A graph accompanying the GAO report illustrates the dramatic and consistent upward trend in PII-related breaches over the last several years:
- [I]n May 2006, the Department of Veterans Affairs (VA) reported that computer equipment containing PII on about 26.5 million veterans and active duty members of the military was stolen from the home of a VA employee.
- In July 2013, hackers stole a variety of PII on more than 104,000 individuals from a Department of Energy system. Types of data stolen included Social Security numbers, birth dates and locations, bank account numbers and security questions and answers...
- In May 2012, the Federal Retirement Thrift Investment Board (FRTIB) reported a sophisticated cyber attack on the computer of a contractor that provided services to the Thrift Savings Plan. As a result of the attack, PII associated with approximately 123,000 plan participants was accessed. According to FRTIB, the information included 43,587 individuals' names, addresses, and Social Security numbers, and 79,614 individuals' Social Security numbers and other PII-related information.
- only one of seven agencies reviewed had documented both an assigned risk level and how that level was determined for PII data breaches
- only two agencies documented the number of affected individuals for each incident
- only two agencies notified affected individuals for all high-risk breaches
- the seven agencies did not consistently offer credit monitoring to affected individuals
- none of the seven agencies consistently documented lessons learned from their breach responses
The GAO report also gives a preview of an upcoming report specifically on cybersecurity at federal agencies, and preliminary results are not encouraging. The GAO has found effective and consistent response to cyber incidents in only about 35% of cases:
While these results are still subject to revision, we estimate, based on a statistical sample of cyber incidents reported in fiscal year 2012, that the 24 major federal agencies did not effectively or consistently demonstrate actions taken in response to a detected cyber incident in about 65 percent of reported incidents.
The full GAO report on cybersecurity will be completed and issued later this spring.
Note: A version of this post first appeared at The Weekly Standard.
Note: A version of this post first appeared at The Weekly Standard.
No comments:
Post a Comment