Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« The Emperors' New Clothes Lack Privacy | Main | Yet Another Stolen Laptop With Clear Text Patient PII »

Passport Breach: Poor Security Practices Lead To Privacy Breaches

The breach of the presidential candidates' passport files were widely reported over the past few days, such as here and here, not to mention the many postings referencing it as "passport-gate" throughout the blogosphere and the political implications. However, based upon what I've been reading it looks more like the result of a poor, inadequate and vulnerable information security program.

There are many information security and privacy issues involved with this incident. It would make a great case study to use at a joint meeting with your information security, privacy and compliance folks. Some of the questions to include in your discussion could include...

Why did the peeping personnel have access to the files? Did they have applications and/or systems authorization? Or, were they using someone else's account? Or, did the applications that controlled access to the passport files not have appropriate security built in?
It is reported the peepers were contract workers from Analysis Corp. of McLean, Va., and Stanley Inc., an Arlington, Va. Did the State Department contract require the workers to have appropriate training? Did the contracted company have information security policies as part of a comprehensive information assurance program? Did the State Department provide training to the contract workers prior to giving them access to the network and data?
Will the State Department cancel the contracts with Analysis Corp. and Stanley Inc.? Should they? Why or why not?
What groups of personnel should have access to the passport files? How is access authorization determined? Do policies exist, along with supporting procedures?
Why were a couple of the contractors fired, and the other was not? What problems could this inconsistent application of sanctions cause?
Hillary Clinton's file was accessed during a training session. Discuss the legal implications of using production data for test, development and training. Discuss what this case points out to be poor training practices.
The passport files reportedly contained date and place of birth, occupation, family status, physical characteristics, copies of birth or baptismal certificates, medical, personal and financial reports or arrest warrants, and the individual's Social Security number. Discuss the ways in which these types of information could be used maliciously. Think about not only how such information can be used maliciously for any individual, but also for individuals who are running for president.
The inappropriate access was flagged as a result of a "software system that alerts supervisors when files of a "high-profile person" are searched." Should such alerts be generated for all persons, not just for high-profile persons? Why or why not?
Shouldn't the personally identifiable information (PII) be encrypted in storage? If not, under what circumstances?
What safeguards should be considered to prevent this type of privacy breach?
What responsibilities should the State Deparment have for this privacy breach? Should they be sanctioned? In what ways?

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/688

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold, CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for the past two decades. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the world's best privacy experts and on their list of the best privacy consulting firms in both 2007 and 2008. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 13th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.