Wednesday 28 November 2012

HMRC, Skyscape and a 2nd response from Phil Pavitt

G-Cloud, GDS, HMRC and Skyscape, the company with just one director, who owns all the shares – Whitehall SNAFU
Open letter to Lin Homer, Chief Executive, HMRC, asking about the wisdom of entrusting their data (our data) to the cloud with Skyscape Cloud Services Ltd.
Response from Phil Pavitt, Director General Change, Security and Information, HMRC, on behalf of Lin Homer.
Open letter to Phil Pavitt.
28 November 2012
Response dated 26 November 2012 from Phil Pavitt, please see below:

[Skyscape has subsequently changed its name to UKCloud: "London – August 1, 2016 – Skyscape Cloud Services Limited, the easy to adopt, easy to use and easy to leave assured cloud services company, has today renamed and relaunched as UKCloud Ltd (www.ukcloud.com), to reinforce the company’s exclusive focus on supporting the UK public sector in the digital transformation of services".]


HMRC and Skyscape Cloud Services Ltd

Dear Mr Moss

Thank you for your letter of 24 October 2012 expressing your concerns in respect of Skyscape Cloud Services Ltd suitability to host HMRC data. I apologise for the delay in responding to you.

Further to my reply of 22 October, I wanted to provide you with some more information to alleviate your concerns. I must reiterate our assurance that using Skyscape HMRC data will continue to be kept in accordance with existing legislation and HMRC security policies.

When fully operational, Skyscape Cloud Services Ltd will securely host all HMRC data currently held on office File and Print Servers (FAPS). FAPS support the work of many HMRC offices and hold data for a wide range business purposes e.g. administrative and customer related. FAPS do not hold the definitive tax records for the UK and these records remain distributed across a number of secure systems.

HMRC routinely risk assesses and tests the security of our solutions and services. Our secure connection to Skyscape will be delivered in line with HM Government standards to protect our data, with ongoing assurance checks throughout the life of this service.

As emphasised in my letter of 24 October, in order to deliver through G-Cloud, Skyscape were required to meet a set of mandatory criteria set out by Government Procurement Services (GPS) including financial standing and Experian risk assessments. Additionally, HMRC carried out its own standard taxation and financial compliance checks before awarding the contract and Skyscape passed the standards set by HMRC and Government.

All G Cloud contracts are let on a one year basis, with exit provisions agreed to transfer the data to a new supplier should this prove necessary.

Data security remains integral to HMRC and a pre-requisite of any of our data being migrated to Skyscape is for their solution, including all the constituent parts, to be formally accredited by CESG (the Communications-Electronics Security Group) to Impact Level 3 (IL3). All security aspects of the service will have to be proven in line with HM Government security standards. This will include the need to ensure the ‘cloud’ is hosted in a UK domiciled, secure data centre(s) and operated by staff with appropriate security clearance. We are also carrying out internal accreditations including Internal Risk Management and Accreditation Document Set (RMADS) and PSN risk assessments.

I trust that this answers your concerns and you are able to appreciate our decision to contract with Skyscape.

Yours sincerely

Regards

Phil Pavitt
HMRC Director General Change, Security and Information

HMRC, Skyscape and a 2nd response from Phil Pavitt

G-Cloud, GDS, HMRC and Skyscape, the company with just one director, who owns all the shares – Whitehall SNAFU
Open letter to Lin Homer, Chief Executive, HMRC, asking about the wisdom of entrusting their data (our data) to the cloud with Skyscape Cloud Services Ltd.
Response from Phil Pavitt, Director General Change, Security and Information, HMRC, on behalf of Lin Homer.
Open letter to Phil Pavitt.
28 November 2012
Response dated 26 November 2012 from Phil Pavitt, please see below:

[Skyscape has subsequently changed its name to UKCloud: "London – August 1, 2016 – Skyscape Cloud Services Limited, the easy to adopt, easy to use and easy to leave assured cloud services company, has today renamed and relaunched as UKCloud Ltd (www.ukcloud.com), to reinforce the company’s exclusive focus on supporting the UK public sector in the digital transformation of services".]


HMRC and Skyscape Cloud Services Ltd

Dear Mr Moss

Thank you for your letter of 24 October 2012 expressing your concerns in respect of Skyscape Cloud Services Ltd suitability to host HMRC data. I apologise for the delay in responding to you.

Further to my reply of 22 October, I wanted to provide you with some more information to alleviate your concerns. I must reiterate our assurance that using Skyscape HMRC data will continue to be kept in accordance with existing legislation and HMRC security policies.

When fully operational, Skyscape Cloud Services Ltd will securely host all HMRC data currently held on office File and Print Servers (FAPS). FAPS support the work of many HMRC offices and hold data for a wide range business purposes e.g. administrative and customer related. FAPS do not hold the definitive tax records for the UK and these records remain distributed across a number of secure systems.

HMRC routinely risk assesses and tests the security of our solutions and services. Our secure connection to Skyscape will be delivered in line with HM Government standards to protect our data, with ongoing assurance checks throughout the life of this service.

As emphasised in my letter of 24 October, in order to deliver through G-Cloud, Skyscape were required to meet a set of mandatory criteria set out by Government Procurement Services (GPS) including financial standing and Experian risk assessments. Additionally, HMRC carried out its own standard taxation and financial compliance checks before awarding the contract and Skyscape passed the standards set by HMRC and Government.

All G Cloud contracts are let on a one year basis, with exit provisions agreed to transfer the data to a new supplier should this prove necessary.

Data security remains integral to HMRC and a pre-requisite of any of our data being migrated to Skyscape is for their solution, including all the constituent parts, to be formally accredited by CESG (the Communications-Electronics Security Group) to Impact Level 3 (IL3). All security aspects of the service will have to be proven in line with HM Government security standards. This will include the need to ensure the ‘cloud’ is hosted in a UK domiciled, secure data centre(s) and operated by staff with appropriate security clearance. We are also carrying out internal accreditations including Internal Risk Management and Accreditation Document Set (RMADS) and PSN risk assessments.

I trust that this answers your concerns and you are able to appreciate our decision to contract with Skyscape.

Yours sincerely

Regards

Phil Pavitt
HMRC Director General Change, Security and Information

Monday 26 November 2012

HMRC soon to be Pavittless

Computer Weekly, 22 November 2012:
Phil Pavitt has stepped down as HMRC’s CIO to join insurance giant Aviva as global director of IT transformation ...

Under his role at Aviva Pavitt will be tasked with simplifying the firm’s IT services, and modernising and digitising its business.
DMossEsq readers have met Mr Pavitt a couple of times.

Back in May he forgot that the UK already has a Government Gateway and doesn't need GDS – the Government Digital Service – to develop a new one, even if they could.

More recently, he was deputed by Lin Homer, Chief Executive of HMRC, to explain why HMRC have decided to store all our tax records with a one-man company, Skyscape Cloud Services Ltd:
  • Let's hope he has time to explain this transformational decision to the public before he leaves HMRC.
  • And let's see if Aviva, in the name of "modernisation", will store all their insurance records in the cloud and instantly lose control of them.

HMRC soon to be Pavittless

Computer Weekly, 22 November 2012:
Phil Pavitt has stepped down as HMRC’s CIO to join insurance giant Aviva as global director of IT transformation ...

Under his role at Aviva Pavitt will be tasked with simplifying the firm’s IT services, and modernising and digitising its business.
DMossEsq readers have met Mr Pavitt a couple of times.

Identity assurance – one under the eight

On 13 November 2012 the Department for Work and pensions (DWP) announced the appointment of seven so-called "identity providers" for the new digital-by-default UK – the Post Office, Cassidian, Digidentity, Experian, Ingeus, Mydex, and Verizon.

We were previously led to believe that the announcement would be made on 22 October 2012. And before that we were supposed to have the news by 30 September 2012.

Publication slipped. And we still don't know who the eighth "identity provider" will be.

Two things we do know:
  • Whoever the eighth one is, there is clearly some reluctance somewhere, some friction. Maybe DWP aren't sure about the credentials of this eighth supplier. Maybe the eighth supplier isn't sure that it wants to be involved with IDAP, the government's tottering Identity Assurance Programme. Either way, they will start with their credibility impugned.
  • It's not really DWP doing the appointing. It's GDS, the Government Digital Service. GDS may be very good at designing websites. But what credentials, if any, do they have for identity assurance? The appointment is clearly giving them an embarrassing problem. More to the point, there are 21 million prospective claimants for Universal Credit in the UK. Identity assurance is meant to be operational by the Spring of 2013 for all 21 million of them. The chances of that happening are now nil. GDS's failure is extending the imprisonment in the poverty trap of millions of claimants who could be released by Universal Credit. Putting the wrong people in charge of identity assurance has miserable social consequences.

Identity assurance – one under the eight

On 13 November 2012 the Department for Work and pensions (DWP) announced the appointment of seven so-called "identity providers" for the new digital-by-default UK – the Post Office, Cassidian, Digidentity, Experian, Ingeus, Mydex, and Verizon.

We were previously led to believe that the announcement would be made on 22 October 2012. And before that we were supposed to have the news by 30 September 2012.

Publication slipped. And we still don't know who the eighth "identity provider" will be.

Two things we do know:

Thursday 22 November 2012

midata – nudging you into an interactive flashbased graph

There's so much wrong with midata, the Department for Business Innovation and Skills initiative to "empower" all us consumers, that you may forget the delightful loopiness of its proposed benefits:
If organisations try to share customer data with each other they invade individuals’ privacy and risk breaching the Data Protection Act. The result is duplication, waste and missed opportunities ...

Tallyzoo, a service dedicated to self monitoring, allows users to measure anything from their caffeine intake to the number of times they cut their grass. Users collect data using a mobile device or website program which creates interactive flashbased graphs enabling them to spot trends and patterns in their consumption habits, work, health and fitness goals. Data is manipulated so that users can share statistics and compare the end results ...

Access to such data represents a ‘holy grail’ data to companies because it explains why people do what they do and predicts what they are going to do next.
Silly old privacy laws. They just get in the way. They're synonymous with waste and duplication. They stand in the way of interactive flashbased  graphs of our coffee consumption and lawn-mowing. With midata choice engines we'll be able to predict the future and control it.

Which mooncalf would fall for this unlikely sales pitch? Cui bono?

There are many answers but one obvious one is Whitehall's Behavioural Insights Team.

They're not having much luck. Most people ridicule the team's nudging job. Their behavioural insight is limited. Tasked with getting UK retailers to sign up to midata, they failed and have now resorted to legislation – the very tool they're meant to abjure.

How could their performance be improved? What would help the Behavioural Insights Team to do its job?

These questions must have haunted Sir-Gus-now-Lord O'Donnell, head of the team's advisory board. And then along came midata. midata and its attendant app-writers, churning out choice engines to help people make life-style decisions, vehicles which could be tuned, perhaps, by Whitehall – who are footing the bill, after all, let's face it – tuned to influence, or nudge people's decisions in a chosen direction, an officially preferred direction ...

----------

Just after writing the word "pitch", just before "Cui bono", an email appeared from Alan Mitchell, the man who thinks midata will allow us to tell the future more accurately than horoscopes:
Please forward this newsletter to colleagues if you think they will find the content useful. Anyone can sign up to receive the newsletter by joining our registered [sheltered?] community here. We only send the newsletter to people who request to receive it.
Would you like to join this registered community? Perhaps this sample will help to nudge you:
We have published a short, informative paper, ‘midata: where next?’ ... It summarises the new focus areas of the programme and showcases a prize winning example straight from the recent inaugural, ground-breaking midata Hackathon of what innovation and value can be achieved in a new midata-enabled world ...

In a series of blog posts we’ve ... discussed how, by opening up a new private sector market of Identity Providers which can act on an individual’s behalf, the Government is kick starting an ecosystem of enriched, trusted data sharing, stimulating innovation and cost saving opportunities ...

There is further investment in the quantified self space as Canadian company Retrofit announces $8 million in new funding ...
----------

Added 1.4.13: Nike+ FuelBand and Google Glass: what next for the 'quantified self'?

midata – nudging you into an interactive flashbased graph

There's so much wrong with midata, the Department for Business Innovation and Skills initiative to "empower" all us consumers, that you may forget the delightful loopiness of its proposed benefits:
If organisations try to share customer data with each other they invade individuals’ privacy and risk breaching the Data Protection Act. The result is duplication, waste and missed opportunities ...

Tallyzoo, a service dedicated to self monitoring, allows users to measure anything from their caffeine intake to the number of times they cut their grass. Users collect data using a mobile device or website program which creates interactive flashbased graphs enabling them to spot trends and patterns in their consumption habits, work, health and fitness goals. Data is manipulated so that users can share statistics and compare the end results ...

Access to such data represents a ‘holy grail’ data to companies because it explains why people do what they do and predicts what they are going to do next.
Silly old privacy laws. They just get in the way. They're synonymous with waste and duplication. They stand in the way of interactive flashbased  graphs of our coffee consumption and lawn-mowing. With midata choice engines we'll be able to predict the future and control it.

Which mooncalf would fall for this unlikely sales pitch? Cui bono?

midata and identity assurance – BIS and DWP lure the British public into danger

Hat tip: Dave Birch

Questions have been raised about the advisability of creating population registers on the web.

The Department for Business Innovation and Skills (BIS) have an initiative called "midata" which would require us to enrol in identity registers in the cloud, please see for example Cybersecurity – good news at last, from midata.

The Department for Work and Pensions (DWP) have an initiative called "Universal Credit" which would require us to ditto, please see for example Identity assurance – convenient? It'll make your life so much easier.

The objections to subscribing to on-line population registers are manifold and include the dangers of cybercrime.

What dangers of cybercrime?

Take a look at this, from Reuters, 20 November 2012:
Man arrested in Athens over ID theft of most of Greek population

ATHENS | Tue Nov 20, 2012 12:14pm EST

(Reuters) - Greek police have arrested a man on suspicion of stealing the personal data of roughly two thirds of the country's population, police officials in Athens said on Tuesday.

The 35-year old computer programmer was also suspected of attempting to sell the 9 million files containing identification card data, addresses, tax ID numbers and license plate numbers. Some files contained duplicate entries, police said.

Greece's population is 11 million ...
BIS and DWP promise us, of course, that the midata and Universal Credit registers will be held in secure websites. No doubt. But then the Greek population register was supposed to be secure, too. Not much help, is it?

Surely this must be a one-off, you object? No. You're forgetting last year's Jerusalem Post, 24 October 2011:
'Contract worker stole all Israelis' personal information'

By JPOST.COM STAFF LAST UPDATED: 10/24/2011 13:16

Information was used to create searchable database; computer technician put the database on Internet for anyone worldwide to access.

A contract worker from the Labor and Welfare Ministry was charged with stealing the personal information of over nine million Israelis from the Population Registry, the Justice Ministry announced Monday after a media ban was lifted.

The worker electronically copied identification numbers, full names, addresses, dates of birth, information on family connections and other information in order to sell it to a private buyer ...
And so it goes on ...

BIS and DWP are luring the British public into danger. It is at the very least irresponsible of them to do that. Why are they doing it?

It's up to them to answer that question.

Meanwhile, you are strongly advised to resist their invitations.

midata and identity assurance – BIS and DWP lure the British public into danger

Hat tip: Dave Birch

Questions have been raised about the advisability of creating population registers on the web.

The Department for Business Innovation and Skills (BIS) have an initiative called "midata" which would require us to enrol in identity registers in the cloud, please see for example Cybersecurity – good news at last, from midata.

The Department for Work and Pensions (DWP) have an initiative called "Universal Credit" which would require us to ditto, please see for example Identity assurance – convenient? It'll make your life so much easier.

The objections to subscribing to on-line population registers are manifold and include the dangers of cybercrime.

What dangers of cybercrime?