logo
Review finds urgent need to change police internet rules

Review finds urgent need to change police internet rules

By Sam Sherwood of RNZ
A review commissioned amid an investigation into the former deputy police commissioner has revealed weaknesses in police's internet access controls, unmanaged devices, limited monitoring and governance gaps.
Police Commissioner Richard Chambers says the review made clear the current settings were "not robust enough and urgent attention is required".
He has ordered the re-introduction of audits of data and internet usage on police devices and initiating an assessment of police-owned standalone devices which operated outside the police network.
RNZ earlier revealed the investigation into Jevon McSkimming which centered on allegations pornography found on McSkimming's work computer was being investigated as alleged objectionable material, led to concerns that staff could bypass internal controls and "exploit vulnerabilities to access inappropriate content".
The concerns prompted Chambers to order a "rapid review" of police's information security (INFOSEC) controls to ensure police had sufficiently strong controls to prevent or detect the misuse of police technology and equipment for non-work-related purposes.
A summary of the review was released on Monday.
The report said police managed an "extremely complex technology operating environment".
"This requires a variety of different user personas to be catered for, each with different levels of security controls (and in some cases a requirement to have permissive controls)."
"Additionally, the varied (and law enforcement) nature of policing may require some employees to access websites that in other corporate environments may be blocked."
For several years police had been faced with a "technical debt", however steps were being taken to address this.
"As with many agencies and businesses, there has been an increase of what is commonly known as Shadow IT - that is, technology purchased or used for legitimate business purposes but operated outside of the management and oversight, and often the knowledge of the ICT group."
The report said police had a "wide range" of modern security technology in place which protected police information.
"Most user activity is logged and monitored in accordance with good industry practice.
"The review found some key issues however, which provide opportunity for improvement."
The main risks were; weaknesses in technology configuration, lack of visibility over user activity and gaps in governance.
The report included key findings and recommendations in relation to each of the risks.
There was "inconsistent application" of internet access policies across different workgroups as well as a "lack of robust filtering mechanisms" to consistently prevent access to unauthorised websites.
The review also found there was "insufficient monitoring of internet usage to detect and respond to potential security threats and inappropriate usage."
Other findings included unmanaged devices being used for operational activities and inadequate monitoring of user activity and network traffic.
There was an absence of centralised logging and analysis tools to detect anomalies and potential issues and "insufficient resources allocated to continuous monitoring and incident response".
The review also said there was lack of "clear governance structures and accountability" for INFOSEC controls, with "inconsistent enforcement" of security policies and procedures.
The report called for "improved oversight and coordination among different workgroups".
Among the recommendations was that police implement consistent internet access policies across all work groups and use advanced filtering mechanisms to block unauthorised websites.
It was also recommended that police enforce policies to ensure all devices were managed and monitored, and that they allocate resources to "continuous monitoring and incident response".
In relation to the concerns about governance, the report recommended police established clear structures and accountability for INFOSEC controls and "ensure consistent enforcement of security policies and procedures".
"Addressing these issues through the recommended actions will enhance operational security, visibility, and policy enforcement, ensuring a robust INFOSEC posture," the report said. Police commissioner responds
Chambers said the review found that while police had a wide range of security measures in place, there were "opportunities to strengthen and tighten controls on their use".
"The review found police has a range of modern security controls which protect police information and systems from malicious activity. Most user activity is logged in line with good industry practice and there is clear guidance and expectations for staff around acceptable use.
"However, the review also identified several areas where improvement was needed. These include more monitoring of staff internet use and stronger filtering mechanisms to guard against inappropriate or harmful content being accessed or downloaded."
The review also recommended better oversight of all police-owned devices, including those that sit outside the police network for legitimate work purposes, Chambers said.
"Police is an extremely complex workplace and different levels of security settings will always be required by some staff for lawful policing purposes. Some staff also require devices that operate outside the central police system.
"However, the review has made it very clear the current settings are not robust enough and urgent attention is required. The report includes recommendations to strengthen the settings."
Chambers said he had made two decisions immediately in wake of the review.
He would be re-introducing audits of data and internet usage on police devices, a process that was halted about four to five years ago, and initiating an assessment of police-owned standalone devices which operate outside the police network.
"While there are legitimate work reasons for such devices, clarity is needed around the oversight of them.
"I have requested a remediation plan to consider the review's recommendations and address key issues. I have asked this be done quickly and expect to make further decisions within the month."
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

One injured, extensive damage in Kenmure house fire
One injured, extensive damage in Kenmure house fire

Otago Daily Times

time28 minutes ago

  • Otago Daily Times

One injured, extensive damage in Kenmure house fire

A fire that broke out in a home's bedroom in Barr St extensively damaged the property. PHOTO: PETER MCINTOSH One person was treated for burns after a fire broke out in the bedroom of a Dunedin home. A Fire and Emergency New Zealand spokesman said initially crews from the Lookout Point and Roslyn stations were called to the blaze at a property in Barr St, Kenmure, at 11pm yesterday. While on route, it was confirmed to Fenz that everyone inside has made it out of the property. On arrival, firefighters found a well-involved fire, and put through a second alarm. The house was approximately 150sq m. Smoke from a fully involved house fire on Barr Street on Sunday night. Photo: Craig Baxter Further crews from the Dunedin City and St Kilda stations attended. The fire broke out in a bedroom on the bottom storey and was extensively damaged. Smoke also significantly damaged the rest of the structure, the spokesman said. One person received burns to their hands and were treated at the scene before being transported to Dunedin Hospital by Hato Hone St John. Police were called to assist with crowd control due to onlookers. A fire investigator was at the property this morning to work out the cause of the fire.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store