Security not an issue with city software: DfP

A PIECE of tracker software produced by a Londonderry IT company, which stores detailed information on charities and community groups, is hosted on a secure server and does not require security clearance, according to Finance Minister Sammy Wilson.

The Social Impact Tracker software is designed and owned by Cúnamh ICT costs around £1k per year and is billed as “a secure, web-based database application that allows you to capture and report your outputs, outcomes and your social impact.”

But Traditional Unionist Voice (TUV) MLA Jim Allister quizzed the Finance Minsiter for his assessment of the security of the software. He also asked whether its hosts have received security clearance.

Hide Ad
Hide Ad

Mr Wilson replied: “Advice to the Special EU Programmes Body (SEUPB) is that the Social Impact Tracker product is hosted on a secure server encrypted using 256 bit strong SSL encryption to maintain data privacy and integrity.

“The system is password protected and secure programming techniques are used to prevent unauthorised access. Data relating to the product is managed by a third party supplier located in a secure data centre, and access to the servers is strictly limited.

“Cúnamh ICT has also advised that it adheres to the Data Protection Act 1998 and is registered as a Data Controller with the Information Commissioner’s Office.

“SEUPB has never itself used the Social Impact Tracker software, and has no role in management or supervision of the software.”

Hide Ad
Hide Ad

The Minister also revealed that any endorsement previously provided by the SEPUB did not relate to the current online software, but to a previous desktop based version.

The former incarnation involved the software being installed on individual PCs and “a central records database setup in-house within the project/client organisation.”

The Minister stated that security was not relevant in this case.

“Additionally, any endorsement does not offer commentary on the adequacy of technical security or data management issues. I believe that in this instance the issue of security clearance is not relevant,” he stated.