March 21, 2008

Obama passport records breached; IT system flagged violation

State Department's privacy protection exposes intrusions; supervisors kept mum

Private contract employees working for the U.S. Department of State have repeatedly accessed U.S. Sen. Barack Obama's passport records over the past three months — a breach flagged by the State Department's in-house computer system but subsequently downplayed by the supervisors of the offices in which the breaches occurred. Two of those workers have been fired by their employers. The Obama campaign is seeking answers as to how it happened, and a broader investigation is now in the works.

The actions of the three separate workers, employees of two different contractors, were described Thursday night by State Department spokesman Sean McCormack as "imprudent curiosity." But he said that is only an "initial finding" and said the department's inspector general has been asked to investigate. Details about the breach emerged in a late-night, hastily called press conference by State Department officials.

McCormack said the department "is not being dismissive of any other possibility," meaning that it hasn't closed the door to motives other than simple curiosity.

None of the people or employers involved was identified. A third contractor was disciplined, but hasn't been fired, for viewing the records and is apparently still doing State Department work.

The breaches occured on Jan. 9, Feb. 12 and March 14, but senior State Department officials weren't aware of them until a reporter sent an e-mail query to the department's press office on Thursday.

Notification, but little prevention

In explaining what happened, the department also provided details about how its security monitoring system works to protect records privacy. The system identifies breaches after the fact.

The State Department has "strict policies and controls" regarding passport records, said McCormack. Employees and contractors are trained on the use of the system, and each time an employee logs onto it, "he [or] she acknowledges that the records are protected by the Privacy Act and they are only available on a need-to-know basis."

The Privacy Act of 1974 (PDF format) requires that "all managers of record systems are responsible for making employees and contractors, working with that system of records, fully aware of these provisions and the corresponding penalties."

"In each of these three cases, the system that was set up to detect any authorized access of these kinds of records worked. These unauthorized accesses were detected by the State Department and immediately acted on," said McCormack.

Undersecretary Pat Kennedy said some records have "what computer people call flags — we put flags on certain records that trigger a report to a supervisor that the record has been accessed," he said.

Not all 18 million passport records have flags, said Kennedy. The department's Bureau of Counsel Affairs determines what records to flag, he said.

Kennedy was less specific concerning what controls, if any, might restrict employees' or contractors' access to data once they've logged into the system.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.