FACEbook

Showing posts with label GAO. Show all posts
Showing posts with label GAO. Show all posts

Thursday, August 13, 2015

Old Fashioned Crime: One-Quarter of Federal 'Security Incidents' are Non-Cyber

     While cyber-security incidents and computer system breaches such as the recent Office of Personnel Management (OPM) hack grab the headlines, a recent government reports shows that more mundane non-cyber incidents have skyrocketed as well. A graphic in a recent Government Accountability Office (GAO) report illustrates that a full 25% of "Information Security Incidents" are actually non-cyber in nature. This percentage represents 16,879 incidents in 2014 alone:



     When asked to explain the nature of these "non-cyber" incidents,  Gregory C. Wilshusen, Director, Information Security Issues for the GAO told THE WEEKLY STANDARD [emphasis added]:
The non-cyber incidents are those pertaining to the spillage or mishandling of personally identifiable information which involve hard copies or printed material as opposed to digital records. While my statement focused on cyber threats, it also touched upon data breaches which can be effected through cyber and non-cyber means.
     The GAO report indicated that in 2006, the total number of "information security incidents reported by federal agencies" (cyber and non-cyber) were 5,503. (The breakdown of cyber versus non-cyber for 2006 was not available.) But even using these figures, the number of non-cyber incidents alone in 2014 (16,879) is more than three times the total number of security incidents in 2006.
     Although cyber incidents have the potential to do widespread damage due to the nature of computer-based crime, the rapid increase in paper-based incidents involving personally identifiable information is worrisome as well. As bureaucrats and policy makers focus on high-tech mischief and crime, a growing number of criminals appear to be content to steal information the old fashioned way.


Note: A version of this post first appeared at The Weekly Standard.

Thursday, April 3, 2014

Security Breaches of Personal Information at Federal Agencies More Than Double Since 2009

    Millions of individuals who recently entrusted personal, medical, and financial information to the federal government while enrolling in Obamacare via Healthcare.gov may find a recent trend reported by the Government Accountability Office (GAO) rather unsettling.  The number of security breaches involving Personally Identifiable Information (PII) at federal agencies more than doubled in recent years, increasing from 10,481 in 2009 to 25,566 in 2013.  Perhaps even more disturbing, the GOA found that "none of the seven agencies [in a related study] consistently documented lessons learned from PII breaches."
    A graph accompanying the GAO report illustrates the dramatic and consistent upward trend in PII-related breaches over the last several years:


    A data breach may consist of something as simple as mailing documents containing PII to the wrong recipient, but also includes incidents involving massive loss of sensitive data as illustrated by these examples in the report:
  • [I]n May 2006, the Department of Veterans Affairs (VA) reported that computer equipment containing PII on about 26.5 million veterans and active duty members of the military was stolen from the home of a VA employee. 
  • In July 2013, hackers stole a variety of PII on more than 104,000 individuals from a Department of Energy system. Types of data stolen included Social Security numbers, birth dates and locations, bank account numbers and security questions and answers...
  • In May 2012, the Federal Retirement Thrift Investment Board (FRTIB) reported a sophisticated cyber attack on the computer of a contractor that provided services to the Thrift Savings Plan. As a result of the attack, PII associated with approximately 123,000 plan participants was accessed. According to FRTIB, the information included 43,587 individuals' names, addresses, and Social Security numbers, and 79,614 individuals' Social Security numbers and other PII-related information. 
    While the increasing number of incidents is concerning, the GAO also found that "agencies have had mixed results in addressing" information security "and most agencies had weaknesses in implementing specific security controls."  An earlier GAO report in December 2013 covered the responses to PII data breaches of seven federal agencies, including the IRS; the Centers for Medicare and Medicaid Services (CMS), the agency charged with implementing and running Obamacare; and the Veterans Administration (VA).  That report found agency responses broadly inconsistent.  For example:
  • only one of seven agencies reviewed had documented both an assigned risk level and how that level was determined for PII data breaches
  • only two agencies documented the number of affected individuals for each incident 
  • only two agencies notified affected individuals for all high-risk breaches
  • the seven agencies did not consistently offer credit monitoring to affected individuals
  • none of the seven agencies consistently documented lessons learned from their breach responses
    The GAO report also gives a preview of an upcoming report specifically on cybersecurity at federal agencies, and preliminary results are not encouraging.  The GAO has found effective and consistent response to cyber incidents in only about 35% of cases:
While these results are still subject to revision, we estimate, based on a statistical sample of cyber incidents reported in fiscal year 2012, that the 24 major federal agencies did not effectively or consistently demonstrate actions taken in response to a detected cyber incident in about 65 percent of reported incidents.
    The full GAO report on cybersecurity will be completed and issued later this spring.


Note: A version of this post first appeared at The Weekly Standard.

Thursday, May 9, 2013

The Federal Government's "Death Master File" (I Am Not Making That Up)

    While I certainly would not dispute the reasons for maintaining such a record, does it strike anyone else as just a little creepy that the government has a database called the Death Master File?  The Government Accountability Office (GAO) is currently conducting a review of the Social Security Administration's Death Master File to determine weaknesses and irregularities and recommend improvements to prevent improper payments.  The review is still in process, but the GAO issued a preliminary report this week.  Apparently this review is a long time in coming.  In a run-through of some 98,000,000 records, the GAO found a few peculiarities:
Specifically, we identified:
• 130 records where the date of death was recorded to occur before the date of birth;
• 1,295 records where the recorded age at death was between 111 and 129; and
• 1,791 records where the recorded death preceded 1936, the year SSNs were first issued, although the decedents had SSNs assigned to them. 
SSA officials said some of these anomalies were likely associated with records added prior to the mid-1970s that were manually processed.
    Obviously the government's interest in knowing when U.S. citizens die is not so it knows when to send flowers.  The report noted the real reason: money.
Federal benefit-paying agencies generally can access the information in this file and match it against data in their files to alert them to deceased benefit recipients, and therefore help reduce improper benefit payments. As the steward of taxpayer dollars, the federal government must guard against improper payments. Yet for fiscal year 2012, the Office of Management and Budget reported federal agency improper payment estimates totaling almost $108 billion.
    If it is true that the only two things certain in life are death and taxes, then I think there's plenty of evidence that the government has got the certainty of the latter handled.  With the help of the GAO, the government should be able to nail down the former, too.

Sunday, January 20, 2013

Watching the Watchdog: Gov't Accountability Office Issued Only Two of Six Bimonthly Reports Required By 2009 Recovery Act in 2012 [Updated]

    When Congress passed the American Recovery and Reinvestment Act of 2009, one of the provisions to ensure transparency instructed the Government Accountability Office to issue bimonthly reports on the use of funds authorized in the Recovery Act and to make those reports available on the internet.  However, after fairly consistent reports in the first year, the regularity of the reports began to wane, and in 2012, only two such reports were posted on the Recovery.gov website.  Rather than bimonthly review reports at 60-day intervals, the average report interval has been more than 90 days, more than 50% longer than the statutory requirement.

    One section of the Recovery website is titled GAO Findings.  A note at the top of the page says:
 The Recovery Act requires the Government Accountability Office (GAO) to review the use of Recovery funds by states and localities every two months. Its reports are below[.]
    Indeed, all the reports issued since the inception of the program are available on the site.  The summaries of the first three reports in 2009 each make reference to a "bimonthly report."  After that, the term is dropped and only makes one more appearance in the December 2010 report which refers to "previous bimonthly and recipient reporting reviews."  However, in both the highlights and full version of even the most recent report (October 2012,) the bimonthly requirement is mentioned.

    With that in mind, here are the issue dates of the reports listed on Recovery.gov:
  1. April 28, 2009
  2. July 8, 2009
  3. September 23, 2009
  4. November 19, 2009
  5. December 10, 2009
  6. March 3, 2010
  7. May 26, 2010
  8. September 20, 2010
  9. December 15, 2010
  10. April 7, 2011
  11. June 29, 2011 
  12. June 29, 2011 (two reports issued on same day)
  13. September 22, 2011
  14. December 16, 2011
  15. June 18, 2012
  16. October 15, 2012
    If bimonthly reports had been issued on a strict schedule, there would have been 23 reports at about 61 day intervals as opposed to 15 reports at an average interval of 92 days (not counting the two reports issued on the same day).  Days between reports for the last two (2012) were 185 days and 119 days.  As of January 20, 2013, another 97 days have passed since the most recent report.

    Interestingly, the GAO does not dispute this finding, although a slight discrepancy exists. In a speech on November 16, 2012, in Beijing, China, Gene L. Dodaro, Comptroller General of the United States, made the following statement concerning the reviews and reporting by the GAO:
Since 2009, GAO has issued 17 bimonthly review reports and one more is underway.  And we have issued more than 100 other reports and testimonies on Recovery Act funding.  These proactive efforts continue to yield very positive results. GAO’s Recovery Act efforts have helped ensure accountability, counter fraud, and promote transparency over where the money went and the results it achieved.  
    Although Dodaro stated "17 bimonthly review reports" have been issued, only 16 are listed on the GOA website as was stated above. In either case, despite the "bimonthly" claim, the reports have averaged around 90 days, or quarterly, not bimonthly, and the total is six or seven short of the 23 called for by the legislation.  Here is the relative text from the legislation spelling out the reporting responsibilities of the GAO.  There do not appear to be any caveats or exceptions to the bimonthly requirement:
TITLE IX--LEGISLATIVE BRANCH
GOVERNMENT ACCOUNTABILITY OFFICE
......
GENERAL PROVISIONS--THIS TITLE
Sec. 901. Government Accountability Office Reviews and Reports. (a) Reviews and Reports-
(1) IN GENERAL- The Comptroller General shall conduct bimonthly reviews and prepare reports on such reviews on the use by selected States and localities of funds made available in this Act. Such reports, along with any audits conducted by the Comptroller General of such funds, shall be posted on the Internet and linked to the website established under this Act by the Recovery Accountability and Transparency Board.
    In a year when the agency has only issued two of six required reports, it is curious to say the least that the head of the GAO continued to refer to the Recovery Act reports as "bimonthly." This misstatement alone is cause for concern about the level of transparency at the government's largest watchdog agency.

    Although the GAO works for Congress, the Obama administration is widely recognized as having ownership of the Recovery Act. Though Congress bears some responsibility for being asleep at the switch, with the GAO's reporting in 2012 occurring at only one-third of the level Congress mandated for the trillion-dollar Recovery Act, the Obama administration's pledge to run the "most open and transparent administration in history" could certainly be called into question as well.

UPDATE: I received a response from Chuck Young, Managing Director of Public Affairs for the GAO in which he stated that the "Recovery Act requires bi-monthly reviews but does not require bi-monthly reporting."