The Ostrich Maneuver: Burying bad news is a bad idea

Opinion
Sep 12, 20063 mins

* Department of Defense's reaction to bad news

One of the important steps in any information systems incident response plan is public relations. How will your organization cope with unfavorable news? Will you delay responses to legitimate questions? Suppress the truth? Outright lie? Or will you focus on clear, timely answers to the questions, constructive responses and a timetable for correcting the problem?

Bob Brewin reported in Federal Computer Week on March 16 about Report No. D-2006-053 from the U.S. Department of Defense Office of the Inspector General. He wrote that:

“The network that stitches together radars, missile launch sites and command control centers for the Missile Defense Agency (MDA) ground-based defense system has such serious security flaws that the agency and its contractor, Boeing, may not be able to prevent misuse of the system, according to a Defense Department Inspector General’s report.”

The results section of the report’s Executive Summary says:

“Missile Defense Agency officials had not prepared a System Security Authorization Agreement for the Ground-Based Midcourse Defense Communications Network. Additionally, available security documentation did not properly reflect current operations of the network. Missile Defense Agency officials also had not fully implemented information assurance controls required to protect the integrity, availability, and confidentiality of information in the Ground-Based Midcourse Defense Communications Network… Further, a Plan of Action and Milestones designed to assist managers in correcting security weaknesses had not been prepared. As a result, Missile Defense Agency officials may not be able to reduce the risk and extent of harm resulting from misuse or unauthorized access to or modification of information of the Ground-Based Midcourse Defense Communications Network and ensure the continuity of the network in the event of a disruption.”

The report was removed from its original government Web site shortly after publication of the news story. When I wrote my first draft of this article in June, I was unable to locate it anywhere other than in the mirrored version cited above despite a diligent search. I am relieved to report that it is currently available for download here.

I think that all of us responsible for system security of any kind must be prepared to handle negative audit results. I’m relieved that the Department of Defense chose to make the Inspector General’s report – a non-classified, public-domain document that we taxpayers paid for – public after all. Let’s all make that approach our own standard for dealing with bad news.