DIAC security threatened by flood of contractors

A clarification was made to this story.
Read below for details.

The Department of Immigration and Citizenship's (DIAC) network has been threatened by a flood of IT contractors.

Since 2003, the number of staff-security clearances DIAC processes annually has more than tripled from 800 to 2,500, according to Mark Handley, director of protective security at DIAC who spoke at The National Corporate Security Summit in Sydney today.

Some 90 per cent of DIAC's staff — temporary and permanent — require some level of security clearance and the demand for contractors shows no signs of slowing. "We're well on track to do 2,500 clearances this year," said Handley.

Security clearances, ranging from "protected" to "top secret", determine what systems and information staff can access while employed with the agency. These must comply with the Australian Government Protective Security Manual (PSM).

"If you do the maths, 10,000 clearances over four years for a department of less than 10,000, indicates there is a significant churn rate. That churn rate is mainly in contractors... And it's basically contractors coming in to work on a short term project and going out — that's where our clearances are mainly focused," said Handley.

To manage the higher level of staff-clearances, DIAC outsourced the process in 2004, which cost it AU$1 million per year, according to Handley. Currently, an internal team of 10 security clearance assessors handle priority cases (which make up a total of 10 per cent), while the bulk is handled by contracting companies.

"In Immigration we share much of the responsibility for security with our contracted service providers. For example, our larger providers may develop their own security policy — based on our interpretation of the PSM, of course... We have agreements with some companies that they will actually manage the security clearance process," he said.

Handley says that "empowering the contractor to be responsible and accountable for their security practices has resulted in excellent long term working relationships with our providers". However, offering a degree of autonomy has proved a headache too — especially when the term of a contract is about to end.

"We had a recent contract where we were tendering out our IT support systems. There was a problem there. [The incumbent provider] could access every nook and cranny of our process. That's why we cleared every single one of them to protect it. How could we protect commercial-in-confidence material from a professional who is concerned about his job?

"We had to go to extraordinary lengths. We even got our own separate network on a floor in a building that was compartmentalised from any other areas. We did not allow the IT company that was our incumbent at the time to provide us with any services for that network because there was material that directly affected the future of that company," said Handley.

"The problem is that commercial-in-confidence material can be much more damaging than top secret," he added.

DIAC's technology partner for the AU$496 million Systems for People overhaul is IBM. Other smaller providers include UXC, Fujitsu, EDS, Oracle, Siebel and smaller suppliers Tibco, RuleBurst and Apis Computing.

DIAC's on-going AU$200 million a year IT operations have previously been dominated by IT outsourcing company CSC; however, in January 2007 it handed an AU$140 million contract to Unisys. CSC recently signed a two-year deal worth AU$110 million to manage DIAC's mainframe and mid-range computing needs.

Clarification: In his presentation at the National Corporate Security Summit, Mark Handley did not say the Department of Immigration and Citizenship's network was "at risk" due to the increased number of contractors.

Like this article? Click below to send it to your mobile for free!

Talkback 1 comments

  1. Confused Anonymous -- 03/07/08

    10,000 checks / 4 years = 2,500 average checks per year.

    But it's gone up to around 2,500 this year form 800 four years ago. How do you get to 10,000 in this time?

    Are you sure the outsourcers are being honest with their figures?

    It's a bit ironic that DIAC have such bad people skills that they can't retain their staff.


Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay Australian Govt funds IT start-ups
    This week Australia's Federal Government announced it had allocated $3.6 million in funding to 57 local research projects so that they could be commercialised, with many of them being web or IT-related start-ups.
  • Array Google should come clean on datacentres
    It's nice that Google says it has put an effort into making its datacentres more energy efficient, but the search giant's pledges won't mean much until it discloses just how many of the beasties it's actually running.
  • Array US shows what OPEL could have been
    Sprint's WiMAX roll-out in Baltimore will prove the Australian government's decision to worm its way out of the Opel WiMAX contract was a short-sighted, and ultimately damaging, political stunt that has benefited nobody.
  • More blogs »

Tags

Back to top

Featured