ÐÇ¿Õ´«Ã½

Skip to main content

Auditor general calls for stronger federal action on cloud cybersecurity

Networking cables on a batch board are shown in Toronto on Wednesday, Nov. 8, 2017. THE CANADIAN PRESS/Nathan Denette Networking cables on a batch board are shown in Toronto on Wednesday, Nov. 8, 2017. THE CANADIAN PRESS/Nathan Denette
Share
OTTAWA -

The federal auditor general says government departments have not always effectively implemented measures to ensure secure storage of information in the digital cloud.

Karen Hogan says requirements were not always clear for putting information in the cloud -- computer servers located in data centres.

Hogan's report said these shortcomings increase the risk of security breaches as cyberattacks become more common and sophisticated.

She urged the federal government to take immediate action to strengthen how it prevents, detects and responds to cyberattacks.

Hogan said the government should do this now, while departments are still in the early stages of moving personal information to the cloud.

The recommended action includes shoring up key security controls as well as clarifying shared roles and responsibilities for cybersecurity. In a response included with her report, the government agreed with her recommendations and listed steps it intended to take.

The Treasury Board Secretariat has directed departments to consider moving applications and databases to the cloud, meaning more personal information of Canadians is being stored there, the report noted.

The auditor general found that in the four years since this direction, there had been no long-term funding plan for cloud adoption.

"Departments need both a funding approach and costing tools to ensure that the people, expertise, skills, training, funding, and other resources they need to secure cloud-based information are available to prevent and address the greatest threats and risks," the report said.

The government relies on several parties to work together to protect information in the cloud.

The auditor general said the Treasury Board Secretariat, Shared Services Canada, Public Services and Procurement Canada, the Communications Security Establishment and selected departments had controls to manage cybersecurity events in the cloud "but did not effectively implement them or establish and communicate clear roles and responsibilities for implementing them."

Hogan's team also found gaps in the way security inspections for cloud service providers were carried out. "We cannot report our findings publicly because doing so could reveal information on vulnerabilities and pose a risk to national security. Consequently, we reported them directly to Public Services and Procurement Canada."

The contracts for cloud services put in place by Shared Services Canada and the supply arrangements established by Public Services and Procurement Canada included only limited details about providers' obligations during security episodes, such as who should respond and how quickly, the report added.

The roles and responsibilities for cloud security are articulated in multiple documents, the auditor discovered. "As a result, we found that departments were confused about some of their roles and responsibilities."

For example, one directive says departments are responsible for ensuring that data stored in the cloud, including sensitive and personal information, resides on servers located in Canada. But after reviewing contracts and supply arrangements, it emerged that "not all parties involved understood this."

"Without a clear understanding of who ensures that data stored in the cloud resides in Canada, organizations risk not knowing whether personal information ends up stored in a different country and if so, whether it is subject to different (potentially inferior) privacy protection laws and security protocols."

This report by The Canadian Press was first published Nov. 15, 2022.

IN DEPTH

Opinion

opinion

opinion Don Martin: Gusher of Liberal spending won't put out the fire in this dumpster

A Hail Mary rehash of the greatest hits from the Trudeau government’s three-week travelling pony-show, the 2024 federal budget takes aim at reversing the party’s popularity plunge in the under-40 set, writes political columnist Don Martin. But will it work before the next election?

opinion

opinion Don Martin: How a beer break may have doomed the carbon tax hike

When the Liberal government chopped a planned beer excise tax hike to two per cent from 4.5 per cent and froze future increases until after the next election, says political columnist Don Martin, it almost guaranteed a similar carbon tax move in the offing.

CTVNews.ca ÐÇ¿Õ´«Ã½

The province's public security minister said he was "shocked" Thursday amid reports that a body believed to be that of a 14-year-old boy was found this week near a Hells Angels hideout near Quebec City.

Since she was a young girl growing up in Vancouver, Ginny Lam says her mom Yat Hei Law made it very clear she favoured her son William, because he was her male heir.

An Ontario man says it is 'unfair' to pay a $1,500 insurance surcharge because his four-year-old SUV is at a higher risk of being stolen.

The Montreal couple from Mexico and their three children facing deportation have received a temporary residence permit.

Local Spotlight

They say a dog is a man’s best friend. In the case of Darren Cropper, from Bonfield, Ont., his three-year-old Siberian husky and golden retriever mix named Bear literally saved his life.

A growing group of brides and wedding photographers from across the province say they have been taken for tens of thousands of dollars by a Barrie, Ont. wedding photographer.

Paleontologists from the Royal B.C. Museum have uncovered "a trove of extraordinary fossils" high in the mountains of northern B.C., the museum announced Thursday.

The search for a missing ancient 28-year-old chocolate donkey ended with a tragic discovery Wednesday.

The Royal Canadian Mounted Police is celebrating an important milestone in the organization's history: 50 years since the first women joined the force.

It's been a whirlwind of joyful events for a northern Ontario couple who just welcomed a baby into their family and won the $70 million Lotto Max jackpot last month.

A Good Samaritan in New Brunswick has replaced a man's stolen bottle cart so he can continue to collect cans and bottles in his Moncton neighbourhood.

David Krumholtz, known for roles like Bernard the Elf in The Santa Clause and physicist Isidor Rabi in Oppenheimer, has spent the latter part of his summer filming horror flick Altar in Winnipeg. He says Winnipeg is the most movie-savvy town he's ever been in.

Edmontonians can count themselves lucky to ever see one tiger salamander, let alone the thousands one local woman says recently descended on her childhood home.

Stay Connected