TOPICS
TOPICS
Management structure contributed to VA data breach, observers say
As the scope of the Veterans Affairs Department's data breach continues to expand, former agency information technology officials say the catastrophe possibly could have been avoided with a better IT management structure.
Robert McFarland, who stepped down as the VA's chief information officer before the May 3 theft of sensitive records from a VA career IT specialist's home, said the database containing the personal information on veterans and active duty military personnel fell outside the direct control of the CIO office.
This setup, in which the department's IT systems and databases are dispersed across its three divisions, is on schedule to be changed, McFarland said, though that won't happen overnight.
"You have these databases out there without any access controls or notifications for when duplications are made ... access is free and open," he said. "As bad a hit as the agency is taking right now, it is moving in the right direction."
Technology management at the VA has been a source of contention on Capitol Hill and within the department.
The department's "federated" IT management model, adopted last year, gives the CIO office line-item budget control, but critics, including House Veterans Affairs Committee Chairman Steve Buyer, R-Ind., argue that the department needs to move toward a "centralized model."
Bruce Brody, vice president for information security at the Reston, Va-based market research firm INPUT and associate deputy assistant secretary for cyber and information security at the VA from 2001 to 2004, said during his time, the CIO office could issue agencywide policies but lacked enforcement power.
"He had no authority," Brody said. "He could not shut down systems or cut off funds. If you centralize authority, at least for security, there is a better chance you will get a handle on this stuff."
But Brody said the data breach is being treated more as a physical security issue than a cybersecurity problem, because the employee walked out of the agency's offices with the data. According to the VA, the employee had been taking sensitive records home unauthorized for three years.
The House Government Reform Committee is scheduled to hear testimony from VA Secretary James Nicholson and other government officials Thursday regarding the security of personal data in the government.
Committee Staff Director Dave Marin said Rep. Tom Davis, R-Va., chairman of the panel, is troubled that information from the VA on the content of the data continues to evolve.
A chronology of the data breach obtained by Government Executive shows that Michael H. McLendon, deputy assistant secretary for policy, who resigned last week, knew of the incident less than an hour after the GS-14 employee discovered the break-in. The employee immediately notified his office of the possible data loss, which then notified McLendon.
Nicholson was not notified until nearly two weeks later, on May 16. Veterans and lawmakers were informed of the breach on May 22.
While the VA has received approval to shift $25 million from its fiscal 2006 funding to support a toll-free number for veterans to call for information, the overall cost of the breach is likely to rise.
Vietnam Veterans of America, along with four other national veteran organizations and several individual veterans, has filed a class-action lawsuit that seeks a $1,000 award for each veteran who can show harm due to the breach. VA officials said Tuesday there are no indications that the stolen information has been used to commit identity theft.
The suit, filed in the U.S. District Court for the District of Columbia, seeks an injunction that would prevent VA from altering any data storage system and prohibit use of any such system until a court-appointed panel of experts determines how to implement adequate safeguards.
COMMENTS
- Fred, They are taking all possible steps, just ask them! Keep asking them and keep asking them until you get an answer that satisfies you. They are doing nothing because no one keeps hounding them about what they are doing. I work in DoD and totally agree with Robert M. DoD management is bad because most of the management positions are filled by military to provide a place to house high priced officers that really have no management skills or desires. Also they change jobs so frequently that they never have to live with the problems they generate from their actions or lack of actions. They treat civilians as military and wonder why the civilians revolt. They do whatever the general in charge (and a general always is in charge, wants done and this even will get worse under the new evaluation methodology for pay determination). There will be no improvement in DoD management (and that includes all the services) unless and until the managers become long-term qualified individuals and not two year military wonders. There is little management in DoD and its subs and there is likely not going to be for a long time. Taxpayer Posted June 12, 2006 7:38 AM
- 1. Has anyone ever said why the VA employee took the information home? 2. Has anyone ever said how long this employee had been doing so? 3. Has anyone ever said how many others had being doing the same? I would venture to guess that it probably had something to do with the older employee's age and/or the lack of staff by the VA. The VA has increasingly had to absorb costs into their yearly budgets and do more with decreasing numbers of employees. Maybe this employee wasn't able to accomplish all of his work at work and had to take work home. Don't get me wrong, there is still a lot of waste and potential savings within the VA and management is still the problem. There are way too many inept people being hired and way too many inept people being promoted on the basis of who they know. Even promoting veterans first is a joke. Will it ever change? No ... because the people who can make the changes don't want to! GovExec.com reader Posted June 12, 2006 7:49 AM
- The military services used to and may still safeguard sensitive unclassified information to protect it from use to construct classified intelligence data. 26 million personnel records with sensitive personal data certainly falls into this category. I received my letter from the Department of Veterans Affairs yesterday. It didn't tell me anything I didn't already know about protecting myself from identity theft. The letter said "the VA was taking all possible steps to protect veterans." When I called the hotline to ask what they were doing to protect veterans they didn’t know. This is the third time in 12 months that some agency or organization has lost my personal data. What is the federal government doing at a national level to close the loopholes in all its agencies? Fred Hyatt Posted June 8, 2006 9:16 AM
PROMO RIGHT: GBC
Advancing the business of government through analysis, insight and the sharing of best practices.
SPONSORED RESEARCH
Achieving a Greener Federal Government IBM
Federal Cybersecurity: Securing the Nation's Information IBM
American Recovery and Reinvestment Act: New Requirements for Tracking and Reporting Federal Workforce Data Kronos
Managing the Stimulus: A Candid Survey of Federal Program Managers Accenture and Microsoft
Improving Collaboration and Productivity in 21st Century Government: The Role of Communication for Government Executives Cisco









