may be jeopardized, and assessing whether taxes are owed by an individual. Still, it maintains that safeguards are in place to determine whether such cases mandate privacy invasion; and when they do, only a certain specially trained team of elite investigators are allowed to dive into private communications -- a team that sounds like something out of a Jerry Bruckheimer series, and that uses an acronym that must have been unavoidably tempting.

"The single point of contact system (SPoC), extended beyond police to all relevant public authorities following the enactment of RIPA, created trained and accredited experts in each public authority who understand how to interpret the information that is held by communications service providers," reads the communiqué. "This group, trained partially by industry to know what data is available to support investigations, helps to ensure effective working relationships between investigators and companies."

Already, the UK government has a kind of "tsar" in place to serve as the single point of contact, if you will, in cases where the government's authority may be under dispute, says the communiqué. This is the Interception of Communications Commissioner, who by law must have served as a judge. However, if a citizen feels her or his private data has been abused by authorities, he may seek redress before the Investigatory Powers Tribunal.

The Tribunal's own Web site describes itself this way: "The Tribunal can investigate complaints about any alleged conduct by or on behalf of the Intelligence Services -- Security Service (sometimes called MI5), the Secret Intelligence Service (sometimes called MI6) and GCHQ (Government Communications Headquarters). Because the Tribunal is the only appropriate place you can complain about the Intelligence Services, the scope of conduct it can investigate concerning them, is much broader than it is with regard to the other organizations under its jurisdiction."

Comments

View comments by with a score of at least

I have a better idea, intstead of actually appointing someone a post "Mister Cyber Security" and wasting even more time and goverment funds, why dont the governments/organisations not put any sensitive information online in the first place. Then there would be no need to throw acusations or hold anyone responsible if something does go wrong.

If something does go wrong like the leaking or hacking of a personal database online then the companies should then be held liable, not the ones who are messing about typing random exploits they have just found on a security forum into their own personal computer's.

Score: 0

|

perhaps, that european country that produced the "governator" can also produce a "cybernator" or an "internator".

maybe we will "haave-tu" "be-back" and "re-vizit" this "ee-shoo"

Score: -1

|

Is this where Obama's getting his idea's from? Sounds like another step closer to Communism. Might not be a bad thing.... I just want to know when I can stop working so I can make the same as everyone else who is working......

Score: 0

|

That depends. Are you a wealthy Democrat politician or a militant homosexual? Or an illegal alien? In any of those instances, you're set for life. Otherwise, not so much.

Score: 1

|

What does AT&T's 'Mark the Spot' app say about service quality?

That's a question for Betanews readers to answer in comments to this post.

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.

Google rolls out real-time search, Near Me Now, extended personalization

Over time, searches from PCs and mobile phones will grow even "more personalized." But what about user privacy and search results that give you "the truth"?

Intel's marriage of CPU and GPU not ready for prime time

Although there will be an Intel component this month that can compute and plot in parallel, Betanews was told today, it won't be based on Project "Larrabee."

Betanews Podcast: Rupert Murdoch and the buying stuff online problem

We'll have a more difficult time paying for online news if the underlying protocol for online payment has a big gaping hole in it.

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.

Google Goggles: Hands on with the Shazam of the Real World

Google today unveiled Goggles, its visual search lab for Android devices that identifies objects by sight.

Microsoft: Windows 7 Family Pack wasn't 'pulled,' it just sold out

If you hurry, you may still be able to find the last Family Pack upgrade editions hanging around retail store shelves, but probably not so much online.

Clever iPhone game returns after being bumped over a name dispute

The game's simple concept and multitude of platforms and puzzles manage to pull off a retro, 8-bit style that's reminiscent of an old Atari game given a modern makeover.

An alternative to Research in Motion's enterprise e-mail? There's an app for that

Good Technology today released an iPhone app compatible with its enterprise e-mail solution.

Playing catch-up in 2010: Windows Mobile, BlackBerry, and Symbian

Microsoft, RIM, and Nokia are each working on improved mobile operating systems. But could these efforts add up to too little, too late?