Risk
11/1/2013
09:05 AM
50%
50%

Senate Bill Proposes Random Audits Of Security Clearances

Legislation would scour public and commercial databases for signs of trouble among federal workers holding security clearances.

5 Army Tech Innovations To Watch
5 Army Tech Innovations To Watch
(click image for larger view)
Senate lawmakers have introduced legislation aimed at strengthening the government's security clearance process using automated data searches. The legislation would task the Office of Personnel Management (OPM) to set up an automated review process that would search public records and databases for information on every individual who holds a security clearance, at random intervals, but at least twice every five years.

The Enhanced Security Clearance Act of 2013 was introduced by Senators Claire McCaskill (D-Mo.), Susan Collins (R-Maine), Heidi Heitkamp (D-N.D.), and Kelly Ayotte (R-N.H.) in response to classified information leaks by former NSA contractor Edward Snowden and the September shootings at the Navy Yard by a contractor.

If enacted, the new legislation would expand on a database of employees and contractors, established by the Intelligence Reform and Terrorism Prevention Act of 2004 (IRTPA), which identifies individuals who require access to classified information. OPM would be responsible for auditing the records of security clearance holders. It would use automated tools to search for information that would be added to the database, gleaned from a variety of sources, including government records, major consumer reporting agencies, publicly available and commercial data sources, and social media.

The information to be gathered would include everything from bankruptcy proceedings, lien filings, mortgage fraud and "high-value assets ... obtained by the covered individual from an unknown source." It would also catalog public information such as news stories and look for derogatory information posted to social media websites that "may suggest ill intent, vulnerability to blackmail, compulsive behavior, allegiance to another country or change in ideology" of the individual, according to the bill.

[ It looks like there's good reason for this bill. See Think Hackers Are IT's Biggest Threat? Guess Again. ]

"There are systemic failures in the current process that are jeopardizing our ability to protect our nation's secrets and our secure facilities," McCaskill said in a press release. "Senator Collins and I aren't ones to identify a problem and just talk about it – we are determined to offer concrete solutions, and that's what this bill is all about."

McCaskill is chair of the Homeland Security and Government Affairs subcommittee on financial and contracting oversight, and a senior member of the Senate Armed Services Committee. Collins serves on the Senate Intelligence Committee, and Heitkamp and Ayotte both hold seats on the Homeland Security Committee.

A number of law enforcement, professional and corporate associations have endorsed the legislation, including the Federal Managers Association, the International Association of Chiefs of Police, and the technology industry trade association TechAmerica.

"This legislation is a critical step forward in updating the security clearance process that must reflect not only the current environment, but also the many technological advances that are available to those maintaining our nation's security," said Trey Hodgkins, TechAmerica senior VP, Global Public Sector, in a statement and in letters of support sent to all four senators.

"Industry agrees that when someone applies to be considered for a position of trust, whether contractor or government employee, that a thorough examination of their past and present activities, including their digital and paper trails, is in all of our best interests."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Ramon S
50%
50%
Ramon S,
User Rank: Apprentice
11/2/2013 | 12:15:24 PM
re: Senate Bill Proposes Random Audits Of Security Clearances
Too bad and clearly not in the interest of the public. What we need is a bill that encourages more workers with security clearances to come forward in a responsible way as Snowden did. If anything Snowden's disclosures improve US security by reigning in the NSA and others before even more distrust towards the US is generated.
Sadly, those people who run this country have no clue and no interest to protect the USA and its residents.
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: " I think Google Doodle is getting a little out of control"
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] Assessing Cybersecurity Risk
[Strategic Security Report] Assessing Cybersecurity Risk
As cyber attackers become more sophisticated and enterprise defenses become more complex, many enterprises are faced with a complicated question: what is the risk of an IT security breach? This report delivers insight on how today's enterprises evaluate the risks they face. This report also offers a look at security professionals' concerns about a wide variety of threats, including cloud security, mobile security, and the Internet of Things.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.