NITA security evaluation recommends GCnet system
The Ghana Ports and Harbours Authority (GPHA), he said, was not left out in this case.
Following the documentary, the Ghana Revenue Authority (GRA) requested the NITA to conduct an initial evaluation of the security of the system with the main objective of ensuring that GRA-CEPS Division information technology platforms and business systems were adequately secured.
It was also to give recommendations on actions to be taken by the GRA to assure the public of confidentiality of their information systems.
The GCNet system, is a web-based system and comprises three different application software used for research, monitoring, valuation, IT, CEPS operations, transit, warehousing among other functions.
Ghana Community Network Services Limited (GCNet) was incorporated in November 2000 as a private-public sector partnership (PPP), with CEPS, Ghana Shippers Council (GSC), Ecobank (Ghana) Limited (EBG), Development Finance Holdings (DFH), a subsidiary of Ghana Commercial Bank (GCB) and Societe General de Surveillance (SGS) as shareholders
Data is transferred automatically from trade-net system and captured onto a system from Aflao, KIA Airport, Elubo, Paga and other borders by GRA-CEPS officials.
The trade-net system allows the capturing of manifest information to the system an and through an impromptu business intelligence tool, data is exported into excel to enable users to analyse data stored in the system.
The report recommended that the information technology policy on acceptable use of GRA’s ICT facilities and sanction for non-compliance should be produced to address the need to protect the agency’s data and balanced it with the need to protect the rights of the agency and its staff.
The report said the GRA should adopt a password policy to ensure proper mechanisms were in place to support termination of user account, among others.
It said the GCNet should introduce a two factor authentication to access the application systems and reassign passwords and new code/pin number for all users.
Furthermore, it said the GRA should recruit a consultancy firm to conduct its audit to audit the system environment, including the application, network and data centre.
The NITA also made long-term recommendations that the GRA should recruit a senior person in the rank of deputy commissioner to oversee its system environment since the GRA intended to use IT systems in managing and supporting its bushiness objectives.
It said that considering the introduction of Ghana’s data protection law, which would enjoin all agencies to ensure p[roper data protection and confidentiality measures were implemented among other automation systems.
That, it said, would enable an independent assessment to be carried out to ensure that sufficient security controls were instituted within GRA IT platforms.
According to the NITA, data shown in the documentary by Anas was an excel spreadsheet which could be generated by other users with privileges to the impromptu system or could be passed on to them by copying of the file.
The excel data, it said, could not be fed back into the system and manipulated whiles NITA was unable to find that there were six other passwords created for any users not allowed to have access to the CEPS system.
CEPS, which manages the activities of GCNet, Destination Inspection Companies as well as companies that transact business at the port, appears to have failed in discharging its duties.resulting in cheating and corruption.
The lack of an effective policing regime by CEPS in the revenue mobilization drive has led to miscreants evading tax with cheeky ease.
Story by Stephen Sah
