Risk
11/1/2013
09:05 AM
50%
50%

Senate Bill Proposes Random Audits Of Security Clearances

Legislation would scour public and commercial databases for signs of trouble among federal workers holding security clearances.

5 Army Tech Innovations To Watch
5 Army Tech Innovations To Watch
(click image for larger view)
Senate lawmakers have introduced legislation aimed at strengthening the government's security clearance process using automated data searches. The legislation would task the Office of Personnel Management (OPM) to set up an automated review process that would search public records and databases for information on every individual who holds a security clearance, at random intervals, but at least twice every five years.

The Enhanced Security Clearance Act of 2013 was introduced by Senators Claire McCaskill (D-Mo.), Susan Collins (R-Maine), Heidi Heitkamp (D-N.D.), and Kelly Ayotte (R-N.H.) in response to classified information leaks by former NSA contractor Edward Snowden and the September shootings at the Navy Yard by a contractor.

If enacted, the new legislation would expand on a database of employees and contractors, established by the Intelligence Reform and Terrorism Prevention Act of 2004 (IRTPA), which identifies individuals who require access to classified information. OPM would be responsible for auditing the records of security clearance holders. It would use automated tools to search for information that would be added to the database, gleaned from a variety of sources, including government records, major consumer reporting agencies, publicly available and commercial data sources, and social media.

The information to be gathered would include everything from bankruptcy proceedings, lien filings, mortgage fraud and "high-value assets ... obtained by the covered individual from an unknown source." It would also catalog public information such as news stories and look for derogatory information posted to social media websites that "may suggest ill intent, vulnerability to blackmail, compulsive behavior, allegiance to another country or change in ideology" of the individual, according to the bill.

[ It looks like there's good reason for this bill. See Think Hackers Are IT's Biggest Threat? Guess Again. ]

"There are systemic failures in the current process that are jeopardizing our ability to protect our nation's secrets and our secure facilities," McCaskill said in a press release. "Senator Collins and I aren't ones to identify a problem and just talk about it – we are determined to offer concrete solutions, and that's what this bill is all about."

McCaskill is chair of the Homeland Security and Government Affairs subcommittee on financial and contracting oversight, and a senior member of the Senate Armed Services Committee. Collins serves on the Senate Intelligence Committee, and Heitkamp and Ayotte both hold seats on the Homeland Security Committee.

A number of law enforcement, professional and corporate associations have endorsed the legislation, including the Federal Managers Association, the International Association of Chiefs of Police, and the technology industry trade association TechAmerica.

"This legislation is a critical step forward in updating the security clearance process that must reflect not only the current environment, but also the many technological advances that are available to those maintaining our nation's security," said Trey Hodgkins, TechAmerica senior VP, Global Public Sector, in a statement and in letters of support sent to all four senators.

"Industry agrees that when someone applies to be considered for a position of trust, whether contractor or government employee, that a thorough examination of their past and present activities, including their digital and paper trails, is in all of our best interests."

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Ramon S
50%
50%
Ramon S,
User Rank: Apprentice
11/2/2013 | 12:15:24 PM
re: Senate Bill Proposes Random Audits Of Security Clearances
Too bad and clearly not in the interest of the public. What we need is a bill that encourages more workers with security clearances to come forward in a responsible way as Snowden did. If anything Snowden's disclosures improve US security by reigning in the NSA and others before even more distrust towards the US is generated.
Sadly, those people who run this country have no clue and no interest to protect the USA and its residents.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-2184
Published: 2015-03-27
Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.

CVE-2014-3619
Published: 2015-03-27
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.

CVE-2014-8121
Published: 2015-03-27
DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up while the database is iterated over...

CVE-2014-9712
Published: 2015-03-27
Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 and 7.8.4 before Hotfix 01 allows remote administrators to read arbitrary files and obtain passwords via a crafted path.

CVE-2015-0658
Published: 2015-03-27
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.