News: 1624358764

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

MI5 still risks breaking the law on surveillance data through poor controls – years after it was first warned

(2021/06/22)


Exclusive MI5's storage of personal data on espionage subjects is still facing "legal compliance risk" issues despite years of warnings from spy agency regulator IPCO, a Home Office report has revealed.

The sustained legal issues even triggered a [1]Parliamentary statement by Home Secretary Priti Patel , revealing that the domestic spy agency did not have "a culture of individual accountability for legal compliance risk" until external oversight forced change upon the agency.

Answering the question of whether MI5's data holdings are "now legally compliant," a Home Office report, published on June 7, said MI5's "implementation of mitigations" for "identified risks" was still under way.

[2]

Government documents in the public domain about the spy agency's law-breaking deliberately omit references to which laws MI5 broke, preferring the euphemism "compliance", but the breaches appear to fall under [3]Part 6 ("bulk warrants") and [4]Part 7 ("bulk personal dataset warrants") of the Investigatory Powers Act 2016, the infamous Snoopers' Charter. References to "warranted data" in external compliance reports published by the government gave the game away.

[5]

[6]

The latest report, itself a report into an earlier review which made recommendations MI5 hasn't fully complied with, stems back to failures first identified in the mid-2010s.

Senior Conservative backbench MP David Davis told The Register : "When the Investigatory Powers Act was written, it was with major input from all the agencies, including MI6, GCHQ, and of course, MI5.

[7]

"Extraordinary powers were given to the agencies under this Act and therefore there is no excuse for non-compliance or inadequate compliance with those restrictions that were set in place."

Fancy giving MI5 an assist?

In the wake of the Home Office report, the spy agency published a job ad last week looking for a permanent chief data officer on a salary of £97,943–£105,883. The civil service bod's role outline included references to an "organisational wide digital transformation" that includes "a significant shift in our approach to data and technology, as well as our ways of working." The new person will be tasked with helping MI5 "put in place the data practices we need to successfully support our mission."

Once the successful candidate has donned a felt fedora, they will "lead a multi-functional team made up of business, technical and data specialists that is responsible for managing all of the MI5's data, information, and knowledge so that it can be lawfully used for maximum value."

Other than the fat salary, if they pass the security check, they get: financial support for further education, an interest-free season ticket loan (we doubt the agency is too keen on WFH), a "generous" government pension, plus subsidised gym, restaurant and coffee bar. Full specs [8]here .

A public summary of a [9]report written by National Crime Agency non-exec director Mary Calam, quietly published earlier this month, revealed that "further work is needed to fully roll out and test new policies and to reduce reliance on manual processes" for legal compliance within MI5.

While the domestic surveillance agency had cleaned up its act from where it was a few years ago, implementing an [10]internal compliance programme to address 14 formal recommendations made to it, it is still dragging its feet in key areas.

Reports over the years revealed an internal culture within MI5 that seemingly treated legal compliance as an unimportant formality, [11]with spies caught using "boilerplate text in applications" for targeted surveillance warrants. Related allegations of law-breaking are the [12]subject of an ongoing legal case by the Privacy International campaign group , which declined to comment for this article.

Exactly what happened?

Tight-lipped official sources would not say precisely what MI5's data storage blunder was but clues lie in the language used by both IPCO (the Investigatory Powers Commissioner's Office, which audits legal compliance by the spy agencies) and Home Secretaries over the years.

You can see mention of a specific data storage issue in IPCO's annual [13]report [PDF] for 2017, published two years later, which noted: "There was one complex error reported by MI5 in relation to the retention of data on an area within their IT systems. MI5 is undertaking work to remedy this problem and delete data which has been retained erroneously."

[14]UK spy auditor gives state snoops a big pat on the back for job well done – except MI5

[15]MI5 slapped on the wrist for 'serious' surveillance data breach

[16]UK spy overseer: Snooper's Charter cockups are still getting innocents arrested

[17]MI5: Gosh, awkward. We looked down the sofa and, yeah, we *do* have intel on privacy bods

By [18]2018 [PDF], IPCO was asking for "demonstrations of MI5's complex IT infrastructure" and didn't like what it was seeing:

We were not informed of serious compliance risks in relation to certain technology environments used by MI5 to store and analyse data. We judge that, by January 2018 (indeed, most probably considerably earlier), MI5 had a clear understanding of the principal compliance risks associated with these technology environments, to the extent that they should have carefully considered the legality of continuing to store and exploit operational data in those systems.

The Investigatory Powers Commissioner, Court of Appeal judge Sir Adrian Fulford, wasn't told about this legal compliance failure until February 2019, an issue IPCO branded "a matter of serious concern." This [19]triggered a Parliamentary statement by the then Home Secretary, Sajid Javid, who would only admit "the compliance risks identified are limited to how material is treated after it has been obtained."

In other words, the risk begins once the collected data hits whatever environment or environments MI5 was using, raising concerns that there might be a configuration or access control issue. This appears to be at the heart of the agency's alleged failure to comply with its legal duties to keep surveillance data secure.

More detail emerged in [20]2019's IPCO report , which castigated MI5 for its "inconsistent approach to controls around the extent to which users were able to copy data and place it into storage areas within the environment". Precisely what the "environment" is was not specified either.

[21]

Yet more information about MI5's wrongdoing in the agency's internal Compliance Improvement Report was published in July of that year, [22]containing 14 recommendations to bring MI5 into line with the law . It was this report which Calam was, in turn, reporting upon – and she found that recommendations 2, 3, 4 and 11 had not been met.

Recommendations MI5 hasn't complied with

2: Legal compliance training "should be regularly reviewed by the Audit, Risk and Assurance Committee and by the Management Board, given its responsibility for governance of MI5 activities. Completion of the training should be a precondition for analysts and technical staff to work on any IT systems which hold warranted data."

3: "The legal requirements for the management of the data processed by MI5 IT systems [must be] understood by all programme staff involved in the IT build" and "Appropriate governance systems (e.g. Gateway Reviews) are put in place to ensure that those requirements are met."

4. "Resources for MI5's compliance function need to be increased substantially, particularly in their Policy, Compliance, Security and Information team," including the hiring of skilled lawyers.

11. "The MI5 Legal Director should provide a quarterly report agreed with the Home Office Chief Legal Advisor to the Home Office Permanent Secretary and the Director General MI5 on issues relating to MI5's compliance with its statutory obligations and key legal risks."

While MI5 is trying to improve compliance, the fact that major work is still necessary to achieve it, years after failures were first noted, is troubling.

Davis, the MP and civil liberties activist, thundered: "When MI5 was found not to be fully compliant, it should have taken extraordinary and immediate efforts to bring itself back inside the rules. It is a matter of serious concern that they have failed to do so now three years after this issue was highlighted. They must bring it under control immediately."

Home Office spokesman Ian Kennedy failed to answer The Register 's questions about the Calam Report, saying only: "The Home Secretary has outlined her position in the Written Ministerial Statement. Nothing further to add to this."

An IPCO spokeswoman told The Register : "As the CIR [MI5's internal compliance project review] explains, the scale and complexity of the remedial work required have been greater than initially anticipated by the CIR. This has also been significantly compounded by the unprecedented challenges posed by the COVID-19 pandemic."

Compliance failure, meet legal action

IPCO's representative also said that part of the delays in compliance were caused by ongoing legal action from anti-surveillance campaigners: "Following a claim brought by Privacy International and Liberty against MI5 and the Home Office, the matter is now subject to litigation before the Investigatory Powers Tribunal. The litigation has necessitated a pause (by Order of the Tribunal) to some of the remedial work in order to ensure evidence is preserved for the purposes of the proceedings."

The Investigatory Powers Tribunal is a specialised court that hears cases brought against the spy agencies over illegal surveillance. Until [23]a 2019 Supreme Court ruling , the IPT was a [24]pale imitation of a real court.

Parliament's Security and Intelligence Committee did not respond to The Register 's request for comment despite the Calam Report having been supplied to its members. The committee forms the main Parliamentary oversight for MI5, MI6, and GCHQ.

IPCO's spokeswoman concluded: "As outlined in IPCO's 2019 Annual Report, IPCO continues to oversee MI5's efforts to manage legal compliance risk regarding its technology environments within the parameters set by the Tribunal. Whilst there is still work to be done, the public can be assured that MI5's compliance approach has improved significantly."

She was echoed by Home Secretary Priti Patel, who told Parliament earlier this month: "I am very grateful to the Director-General of MI5 and his staff, as well as my own officials, for the immense progress that has been made since Sir Martin Donnelly completed his Compliance Improvement Review in June 2019."

It appears that Britain's spy agency overseer has grown teeth — and while the law may not be perfect, bringing MI5 into line with it is a victory for the Investigatory Powers Commissioner. ®

Get our [25]Tech Resources



[1] https://questions-statements.parliament.uk/written-statements/detail/2021-06-07/hcws69

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YNIJIrbK47rfPH6kqsxBygAAAJQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.legislation.gov.uk/ukpga/2016/25/part/6/enacted

[4] https://www.legislation.gov.uk/ukpga/2016/25/part/7/enacted

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNIJIrbK47rfPH6kqsxBygAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNIJIrbK47rfPH6kqsxBygAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNIJIrbK47rfPH6kqsxBygAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.civilservicejobs.service.gov.uk/csr/jobs.cgi?jcode=1727217&csource=csalerts

[9] https://www.gov.uk/government/publications/independent-verification-of-the-compliance-improvement-review

[10] https://www.gov.uk/government/publications/compliance-improvement-review#:~:text=In%20May%202019%20the%20Home,conducted%20the%20Compliance%20Improvement%20Review

[11] https://www.theregister.com/2019/02/01/ipco_annual_report_2017_18/

[12] https://www.theregister.com/2018/09/25/ipt_mi5_privacy_international_bulk_data_collection/

[13] https://ipco-wpmedia-prod-s3.s3.eu-west-2.amazonaws.com/IPCO-Annual-Report-2017-Web-Accessible-Version-20190131.pdf

[14] https://www.theregister.com/2020/03/06/ipco_annual_report_2018_mi5_naughty/

[15] https://www.theregister.com/2019/05/15/mi5_data_breach_investigatory_powers/

[16] https://www.theregister.com/2019/02/01/ipco_annual_report_2017_18/

[17] https://www.theregister.com/2018/09/25/ipt_mi5_privacy_international_bulk_data_collection/

[18] https://ipco-wpmedia-prod-s3.s3.eu-west-2.amazonaws.com/IPCO-Annual-Report-2018-final.pdf

[19] https://www.theregister.com/2019/05/15/mi5_data_breach_investigatory_powers/

[20] https://www.theregister.com/2020/03/06/ipco_annual_report_2018_mi5_naughty/

[21] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNIJIrbK47rfPH6kqsxBygAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[22] https://www.gov.uk/government/publications/compliance-improvement-review

[23] https://www.theregister.com/2019/05/15/supreme_court_ipt_judicial_reviews_green_light/

[24] https://www.theregister.com/2019/12/20/investigatory_powers_tribunal/

[25] https://whitepapers.theregister.com/

Storage areas within the environment

Chris G

Sounds like a printout in an unlocked desk drawer, not even a basement filing cabinet or leopard notices.

I hope they don't employ cleaners with funny accents.

The way they drag their feet on implementation of 'compliance' rules is a clear sign they regard them as an unnecessary imposition.

Re: Storage areas within the environment

Graham Cobb

Personal-use PCs, departmental servers, shadow-IT, project shared network drives, uncontrolled sharepoints. All, probably, completely secure with the required user access controls, but no monitoring, auditing or timely deletion of the data stashed there.

Sound familiar to anyone?

Re: Storage areas within the environment

low_resolution_foxxes

You mean it's like every engineering department in the world?

Move along....nothing to see here......

Anonymous Coward

https://www.wired.com/1999/01/sun-on-privacy-get-over-it/

https://www.bloomberg.com/features/2018-palantir-peter-thiel/

https://www.theguardian.com/uk-news/2018/sep/13/gchq-data-collection-violated-human-rights-strasbourg-court-rules

.....and that's only three links....how many do I need? How many "government reports" do I need?

Excel-lent ?

Anonymous Coward

It's got to be hasn't it? They're storing all their secret data in Excel. Probably a very old version at that.

Is that it?

not.known@this.address

If that list of "Recommendations MI5 hasn't complied with" is it, then what the problem? Unless I'm missing something, that little lot boils down to "MI5 can't prove everyone has had all the most recent legal training" (points 2 and 3), "MI5 haven't thrown a bucketload of money at the lawyers" (point 4) and "MI5 haven't handed information to the civil service that could be used to identify sources when (not if) someone flaps their gums because they disagree with something Box or the Government did and want to embarrass them without giving a damn about giving away secrets" (point 11).

If that really is the sum of the things that have got the pencil-pushers at the Home Office in such a tailspin then they should be ashamed of themselves - which is more important, trying to keep the streets safe for everyone or proving that James Bond can quote Section 3, Subsection 4, Paragraph 5, points 3-17 of the Terrorist Protection Bill and knows not to copy-and-paste from one warrant request to another (and just how many ways are there to say "We know this person is up to no good but we need to prove it before the do-gooders set them free on a technicality - and the blighter goes off and does something a tad unpleasant")?

Besides, since when did completing the paperwork prove anything? Last I heard, civil servants were supposed to be bound by all sorts of confidentiality and secrecy legislation but that doesn't stop them gobbing off when someone says something they don't like...

Re: Is that it?

Graham Cobb

The point of the training is to make sure everyone understands that the law does not give them unlimited access to data! Data must be restricted in who can access it, and must be provably deleted in a timely fashion, not saved in case it is useful in the future.

Re: Is that it?

low_resolution_foxxes

I can imagine an environment that rewards individuals for quick actions and information.

The law says that only suitable qualified and trained staff, can access certain data, with appropriate safeguards. It's not a trivial environment, multiple early staff were caught stalking their partners, ex-partners and ex-partners new partners.

The whole point of training and oversight, was to ensure that those accessing secret information, were doing so for a valid reason, within valid timelines and responsibly deleting that information after. No training = less likely to achieve prosecution later on (if you haven't done the training, you cannot be held to the same legal standard, since it hasn't been spelled out to you)

If you cannot demonstrate this, then you cannot continue to practice.

Whether they really need more legal help, I cringe at throwing more money at lawyers, as I am sure that the internal compliance teams and engineers are more than capable of doing their jobs properly, it is probably more about whether they really have the desire to do so.

PS I laughed at "using boiler plate language", but surely that's the point? You use legal templates for such things?

Get a grip....the authorities are breaking the law.....and not keeping us safe either.....

Anonymous Coward

To: not.known@this.address

Quote: "...which is more important, trying to keep the streets safe for everyone..."

Last time I looked EVERY RECENT OUTRAGE was done by someone "already known to the authorities".

What was that you said about "streets safe"? Even when a known, convicted terrorist is released from jail, under license, the "authorities" pay no attention and three people are harmed!!!!!

So.......to your point, the "authorities" are breaking the law and not keeping us "safe" either!!!!! Fantastic value for taxpayers!!!!!

"compliance risk"

Mike 137

' did not have "a culture of individual accountability for legal compliance risk" '

Although endemic, the concept of "compliance risk" is utterly flawed. In essence it means no more than "risk of getting penalised". The real risk of non-compliance (in the broadest terms) is that some improper act becomes an accepted norm or that some third party suffers harm. So it's typically an externality to the non-compliant unless they get caught.

So what is "compliance" for? There are two obvious answers:

[1] to satisfy a regulator or auditor in order to have q quiet life;

[2] to ensure that something that should be done is done properly so it actually delivers what is required, or ensure that something improper does not occur.

Guess which is the most common interpretation. I'm not awarding any medals.

Re: "compliance risk"

low_resolution_foxxes

#1 is more common, but I have worked for companies than perform #2.

It is surprising, that for something as important as "are we making a good product and are we competent at our jobs" the amount of effort put into compliance is basically box ticking for most.

It is bizarre how many great ideas come out of simple tools like DFMEA and VSM concepts. Even simple things like asking your engineers "stop fixing problems when they fail, spend the day looking for the obvious things that will go wrong and fix them in advance".

Other news..

1752

In other news, a bear shat in the woods.

No one gets sick on Wednesdays.