§ Mr. Colvin
To ask the Secretary of State for Social Security what steps his Department has, and is taking to improve the security of its computer systems.
§ Mrs. Gillian Shephard
For unclassified but sensitive systems the Department is expected to follow Central Computer and Telecommunications Agency guidance covering all aspects of IT security and the application of this has been tightened recently. CCTA advice is kept 83W under continuous review and is based on analysis of security risks and requirements using structured methods such as CCTA's risk analysis and management methodology (CRAMM), which has also been made commercially available.
More stringent conditions apply to classified systems.