News: 1643105646

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK government opens consultation on medic-style register for Brit infosec pros

(2022/01/25)


Frustrated at lack of activity from the "standard setting" UK Cyber Security Council, the government wants to pass new laws making it into the statutory regulator of the UK infosec trade.

Government plans, quietly announced in a [1]consultation document issued last week, include a formal register of infosec practitioners – meaning security specialists could be struck off or barred from working if they don't meet "competence and ethical requirements."

The proposed setup sounds very similar to the General Medical Council and its register of doctors allowed to practice medicine in the UK.

[2]

Officials in the Department for Digital, Culture, Media and Sport (DCMS) even linked their new professional regulation plans with future Computer Misuse Act amendments, floating the idea that people who aren't UKCSC-registered professionals might not be able to claim [3]any new legal defences .

[4]

[5]

Part of [6]the new National Cyber Strategy launched late last year is for there to be a government-controlled body "at the top of the profession" in the UK.

At the moment everyone's running with a hotchpotch of industry-created certifications for staff, with companies passing NCSC-backed audits for access to sensitive government contracts. UKCSC is intended to impose a single UK-specific structure on all of that.

[7]

Yet over the past year it appears UKCSC hasn't achieved very much, with official disapproval of this being all but buried in a [8]very long public consultation document titled "embedding standards and pathways across the cyber profession by 2025."

[9]UK mulls making MSPs subject to mandatory security standards where they provide critical infrastructure

[10]NortonLifeLock and Avast tie-up falls under UK competition regulator's spotlight

[11]Volunteer Dutch flaw finders bag $100k to forward national bug bounty goal

[12]Info-saturated techie builds bug alert service that phones you to warn of new vulns

"We have heard through engagement that providing recognition of the UK Cyber Security Council through legislative underpinning would further support its role as the standard setting body for the profession," said the consultation, adding that UKCSC has received "grant funding for the first four years of operation to allow it to develop a business model."

A suspicious person might think industry appears to be ignoring the self-declared "voice of the cyber security profession" to DCMS's horror. Bemoaning the amount of money and effort poured into UKCSC so far, the consultation said:

This level of support should send a clear signal to organisations across the economy that the government approves of UK Cyber Security Council standards and that these standards should be applied when seeking to build organisational resilience against cyber threats. We are concerned, however, that this is not a foregone conclusion. This approach has been undertaken previously in this space and has not achieved the intended objective of embedding professional standards and pathways.

Last year UKCSC's launch immediately hit the rocks after it told the world to visit its official website; a [13]website on a domain it didn't actually own or control . Putting this kind of organisation in charge of the entire UK cybersecurity sector as a state-owned gatekeeper doesn't seem like an auspicious move.

The consultation on UKCSC's statutory underpinnings is open and runs until 2345 on Sunday 20 March. Have your say – or don't, but don't complain if you do nothing and then don't like the outcome. ®

Get our [14]Tech Resources



[1] https://www.gov.uk/government/consultations/embedding-standards-and-pathways-across-the-cyber-profession-by-2025/embedding-standards-and-pathways-across-the-cyber-profession-by-2025#introduction

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ye-YVSBF3IdsUlVWQXCRmAAAAIc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2021/05/26/cyberup_techuk_public_interest_call/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ye-YVSBF3IdsUlVWQXCRmAAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ye-YVSBF3IdsUlVWQXCRmAAAAIc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/12/16/national_cyber_strategy_uk_launched/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ye-YVSBF3IdsUlVWQXCRmAAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.gov.uk/government/consultations/embedding-standards-and-pathways-across-the-cyber-profession-by-2025/embedding-standards-and-pathways-across-the-cyber-profession-by-2025#introduction

[9] https://www.theregister.com/2022/01/20/uk_nis_regulations_msp_plans/

[10] https://www.theregister.com/2022/01/20/nortonlocklife_avast_cma/

[11] https://www.theregister.com/2022/01/13/divd_bug_bounty/

[12] https://www.theregister.com/2022/01/12/bugalert_matt_sullivan_interview/

[13] https://www.theregister.com/2021/04/06/uk_cybersecurity_council_domain_fail_launch/

[14] https://whitepapers.theregister.com/



Valeyard

so how does this work if you're a regular bounty contributor but not working for peanuts for a professional organisation? will they insist on some of those ridiculously expensive box-ticking certs?

Ditto

Al fazed

The legal/justice industry has taken a similar step recently. Which means as you guessed, in order to continue providing Advocacy for disadvantaged and disabled people, I now need to be a legal professional of some qualification first. So it looks like the end of disadvantaged people having an Advocate with them when they are being grilled by DWP, or the Housing Benefit people, or those very nice Personal Independence Payments Assessors.

Maybe it is time to get me coat ........

ALF

Re: Ditto

ClockworkOwl

Is it not a legal right to advocacy?

If it is then this is just another bullet meets foot situation for the gov.

If not, then I'm more than slightly sickened by the judicial implications...

fnusnu

"I'm from the government and I'm here to help"

FlamingDeath

..Continued

''and I'm here to help myself and my friends"

Probably not a bad idea

Anonymous Coward

Some sort of relevant recognised accreditation would be good for those in the industry.

Better still if it wasn't some sort of pyramid scheme like IISSCC run...

I guess though the trouble is that "security" encompasses many many different specialities. We'll either end up with the shallow depth of CISSP or something so multi domain that nobody will ever want to try to learn all of it. It probably needs a modular approach with certs for particular domains.

The one fear of course is not the quality of the piece of paper nor whether it costs time and large amounts of money to "maintain" it but that you could be struck off...

Struck off for what? Your network gets penetrated? (highly likely even if you are "good") You are found with hax0r tools? You get a speeding ticket?

Re: Probably not a bad idea

Roger Greenwood

It's unlikely you will be struck off as long as you keep paying the fees. After all, those folks who wrapped buildings in flammable plastic for decades still seem to be doing OK. Some of them must have belonged to a professional body, not heard of any being struck off yet. Even doctors and nurses have to be REALLY bad before that happens.

The Briggs-Chase Law of Program Development:
To determine how long it will take to write and debug a
program, take your best estimate, multiply that by two, add
one, and convert to the next higher units.