White House orders security review in wake of WikiLeaks disclosure
OMB calls on U.S. agency and department heads to evaluate procedures in place for protecting classified data
Computerworld - The release of thousands of pages of classified U.S. government information over the weekend by whistleblower Web site WikiLeaks prompted an order to all federal agencies by the White House Office of Management and Budget (OMB) to immediately review procedures in place for protecting sensitive data.
In a brief directive issued Sunday, OMB director Jacob Lew called on the heads of all federal agencies and departments to establish special security assessment teams to conduct the reviews. Each team should include counterintelligence experts as well as security and information assurance experts, the directive noted.
Lew's memo requires that each agency evaluate their specific security measures for restricting access to classified government systems.
The directive also orders agency heads to ensure that employees can only access data that's required for their jobs. As part of the review, agencies have been asked to implement restrictions on the availability and use of removable media on classified government networks.
The OMB and the Office of the Director of National Intelligence and the Information Security Oversight Office will assist agencies in reviewing security practices, the directive added.
Any failure by agencies to safeguard classified information "is unacceptable and will not be tolerated," the memo stated. "Any unauthorized disclosure of classified information is a violation of our law and compromises our national security."
The OMB directive does not offer specific deadlines for completing the reviews and implementing new procedures.
The directive follows WikiLeaks' release of tens of thousands of leaked U.S. Department of State cables on Sunday.
The cables reveal sensitive and what government officials call potentially damaging information on U.S. diplomatic activities in dozens of countries. The documents also revealed more data on the attacks against Google this year.
WikiLeaks claims that it has a cache of more than 250,000 State Department cables, and plans to release them in batches over the next few months. The release of the initial set of documents yesterday provoked intense criticism from U.S. officials as well as from governments around the world.
Peter King (R-NY), ranking member of the Committee on Homeland Security, yesterday called on Attorney General Eric Holder to label WikiLeaks a terrorist organization and to prosecute its founder, Julian Assange, under the Espionage Act.
This is the second time this year that WikiLeaks has released sensitive documents on such a massive scale.
In July, the site released close to 90,000 sensitive documents relating to the wars in Afghanistan and Iraq. That disclosure led Defense Secretary Robert Gates to order all military agencies to review their information security practices.
Bradley Manning, an Army intelligence analyst who has already been accused of supplying WikiLeaks with a video allegedly showing a deadly U.S Apache helicopter attack in Iraq, is a prime suspect in the latest incident as well.
Bradley, who has been in solitary confinement for the past several months is alleged to have downloaded the documents and copied them onto removable thumb drives and rewritable CDs while stationed at a U.S. Army base in Iraq.
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan, or subscribe to Jaikumar's RSS feed . His e-mail address is email@example.com.
- Web apps and point-of-sale were leading hacker targets in 2013, says Verizon
- Michaels breach exposes nearly 3M payment cards
- Teen nabbed in Heartbleed attack against Canadian tax site
- Heartbleed bug can expose private server encryption keys
- FTC can sue companies hit with data breaches, court says
- 5-year-old hacks Xbox, now he's a Microsoft 'security researcher'
- State AGs probe Experian subsidiary's data breach
- NSA sniffing prompts Yahoo to encrypt traffic between its data centers
- Banks withdraw data breach claim against Target
- Bank abandons place in class-action suit against Target, Trustwave
Read more about Security in Computerworld's Security Topic Center.
- Silicon Valley's 19 Coolest Places to Work
- Is Windows 8 Development Worth the Trouble?
- 8 Books Every IT Leader Should Read This Year
- 10 Hot Hadoop Startups to Watch
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts