Risk
11/1/2013
09:05 AM
Connect Directly
RSS
E-Mail
50%
50%

Senate Bill Proposes Random Audits Of Security Clearances

Legislation would scour public and commercial databases for signs of trouble among federal workers holding security clearances.

5 Army Tech Innovations To Watch
5 Army Tech Innovations To Watch
(click image for larger view)
Senate lawmakers have introduced legislation aimed at strengthening the government's security clearance process using automated data searches. The legislation would task the Office of Personnel Management (OPM) to set up an automated review process that would search public records and databases for information on every individual who holds a security clearance, at random intervals, but at least twice every five years.

The Enhanced Security Clearance Act of 2013 was introduced by Senators Claire McCaskill (D-Mo.), Susan Collins (R-Maine), Heidi Heitkamp (D-N.D.), and Kelly Ayotte (R-N.H.) in response to classified information leaks by former NSA contractor Edward Snowden and the September shootings at the Navy Yard by a contractor.

If enacted, the new legislation would expand on a database of employees and contractors, established by the Intelligence Reform and Terrorism Prevention Act of 2004 (IRTPA), which identifies individuals who require access to classified information. OPM would be responsible for auditing the records of security clearance holders. It would use automated tools to search for information that would be added to the database, gleaned from a variety of sources, including government records, major consumer reporting agencies, publicly available and commercial data sources, and social media.

The information to be gathered would include everything from bankruptcy proceedings, lien filings, mortgage fraud and "high-value assets ... obtained by the covered individual from an unknown source." It would also catalog public information such as news stories and look for derogatory information posted to social media websites that "may suggest ill intent, vulnerability to blackmail, compulsive behavior, allegiance to another country or change in ideology" of the individual, according to the bill.

[ It looks like there's good reason for this bill. See Think Hackers Are IT's Biggest Threat? Guess Again. ]

"There are systemic failures in the current process that are jeopardizing our ability to protect our nation's secrets and our secure facilities," McCaskill said in a press release. "Senator Collins and I aren't ones to identify a problem and just talk about it – we are determined to offer concrete solutions, and that's what this bill is all about."

McCaskill is chair of the Homeland Security and Government Affairs subcommittee on financial and contracting oversight, and a senior member of the Senate Armed Services Committee. Collins serves on the Senate Intelligence Committee, and Heitkamp and Ayotte both hold seats on the Homeland Security Committee.

A number of law enforcement, professional and corporate associations have endorsed the legislation, including the Federal Managers Association, the International Association of Chiefs of Police, and the technology industry trade association TechAmerica.

"This legislation is a critical step forward in updating the security clearance process that must reflect not only the current environment, but also the many technological advances that are available to those maintaining our nation's security," said Trey Hodgkins, TechAmerica senior VP, Global Public Sector, in a statement and in letters of support sent to all four senators.

"Industry agrees that when someone applies to be considered for a position of trust, whether contractor or government employee, that a thorough examination of their past and present activities, including their digital and paper trails, is in all of our best interests."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Ramon S
50%
50%
Ramon S,
User Rank: Apprentice
11/2/2013 | 12:15:24 PM
re: Senate Bill Proposes Random Audits Of Security Clearances
Too bad and clearly not in the interest of the public. What we need is a bill that encourages more workers with security clearances to come forward in a responsible way as Snowden did. If anything Snowden's disclosures improve US security by reigning in the NSA and others before even more distrust towards the US is generated.
Sadly, those people who run this country have no clue and no interest to protect the USA and its residents.
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6117
Published: 2014-07-11
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.

CVE-2014-0174
Published: 2014-07-11
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVE-2014-3485
Published: 2014-07-11
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.

CVE-2014-3499
Published: 2014-07-11
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.

CVE-2014-3503
Published: 2014-07-11
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.