The Inevitable IT Security Breach
2 Studies Show Why War Logs Leak Wasn't a Surprise…
Several military units failed to adequately sanitize hard drives of data, including Social Security numbers of military personnel, before shipping the IT equipment to other organizations, in violation of Department of Defense rules, the DoD inspector general said in a report.
The IG took to task individual units as well as the Defense Reutilization and Marketing Service for failing to implement adequately DoD internal controls that require the sanitization, documentation and full accountability of excess unclassified IT equipment before releasing the equipment to other organizations. "The instances of nonperformance occurred because DoD components did not follow policies, adequately train personnel or develop and implement site-specific procedures to ensure excess unclassified equipment was sanitized and disposed of properly, said the 53-page report, which was issued Sept. 21.
Additionally, the IG said, DoD guidance issued by the assistant secretary of defense for networks and information integration, who also serves as the Defense CIO, and the Navy CIO was out of date and did not cover sanitizing and disposing of new types of information storage devices. As a result, four DoD units could not ensure personally identifiable information or other sensitive departmental information was protected from unauthorized release, and one of the units could not account for an excess unclassified computer.
Specifically, the IG reported, the following pieces of excess unclassified IT equipment contained readable information.
According to the IG, the commander of the 436th Medical Group and the 50th Space Communications Squadron did not provide comments on the draft report issued on June. The IG requested comments from them on the final report to be issued in a month. Management comments the IG received were partially responsive, and the auditors asked for further clarification.
| 1 | 2 |
NIST SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems..Next Topic
DoJ: Report to Congress on Implementation of Section 1001 of the USA PATRIOT Act..Next Topic
NIST Guide to Security for WiMAX Technologies (Draft)..Next Topic
NIST SP 800-41 Revision 1: Guidelines on Firewalls and Firewall Policy..Next Topic
OMB Memorandum: New Reporting Instructions for FISMA..Next Topic
NIST IR 709: Cryptographic Key Management Workshop Summary (Draft)..Next Topic