Monday, September 23

Audit discovers noteworthy security spaces in FBI’s storage media management

An audit from the Department of Justice’s Office of the Inspector General (OIG) determined “substantial weak points” in FBI’s stock management and disposal of electronic storage media consisting of delicate and classified details.

The report highlights numerous problems with policies and treatments or controls for tracking storage media drawn out from gadgets, and substantial physical security spaces in the media damage procedure.

The FBI has actually acknowledged these concerns and remains in the procedure of carrying out restorative actions based upon the suggestions from OIG.

OIG’s findings

OIG’s audit highlights numerous weak points in FBI’s stock management and disposal treatments for electronic storage media including delicate however unclassified (SBU) in addition to classified nationwide security info (NSI).

The 3 essential findings are summed up as follows:

  • The FBI does not sufficiently track or represent electronic storage media, such as internal hard disks and thumb drives, when they are drawn out from bigger gadgets, which increases the danger of these media being lost or taken.
  • The FBI stops working to regularly identify electronic storage media with the proper category levels (e.g., Secret, Top Secret), which might result in mishandling or unapproved access to delicate details.
  • The OIG likewise observed inadequate physical security at the FBI center where media damage takes place. This consists of insufficient internal gain access to controls, unsecured storage of media waiting for damage, and non-functioning security electronic cameras, all of which increase the threat of categorized info being jeopardized.

Pallet with storage gadgets exposed in FBI’s center
Source: OIG
Suggestions and FBI’s reaction

The OIG has actually made 3 particular suggestions to the FBI to resolve the determined issues.

  1. Modify treatments to guarantee all electronic storage media consisting of delicate or categorized details, consisting of hard disk drives that are drawn out from computer systems slated for damage, are properly represented, tracked, prompt sterilized, and damaged.
  2. Carry out controls to guarantee its electronic storage media are marked with the proper NSI category level markings, in accordance with appropriate policies and standards.
  3. Reinforce the control and practices for the physical security of its electronic storage media at the center to avoid loss or theft.

FBI acknowledged the audit’s findings and mentioned it remains in the procedure of establishing a brand-new instruction entitled “Physical Control and Destruction of Classified and Sensitive Electronic Devices and Material Policy Directive.”

This brand-new policy is anticipated to attend to the issues recognized in the storage media tracking and category markings.

Protective cages to be utilized in FBI storage centers
Source: OIG

Furthermore, the FBI stated it remains in the procedure of setting up protective “cages” to utilize as storage points for the media, which will be covered by video security.

OIG anticipates the FBI to upgrade it on the status of carrying out the restorative actions within 90 days.

ยป …
Find out more