White House orders security review in wake of WikiLeaks disclosure
OMB calls on U.S. agency and department heads to evaluate procedures in place for protecting classified data
Computerworld - The release of thousands of pages of classified U.S. government information over the weekend by whistleblower Web site WikiLeaks prompted an order to all federal agencies by the White House Office of Management and Budget (OMB) to immediately review procedures in place for protecting sensitive data.
In a brief directive issued Sunday, OMB director Jacob Lew called on the heads of all federal agencies and departments to establish special security assessment teams to conduct the reviews. Each team should include counterintelligence experts as well as security and information assurance experts, the directive noted.
Lew's memo requires that each agency evaluate their specific security measures for restricting access to classified government systems.
The directive also orders agency heads to ensure that employees can only access data that's required for their jobs. As part of the review, agencies have been asked to implement restrictions on the availability and use of removable media on classified government networks.
The OMB and the Office of the Director of National Intelligence and the Information Security Oversight Office will assist agencies in reviewing security practices, the directive added.
Any failure by agencies to safeguard classified information "is unacceptable and will not be tolerated," the memo stated. "Any unauthorized disclosure of classified information is a violation of our law and compromises our national security."
The OMB directive does not offer specific deadlines for completing the reviews and implementing new procedures.
The directive follows WikiLeaks' release of tens of thousands of leaked U.S. Department of State cables on Sunday.
The cables reveal sensitive and what government officials call potentially damaging information on U.S. diplomatic activities in dozens of countries. The documents also revealed more data on the attacks against Google this year.
WikiLeaks claims that it has a cache of more than 250,000 State Department cables, and plans to release them in batches over the next few months. The release of the initial set of documents yesterday provoked intense criticism from U.S. officials as well as from governments around the world.
Peter King (R-NY), ranking member of the Committee on Homeland Security, yesterday called on Attorney General Eric Holder to label WikiLeaks a terrorist organization and to prosecute its founder, Julian Assange, under the Espionage Act.
This is the second time this year that WikiLeaks has released sensitive documents on such a massive scale.
In July, the site released close to 90,000 sensitive documents relating to the wars in Afghanistan and Iraq. That disclosure led Defense Secretary Robert Gates to order all military agencies to review their information security practices.
Bradley Manning, an Army intelligence analyst who has already been accused of supplying WikiLeaks with a video allegedly showing a deadly U.S Apache helicopter attack in Iraq, is a prime suspect in the latest incident as well.
Bradley, who has been in solitary confinement for the past several months is alleged to have downloaded the documents and copied them onto removable thumb drives and rewritable CDs while stationed at a U.S. Army base in Iraq.
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan, or subscribe to Jaikumar's RSS feed . His e-mail address is email@example.com.
- US agencies to release cyberthreat info faster to healthcare industry
- UPS now the third company in a week to disclose data breach
- Healthcare organizations still too lax on security
- Why would Chinese hackers want US hospital patient data?
- About 4.5M face risk of ID theft after hospital network hacked
- Supervalu breach shows why move to smartcards is long overdue
- Grocery stores in multiple states hit by data breach
- Update: Payment cards with chips aren't perfect, so encrypt everything, experts say
- U.S. agencies halt background checks by contractor after cyberattack
- Five unanswered questions about massive Russian hacker database
Read more about Security in Computerworld's Security Topic Center.
- Troubleshooting Common Issues in VoIP Learn more about Voice over Internet Protocol (VoIP), including common VoIP metrics used, best practices in VoIP management and tips and tricks for...
- 2013 Network Management Software (NMS) Buyers Guide This white paper contains an independent comparison study of six different network management solutions and provides guidance on how you can choose the...
- Rightsizing Your Network Performance Management Solution: 4 Case Studies This white paper discusses challenges encountered as organizations search for the most cost-effective network performance management solution.
- Global Growing Pains: Tapping into B2B Integration Services to Overcome Global Expansion Challenges A recent survey by IDG Research explored both the challenges and pain points companies face when growing globally, as well as the capabilities...
- E-Signature RFP Checklist Webcast If your organization is looking to adopt e-signatures, you may be overwhelmed by the number of providers that offer seemingly similar solutions. How...
- Cloud and Collaboration: Driving Your Business Value Mission Critical Cloud from Peer 1 Hosting is enterprise-grade. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!