SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Policy

Canada Revenue Agency invests in IT security

Canada Revenue Agency invests in IT security

By:  Shane Schick  On: 01 Mar 2009 For: ComputerWorld Canada Creator

As Canadians start preparing their taxes, the federal organization responsible for NetFile is making progess on a slew of initiatives designed to protect their data. Read the coverage from GovSym

Canada Revenue Agency is beefing up its IT security just weeks after a phishing scheme tried to fool users about their refunds and as tax season gets under way.

The measures include a security awareness program for all of the Canada Revenue Agency’s (CRA) 50,000 employees and the implementation of an identity and access management program. CRA is also enforcing a policy that 15,000 laptops under its control be encrypted, and is rolling out a vulnerability assessment program to see where software patches may need to be applied.

Ken Canam, CRA’s director of IT security, said the agency has been exploring ways to improve the protection of data and applications following its compliance with the federal Management of Information Technology Security (MITS) standard, which was made mandatory by Treasury Board Secretariat two years ago. The CRA isn’t stopping there, though.

“You can be MITS-compliant, but you have to recognize that MITS is only a baseline,” Canam said. “You have to look at your organization and determine where you meet MITS and where it needs to be exceeded.”

Shane Schick's Computerworld

What we talked about at GovSym

Canam made his comments at GovSym, a public sector security event held in Ottawa last week by IT World Canada and founding sponsor Symantec.

The CRA is a mix of Windows servers, Unix and even Linux machines. A critical priority for the agency is scanning and ensuring the integrity of its NetFile online tax filing system. This is especially important, Canam noted, in light of a recent phishing scheme where Canadians were asked to click a link that promised a lucrative refund.

Mark Fossi, who leads the research effort around Symantec’s Internet Threat Security Report, said the CRA phishing scheme demonstrates the increasing sophistication of online threats.

“It’s not like it’s an e-mail about millions of dollars coming from Africa,” he said, referring to phoney e-mail messages purportedly from Nigera. “It’s reasonable amounts. Who couldn’t use an extra hundred bucks right now?”

Canam noted that the only thing that looked different from the real CRA site was a minor discrepancy in a French character.

The CRA is as focused internally as it is on citizen-facing applications like NetFile. Part of the CRA’s plan involves an enterprise security monitoring console, which Canam said looks for simultaneous access on the same account. “So if you were in Halifax and logged on, and then at the same time someone else logged on with the same ID in Toronto, that would send an alert and we could block that access,” he said.


Sign up for our Newsletters












Print |  Views: 10634   |   Rating:onononoffoff  (14 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Shane Schick Shane Schick is the Editor-in-Chief of IT World Canada. Follow him at Twitter.com/shaneschick, Facebook.com/Shane.Schick.Media or myi.tw/ShaneSchickGoogle.

Related Content

Juniper adds router, switch coverage to security manager
Juniper adds router, switch coverage to security managerJuniper now calls its NSM software Network Security Manager after adding coverage for many of its switches and routers. The company now claims it offers a unified security and infrastructure management solution
MTS Allstream expands security offerings
MTS Allstream expands security offeringsThrough a portal made by SecureWorks, the carrier’s customers can get access to security and compliance information.
Frontiers of risk
Frontiers of riskIt's a safe bet no organization anywhere can be 100 per cent secure. A constantly changing cyberscape helps guarantee this. It's also why security and IT managers can never run and hide from risk management and threat assessment.
Obama, the security threat
much hay was made in the now-mercifully-ended u.s. election campaign (next one starts in january!) about whether the democrats were soft on homeland security. regardless of opinion, the president-elect -- congratulations, sen. obama -- has predictably become an it security threat.websense, symantec and sophos labs reported today on pusa-related security issues. websense says its threats
blog comments powered by Disqus