Govt clamps down on web service providers after data breach
By Pattrick Smellie
Aug. 26 (BusinessDesk) - A swathe of government departments have been ordered not to use web and information
communications technology service providers not on an approved list following disclosure of a major data privacy breach
over the weekend.
The Treasury, which suffered an embarrassing data breach prior to the Budget, is among those required to use only those
providers who appear on an approved 'all-of-government ICT common capabilities procurement list', Prime Minister Jacinda
Ardern announced at her post-Cabinet press conference.
The move follows the inadvertent publication online of key personal detail, including birth certificates, driver's
licences, and passport numbers of 302 people who applied to be part of the Tuia 250 Voyage trainee scheme - an
initiative linked to commemorating the arrival of Captain James Cook in New Zealand waters in 1769.
With immediate effect, all government departments deemed to have "small" ICT capabilities will be bound by the new
requirement to use only approved providers, where previously the list's use was voluntary.
Some surprisingly significant agencies are covered by that definition. Along with the Treasury, the Department of Prime
Minister and Cabinet, the State Services Commission, Ministry of Defence, Ministry of Transport, Ministry of Housing and
Urban Development and the Crown Law Office were singled out by Ardern as being covered by the order.
Also on the list are the Ministries of Women's Affairs and Pacific Peoples, the Education Review Office and the recently
formed Te Arawhiti, which is tasked with managing relations between the Crown and Maori.
"They must review planned and future ICT projects, implement common capability security and privacy-related government
chief digital officer guidance," said Ardern. "They must follow the government chief information officer's information
security standards and policies and they must obtain the government chief information officer's certification that they
are compliant with these requirements."
The move is a clear sign of the Cabinet's frustration with sloppy data management by government agencies and its
capacity to damage public confidence in the Crown's ability to maintain citizens' data privacy - a core requirement in
the social contract between a government and its people.
Ardern said the unnamed firm that established Tuia 250 website was not on the all-of-government procurement list.
"My understanding is that list has not been mandatory but as I've set out, as an interim step while we work through what
we need to do to prevent this ever happening again, we will now be requiring those small agencies to procure from that
list over the near future as we work to secure all New Zealanders' data and restore confidence in the systems and the
agencies who are providing the services to the NZ public," Ardern said.
(BusinessDesk)