IT Pros May Face Background Checks
White House backs measures that include the screening of private-sector employees
Computerworld - Washington
The Bush administration plans to convene a panel of government and private-sector labor and legal experts to develop guidelines for subjecting tens of thousands of corporate IT and other employees to background investigations.
The panel, as described in the president's "National Strategy for Homeland Security" report, released July 16, would be convened jointly by the secretary of Homeland Security and the attorney general following the establishment of a cabinet-level Department of Homeland Security. It would examine whether current employer liability statutes and privacy concerns would hinder "necessary background checks for personnel with access to critical infrastructure facilities or systems."
That means employees in industries that include banking, chemicals, energy, transportation, telecommunications, shipping and public health would be subject to background investigations as a condition of employment.
"Personnel with privileged access to critical infrastructure, particularly [IT-based] control systems, may serve as terrorist surrogates by providing information on vulnerabilities, operating characteristics and protective measures," the Bush report states.
Some IT professionals see the plan as both an infringement on civil liberties and a recipe for destroying innovation and economic prosperity.
Jonathan Blitt, president of ITT Industries Inc.'s Network Systems & Services division in New York, said expanding background investigations would do more harm than good.
"I [have] great concern with any effort to expand the size of government intervention in commercial operations. The people you most want on your side are the people that may seem least desirable to a panel of so-called experts," Blitt said, referring to the community of programmers and ethical hackers who often live on what he referred to as the "fringe" of society.
"This pandering to the masses should stop, and professional reason should start. This plan could put shackles on an industry that is critical to the growth of our country."
Others see no problem with the requirement for background investigations. Eric Johansen, a systems analyst at ReliaStar Life Insurance Co. in Minneapolis, is one of those.
"Yes, there is added cost, but companies should be doing this anyway as part of standard hiring procedures," Johansen said. "A position like systems analyst [or] network administrator requires access to extremely sensitive data and control of many business-critical tasks. It would be ridiculous not to screen employees. Companies should not need President Bush's push in order for this to happen."
Indeed, background investigations are already conducted by many companies that have sensitive or critical positions that are vulnerable to terrorist infiltration, such as airport baggage screeners and air marshals, said Ed Badolato, president of Washington-based Contingency Management Services Inc. Investigations are necessary because they "provide a baseline for preventing known criminals and potential terrorists from working in vulnerable areas," said Badolato, who oversaw some of the government's most stringent and expensive background investigations when he served as deputy assistant secretary for energy emergencies at the Department of Energy.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts