Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Organizations of All Sizes Need IT Security & Privacy Training | Main | First HIPAA Sanction Applied! $100,000 + Required Actions »

Insider Threat Example: San Fran IT Employee Exploits Poor Security Practices

Okay, why would a large city like San Francisco make such a silly, preventable mistake like allowing one employee to be able to establish a super user type of account and then lock everyone else out of the government network?

"Hacker Holds Key to City's Network: An Alleged Hacker Won't Reveal Secret Password to Unlock San Francisco's Network"

The headline is completely misleading. This was not a "hacker"...this employee was a network administrator who was "instrumental in designing the router system for the city's FiberWAN (wide-area network)." The alleged "hacker," Terry Childs, had authorized access to the network. He used that authorized access to install and implement ways to access the other areas of the network, and data, to which he did not previously have access.

He then reportedly created a new account and password to "most of the city's municipal data" and removed the network and data access capabilities from everyone else, including all the city employees who need to use the network to process business.

The statements of Mayor Newsom and Childs' lawyer Mark Jacobs provided in the article are quite silly.

The focus was on Childs, but what about San Francisco's information security program? Do they even have one? Don't they have policies, procedures and tools in place to catch the type of tampering that Childs did?

Sounds like Childs knew there were not good controls, and what sounds like no effective separation of duties, monitoring or logging, in place, and he decided to exploit those vulnerabilities and lax security practices after a reported "misunderstanding" with his supervisor.

Without having any of the details of the exploit, it would seem simple logging and monitoring by the internal auditing and/or information security department, would have caught right away the inappropriate changes that Childs reportedly made. And better network controls would probably have prevented it altogether.

"While in jail, he remains on the city payroll, reportedly earning $127,735 a year."

Nice salary! Rebuilding the network (as the article indicates is being done) will cost much more.

Implementing effective information security controls to begin with would have been MUCH less costly!

Wonder if the San Francisco government office will learn a costly lesson from this, or if it will just end up being costly?

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/766

Comments

All I can say is WOW! It is hard to believe this actually has happened since I am sure there is more than one movie out of Hollywood focusing on this issue. It will be interesting to see how this turns out. Have a great day and thanks for sharing!

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.