VAgue promises of improvement

Opinion
Jun 19, 20072 mins

* More on the VA data theft saga

In this brief series of articles, I’ve been recounting the tale of data losses at the Department of Veterans Affairs (VA).

On June 14, 2006, Linda D. Koontz, Director, Information Management Issues and Gregory C. Wilshusen, Director, Information Security Issues of the Government Accountability Office of the United States offered testimony before the Committee on Veterans’ Affairs, House of Representatives. The GAO report on their analysis and recommendations later appeared as GAO-06-866. Highlights of their analysis included these comments:

“For many years, significant concerns have been raised about VA’s information security—particularly its lack of a robust information security program, which is vital to avoiding the compromise of government information, including sensitive personal information. Both GAO and the department’s inspector general have reported recurring weaknesses in such areas as access controls, physical security, and segregation of incompatible duties. The department has taken steps to address these weaknesses, but these have not been sufficient to establish a comprehensive information security program. For example, it is still developing plans to complete a security incident response program to monitor suspicious activity and cyber alerts, events, and incidents. Without an established and implemented security program, the department will continue to have major challenges in protecting its information and information systems from security breaches such as the one it recently experienced.” Two related reports appeared about a week later with specific comments about the May 2006 data breach (GAO-06-897T) and about the overall challenges facing the VA and the Department of Defense (DoD) in protecting personally-identifiable information (PII) of active-duty and retired military personnel (GAO-06-905T).

At the end of June 2006, the laptop and external hard drive stolen on May 3 from the consultant’s home were recovered. Forensic examination suggested that the data had not been accessed. This good news suggested that the disaster might blow over.

It was not to be.

The Inspector General (IG) of the VA, George Opfer, released a report on July 11 severely criticizing senior managers of the VA for their lackadaisical response to the original theft of unencrypted PII. The inadequate data security policies had not yet been corrected. VA Secretary James Nicholsen responded to the IG’s report with assurances that the agency had “embarked on a course of action to wholly improve its cyber and information security programs.”

More of this debacle in the next column.