Michael Cooney
Senior Editor

Study: Federal data security protection is deficient

Opinion
Jun 5, 20072 mins

A study released today say data on Federal PCs and laptops is still vulnerable to theft or loss a year after the officials handling the Veteran’s Administration laptop loss scandal promised improvements.

You may recall the laptop contained personal information including names, Social Security numbers, dates of birth and some limited health information of 26.5 million U.S. military veterans and their spouses. It was ultimately recovered. Key findings of the study:

* 13% of Federal employees do not have encryption on their newly-issued laptops.

* 41% of respondents note that they use a laptop for work. Out of these laptop users, 45% have switched to a laptop in the last year.

* 48% of respondents said that their agency provided training after the VA laptop scandal, and 47 percent of agencies provided updated encryption and protection technology on computers. Some 16% of respondents said their agencies had no reaction.

* 94% of teleworkers have received security training, compared to 87 % of non teleworkers, who work at the official workplace full time.

* This is where it gets tricky for many agencies: 58% of non teleworkers work at home on nights or weekends, unofficially. Out of these respondents who work at home, 63% use their own PCs and 54% of non teleworkers carry files home. Additionally, 41% log onto their agency’s network from home.

* 94% of survey respondents who are official teleworkers said they have antivirus software on their work computers. 75% of respondents who don’t officially telework said they had antivirus software on their work computers while 67%t of teleworkers said they had encryption on their work computers, while only 60% of non-teleworkers said they did.

“It was a sobering surprise that we found 13% of new workers don’t have encryption on their new laptops,” said Josh Wolfe, director of Federal sales for Utimaco, the security company that cospoonsored the study. “Since 2003 there have been 788 breaches of Federal data – the most significant was the VA loss – how many more don’t we even know about?” In the end the study concluded that U.S. agencies figure out who is teleworking and all employees, not just teleworkers, should receive cybersecurity training. They also recommended agencies should use encryption and other data security protections on all desktops and laptops. The survey, which polled 258 Federal employees in May, was conducted by the Telework Exchange, a teleworker advocacy group and the Utimaco