Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Inspector General Calls VA on Carpet Over Data Theft

Internal report cites 'indifference' of security officers

July 17, 2006 12:00 PM ET

Computerworld - Information security officers and other officials at the U.S. Department of Veterans Affairs reacted with "indifference" and a "lack of urgency" after learning about the theft of computer hardware containing personal data on millions of veterans, according to a report released last week by the agency's inspector general.

The report also says that process and policy failures, a lack of supervision and personal squabbles contributed to the security breach and the VA's response to the incident. The inspector general recommended several steps for addressing the shortcomings, including the adoption of a "clear, concise" policy for safeguarding sensitive data.

In a letter to the inspector general that was included with the report, VA Secretary R. James Nicholson said he fully concurs with the recommendations and is committed to making the VA "a gold standard" for information security among government agencies.

The security breach "exposed deficiencies in information security involving leadership, policies and procedures," Nicholson wrote. "That will change during my tenure." He added that he has made it clear inside the VA that improving security and reorganizing the agency's Office of Information Technology "are my top priorities going forward."

'Decades of Neglect'

But Bruce Brody, a former chief information security officer at the VA, called the inspector general's findings a little underwhelming. The report "points fingers at all the symptoms instead of all the underlying causes," said Brody, who is now a security consultant at Input in Reston, Va.

A lot of the problems at the VA involve systemic cultural issues and an environment in which the agency's IT and security offices traditionally have had far too little authority to be really effective, Brody claimed. "Decades and decades of neglect and a fierce resistance to centralized authority are the root causes for this," he said.

The names, Social Security numbers and other personal data of 26.5 million veterans and active-duty military personnel were exposed when a laptop PC and external hard disk were stolen May 3 from the home of a VA data analyst. Both pieces of hardware were recovered last month by the FBI, which has said that the data appears to have been untouched.

Nonetheless, the VA is stilltaking heat from members of Congress who want the agency to go forward with a sweeping restructuring of its IT operations. The inspector general's 78-page report bolsters the calls for internal changes, listing lapses up and down the chain of command at the VA.

For instance, the data analyst whose house was burglarized was authorized to access VA databases, according to the report. But much of the information he had stored on the hard drive was being used for a self-initiated project he had been doing on his own time since 2003 without the knowledge of his supervisors, the report says.



Jump to comments

$firstKeyword

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs