Stabroek News

The approach to government website security needs revision

-

Dear Editor, The government needs to enforce computer security. Little attention is given to web security on government public-facing websites and more to design and content delivery. While it is very important that public informatio­n is delivered through the various ministries and agencies, they also pose a risk to the security of the layers below. None of the government websites are secure and all are very vulnerable to snooping, among other types of unwanted behaviour. All sites should be encrypted and served over a secure connection. In addition, the expectatio­n should be that this developmen­t is standard across ministries and the continuous dependence and use of third party integratio­ns should be limited, or managed in such a way that the risks involved in using them are known and are at an acceptable level.

It is important to note the Guyana Revenue Authority and the Bank of Guyana websites. These are two very important websites and one utilizes encryption and the other does not. This indicates a disconnect with regards to standards in relation to a government IT level and the requiremen­ts of the agency. While the GRA’s website offers services that require the provision of informatio­n for the verificati­on of various transactio­ns with the agency, it does not provide a secure connection and the data provided is queried on a database that resides in the agency. If

there is some special type of segmentati­on, then that can be assumed is an acceptable risk. If not, then this is significan­t because it means that the database is live and provides very current and not historical data. The inputs are not sanitized and accept any type data input which is unacceptab­le and very susceptibl­e to a SQL injection. In contrast, the Bank of Guyana uses secure encryption and does not facilitate similar interactio­ns. However, the ‘Mail’ link at the top of the page does not direct a user to a user mail module but to the ‘host’ login page of the Bank’s website.

This may not seem like a very important issue but it really is. Keeping this obscured is a better approach. This too indicates that there is no standard web developmen­t framework, revision, certificat­ion and accreditat­ion of the basic, public-facing websites of the state.

There is dire need for a total revision of the security posture of government websites. The push towards an eGovernmen­t approach is needed now more than ever, and the focus should be on the developmen­t of centralize­d security controls. These controls will ensure that the applicatio­n layer offers a level of acceptable security and should contribute to the protection of the layers below, on which they’re hosted. Although this may be a very laborious undertakin­g, it will ultimately achieve uniformity and improved performanc­e. With the developmen­t of a comprehens­ive security policy that takes all the public-facing ministries and agencies into considerat­ion, their components should be defined and enforced consistent­ly.

Yours faithfully, Dustin Fraser

Newspapers in English

Newspapers from Guyana