InvestSMART

Security clearance a stealthy weapon for sales

Technology organisations are realising that government security certification can open doors to the wider business world.
By · 26 Mar 2013
By ·
26 Mar 2013
comments Comments
Technology organisations are realising that government security certification can open doors to the wider business world.

Typically, certification by the Australian government's intelligence agency, Defence Signals Directorate, is used to enable suppliers to work with top-level government agencies, but some are also using it as a marketing tool to build trust and increase sales to the private sector.

DSD is a part of the Department of Defence that stringently evaluates and certifies technology secure enough to be used by government. It produces the Australian Government Information Security Manual (ISM), the standard governing the security of government ICT systems, and maintains an online database of evaluated products.

The notoriously difficult certification process took mobility software company Good Technology two years. It recently obtained certification for its secure mobile application, Good for Enterprise, which allows iOS devices to communicate and store classified information up to "protected" level.

Four levels of security classification - protected, confidential, secret and top secret - reflect the consequences of unauthorised disclosure of information, from damaging the Australian government (protected) to potentially causing exceptionally grave damage to national security (top secret).

BlackBerrys have long had the DSD stamp of approval and almost a year ago government-owned iPads and iPhones (iOS5) were certified to protected level.

Accreditation involves several meetings with DSD, says Chris Roberts, vice-president of Good Technology's worldwide public sector. "We showed them everything we had. They looked at our product documentation and architecture. We gave them our source code and access to our [development] team."

The company wants to have a continuing relationship with DSD, but is also interested in the marketing opportunities: "It's an investment against cyber crime [and] we hope to increase sales."

Security accreditation is the Holy Grail of technology products, according to Kevin Noonan, public sector research director at Ovum.

"Protected-level security is about as high as you want to go for doing business with government. Going higher is in the realm of specialist security."

He says suppliers want accreditation to prove they "can jump through a hoop" and to increase the trust factor. "Certification is a powerful marketing weapon in a new area of technology where standards are settling down. It's also an indication of the company's confidence in the product if they are prepared to go through the time and expense to achieve DSD certification."

For Peter Alexander, chief information officer at the Australian Treasury, using DSD certified products and services means his department has the confidence to share classified information internally and with equally classified partners.

IT service provider Emantra also has the coveted DSD certification. The gateways at its three production data centres are certified Protected. "It is a complex and expensive technical process, subject to annual audit. It opens up our ability to sell services at a high level of government mandate, and (differentiates us) when dealing with larger commercial clients," said managing director Ross Dewar.
Google News
Follow us on Google News
Go to Google News, then click "Follow" button to add us.
Share this article and show your support
Free Membership
Free Membership
InvestSMART
InvestSMART
Keep on reading more articles from InvestSMART. See more articles
Join the conversation
Join the conversation...
There are comments posted so far. Join the conversation, please login or Sign up.

Frequently Asked Questions about this Article…

DSD certification is a government security accreditation run by the Defence Signals Directorate (part of the Department of Defence). DSD evaluates and certifies technology for secure use by government, produces the Australian Government Information Security Manual (ISM) and maintains an online database of evaluated products.

Companies pursue DSD certification to qualify for high‑level government contracts, build customer trust, use the certification as a marketing tool, and potentially increase sales both in the public sector and with larger commercial clients.

The certification process is notoriously difficult, complex and can be expensive. The article notes Good Technology took two years to achieve certification. Accreditation typically involves multiple meetings, detailed technical review and ongoing audits (annual audit is mentioned).

DSD uses four levels of security classification: Protected, Confidential, Secret and Top Secret. These levels reflect the consequences of unauthorised disclosure, from damaging government interests (Protected) up to causing exceptionally grave damage to national security (Top Secret). The article notes Protected‑level is about as high as you generally need for doing business with government.

Yes. The article explains some vendors use DSD certification as a marketing weapon to increase trust and differentiate themselves with larger commercial clients, not just to meet government mandates.

The article mentions Good Technology achieved certification for its Good for Enterprise mobile app (allowing iOS devices to handle information up to Protected level). BlackBerry devices have long held DSD approval, iPads and iPhones (iOS5) were certified to Protected level about a year earlier, and IT service provider Emantra has its gateways at three production data centres certified Protected.

According to the article, accreditation involves several meetings with DSD, showing product documentation and architecture, providing source code and giving DSD access to the development team so they can fully evaluate the product.

Government departments gain confidence to share classified information internally and with partners at equivalent classification levels. Using DSD‑certified products also meets procurement mandates and reduces cyber‑security risk, according to the officials quoted in the article.