White House orders security review in wake of WikiLeaks disclosure
OMB calls on U.S. agency and department heads to evaluate procedures in place for protecting classified data
Computerworld - The release of thousands of pages of classified U.S. government information over the weekend by whistleblower Web site WikiLeaks prompted an order to all federal agencies by the White House Office of Management and Budget (OMB) to immediately review procedures in place for protecting sensitive data.
In a brief directive issued Sunday, OMB director Jacob Lew called on the heads of all federal agencies and departments to establish special security assessment teams to conduct the reviews. Each team should include counterintelligence experts as well as security and information assurance experts, the directive noted.
Lew's memo requires that each agency evaluate their specific security measures for restricting access to classified government systems.
The directive also orders agency heads to ensure that employees can only access data that's required for their jobs. As part of the review, agencies have been asked to implement restrictions on the availability and use of removable media on classified government networks.
The OMB and the Office of the Director of National Intelligence and the Information Security Oversight Office will assist agencies in reviewing security practices, the directive added.
Any failure by agencies to safeguard classified information "is unacceptable and will not be tolerated," the memo stated. "Any unauthorized disclosure of classified information is a violation of our law and compromises our national security."
The OMB directive does not offer specific deadlines for completing the reviews and implementing new procedures.
The directive follows WikiLeaks' release of tens of thousands of leaked U.S. Department of State cables on Sunday.
The cables reveal sensitive and what government officials call potentially damaging information on U.S. diplomatic activities in dozens of countries. The documents also revealed more data on the attacks against Google this year.
WikiLeaks claims that it has a cache of more than 250,000 State Department cables, and plans to release them in batches over the next few months. The release of the initial set of documents yesterday provoked intense criticism from U.S. officials as well as from governments around the world.
Peter King (R-NY), ranking member of the Committee on Homeland Security, yesterday called on Attorney General Eric Holder to label WikiLeaks a terrorist organization and to prosecute its founder, Julian Assange, under the Espionage Act.
This is the second time this year that WikiLeaks has released sensitive documents on such a massive scale.
In July, the site released close to 90,000 sensitive documents relating to the wars in Afghanistan and Iraq. That disclosure led Defense Secretary Robert Gates to order all military agencies to review their information security practices.
Bradley Manning, an Army intelligence analyst who has already been accused of supplying WikiLeaks with a video allegedly showing a deadly U.S Apache helicopter attack in Iraq, is a prime suspect in the latest incident as well.
Bradley, who has been in solitary confinement for the past several months is alleged to have downloaded the documents and copied them onto removable thumb drives and rewritable CDs while stationed at a U.S. Army base in Iraq.
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan, or subscribe to Jaikumar's RSS feed . His e-mail address is firstname.lastname@example.org.
- Hackers steal user data from the European Central Bank website, demand money
- Arrests made after international cyber-ring targets StubHub
- SQL injection flaw opens door for Wall Street Journal database hack
- Goodwill Industries probes possible payment card breach
- Aloha point-of-sale terminal, sold on eBay, yields security surprises
- The biggest data breaches of 2014 (so far)
- Blue Shield discloses 18,000 doctors' Social Security numbers
- PF Chang's says breach was 'highly sophisticated criminal operation'
- Breaches exposed 1 in 7 US debit cards in 2013
- New malware program targets banking data
Read more about Security in Computerworld's Security Topic Center.
- Enable secure remote access to 3D data without sacrificing visual perfomance Design and manufacturing companies must adapt quickly to the demands of an increasingly global and competitive economy. To speed time to market for...
- Virtually Delivered High Performance 3D Graphics "A picture is worth a thousand words." That old phrase is as true today as it ever was. Pictures (i.e., those with heavy...
- Best Practices for Securing Hadoop Historically, Apache Hadoop has provided limited security capabilities. To protect sensitive data being stored and analyzed in Hadoop, security architects should use a...
- Top Tips for Securing Big Data Environments: Why Big Data Doesn't Have to Mean Big Security Challenges Organizations must come to terms with the security challenges they introduce. As big data environments ingest more data, organizations will face significant risks...
- What should I look for in a Next Generation Firewall? SANS Provides Guidance With so many vendors claiming to have a Next Generation Firewall (NGFW), it can be difficult to tell what makes each one different....
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!