White House orders security review in wake of WikiLeaks disclosure
OMB calls on U.S. agency and department heads to evaluate procedures in place for protecting classified data
Computerworld - The release of thousands of pages of classified U.S. government information over the weekend by whistleblower Web site WikiLeaks prompted an order to all federal agencies by the White House Office of Management and Budget (OMB) to immediately review procedures in place for protecting sensitive data.
In a brief directive issued Sunday, OMB director Jacob Lew called on the heads of all federal agencies and departments to establish special security assessment teams to conduct the reviews. Each team should include counterintelligence experts as well as security and information assurance experts, the directive noted.
Lew's memo requires that each agency evaluate their specific security measures for restricting access to classified government systems.
The directive also orders agency heads to ensure that employees can only access data that's required for their jobs. As part of the review, agencies have been asked to implement restrictions on the availability and use of removable media on classified government networks.
The OMB and the Office of the Director of National Intelligence and the Information Security Oversight Office will assist agencies in reviewing security practices, the directive added.
Any failure by agencies to safeguard classified information "is unacceptable and will not be tolerated," the memo stated. "Any unauthorized disclosure of classified information is a violation of our law and compromises our national security."
The OMB directive does not offer specific deadlines for completing the reviews and implementing new procedures.
The directive follows WikiLeaks' release of tens of thousands of leaked U.S. Department of State cables on Sunday.
The cables reveal sensitive and what government officials call potentially damaging information on U.S. diplomatic activities in dozens of countries. The documents also revealed more data on the attacks against Google this year.
WikiLeaks claims that it has a cache of more than 250,000 State Department cables, and plans to release them in batches over the next few months. The release of the initial set of documents yesterday provoked intense criticism from U.S. officials as well as from governments around the world.
Peter King (R-NY), ranking member of the Committee on Homeland Security, yesterday called on Attorney General Eric Holder to label WikiLeaks a terrorist organization and to prosecute its founder, Julian Assange, under the Espionage Act.
This is the second time this year that WikiLeaks has released sensitive documents on such a massive scale.
In July, the site released close to 90,000 sensitive documents relating to the wars in Afghanistan and Iraq. That disclosure led Defense Secretary Robert Gates to order all military agencies to review their information security practices.
Bradley Manning, an Army intelligence analyst who has already been accused of supplying WikiLeaks with a video allegedly showing a deadly U.S Apache helicopter attack in Iraq, is a prime suspect in the latest incident as well.
Bradley, who has been in solitary confinement for the past several months is alleged to have downloaded the documents and copied them onto removable thumb drives and rewritable CDs while stationed at a U.S. Army base in Iraq.
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at
@jaivijayan, or subscribe to Jaikumar's RSS feed
. His e-mail address is jvijayan@computerworld.com.
Data breaches
- N.J. mayor arrested on hacking, conspiracy charges
- Security researcher urges IT to keep up with SAP patches
- Anonymous claims it hacked a DOJ site
- Banking malware spies on victims by hijacking webcams, microphones, researchers say
- Utah CTO takes fall for data breach
- UNC Charlotte: 350,000 SSNs exposed in decade-long breach
- Twitter says many leaked passwords inaccurate, duplicates
- Hackers blackmail Belgian bank with threats to publish customer data
- Russian cybercriminals earned $4.5 billion in 2011
- Nissan, Under Armor report breaches of employee information
Read more about Security in Computerworld's Security Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts
