FACEbook

Showing posts with label OPM. Show all posts
Showing posts with label OPM. Show all posts

Thursday, August 13, 2015

Old Fashioned Crime: One-Quarter of Federal 'Security Incidents' are Non-Cyber

     While cyber-security incidents and computer system breaches such as the recent Office of Personnel Management (OPM) hack grab the headlines, a recent government reports shows that more mundane non-cyber incidents have skyrocketed as well. A graphic in a recent Government Accountability Office (GAO) report illustrates that a full 25% of "Information Security Incidents" are actually non-cyber in nature. This percentage represents 16,879 incidents in 2014 alone:



     When asked to explain the nature of these "non-cyber" incidents,  Gregory C. Wilshusen, Director, Information Security Issues for the GAO told THE WEEKLY STANDARD [emphasis added]:
The non-cyber incidents are those pertaining to the spillage or mishandling of personally identifiable information which involve hard copies or printed material as opposed to digital records. While my statement focused on cyber threats, it also touched upon data breaches which can be effected through cyber and non-cyber means.
     The GAO report indicated that in 2006, the total number of "information security incidents reported by federal agencies" (cyber and non-cyber) were 5,503. (The breakdown of cyber versus non-cyber for 2006 was not available.) But even using these figures, the number of non-cyber incidents alone in 2014 (16,879) is more than three times the total number of security incidents in 2006.
     Although cyber incidents have the potential to do widespread damage due to the nature of computer-based crime, the rapid increase in paper-based incidents involving personally identifiable information is worrisome as well. As bureaucrats and policy makers focus on high-tech mischief and crime, a growing number of criminals appear to be content to steal information the old fashioned way.


Note: A version of this post first appeared at The Weekly Standard.

Sunday, July 12, 2015

Day Before Hack Announced, OPM Released 'Sexual Orientation and Gender Identity Discrimination' Guide

     The day before the Office of Personnel Management first announced a massive data breach of personal information, now former OPM director Katherine Archuleta's attention was focused elsewhere. Archuleta published a blog post on June 3 entitled "Celebrating Every Member of Our Federal Family" in recognition of "LGBT Pride Month." The White House reposted Archuleta's article the same day.
     In her post, Archuleta announced the release of an updated guide called "Addressing Sexual Orientation and Gender Identity Discrimination in Federal Civilian Employment: A Guide to Employment Rights, Protections, and Responsibilities."
 

As we celebrate LGBT Pride Month, I want to proudly reinforce my continued commitment to the lesbian, gay, bisexual, and transgender members of our federal family, and recognize the incredible contributions this community has made in service to the American people...

That’s why I’m so excited to announce that the Office of Personnel Management is joining our partners at the Equal Employment Opportunity Commission, the Merit System Protections Board, and the Office of Special Counsel to release an updated guide titled “Addressing Sexual Orientation and Gender Identity Discrimination in Federal Civilian Employment: A Guide to Employment Rights, Protections, and Responsibilities.” This informative resource will help LGBT federal employees make more informed choices about how best to pursue their individual claims when they believe they have suffered from discrimination.
    On the OPM website, the agency has seven "top priorities" listed. The first two are "Honoring the Workforce" and "Build a More Diverse and Engaged Workforce". Number four on the list is "IT Improvement" to "streamline and update IT systems" and number five is "Background Investigations" to "lead efforts to strengthen the background investigations program across government." The priorities list does not include any direct references to "security."
    When reporters questioned White House Press Secretary Josh Earnest on June 17 about calls for Archuleta's resignation over the data breach, Earnest said that Archuleta had made cyber security a priority and that the president had "confidence" in her to do the job:
[T]his is an issue that they’ve been working on for some time; that Director Archuleta, in one of her first priorities that she identified after taking that job, was to upgrade the OPM computer network, particularly their cyber defenses.  And this is obviously an ongoing process, and the President does have confidence that she is the right person for the job...
OPM, under the leadership of Director Archuleta, recognizes that this does need to be a priority and that there is significant and important work that needs to be done to make sure that they’re fulfilling their responsibility to protect the data of federal workers... 
[A] number of senior White House officials have been in touch with the senior leadership at OPM.
     As further information came to light that the OPM breach was far worse than first revealed, Director Archuleta initially said she had no intention of resigning (via Federal Times):
"When I took office in late 2013, one of my priorities was to upgrade OPM's antiquated legacy systems," she said during a call with reporters Thursday. "It is because of the efforts of OPM and its staff that we've been able to identify the breaches."
      Friday, however, news broke of Archuleta's resignation.



Note: A version of this post first appeared at The Weekly Standard.