Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

11/1/2013
09:05 AM
50%
50%

Senate Bill Proposes Random Audits Of Security Clearances

Legislation would scour public and commercial databases for signs of trouble among federal workers holding security clearances.

5 Army Tech Innovations To Watch
5 Army Tech Innovations To Watch
(click image for larger view)
Senate lawmakers have introduced legislation aimed at strengthening the government's security clearance process using automated data searches. The legislation would task the Office of Personnel Management (OPM) to set up an automated review process that would search public records and databases for information on every individual who holds a security clearance, at random intervals, but at least twice every five years.

The Enhanced Security Clearance Act of 2013 was introduced by Senators Claire McCaskill (D-Mo.), Susan Collins (R-Maine), Heidi Heitkamp (D-N.D.), and Kelly Ayotte (R-N.H.) in response to classified information leaks by former NSA contractor Edward Snowden and the September shootings at the Navy Yard by a contractor.

If enacted, the new legislation would expand on a database of employees and contractors, established by the Intelligence Reform and Terrorism Prevention Act of 2004 (IRTPA), which identifies individuals who require access to classified information. OPM would be responsible for auditing the records of security clearance holders. It would use automated tools to search for information that would be added to the database, gleaned from a variety of sources, including government records, major consumer reporting agencies, publicly available and commercial data sources, and social media.

The information to be gathered would include everything from bankruptcy proceedings, lien filings, mortgage fraud and "high-value assets ... obtained by the covered individual from an unknown source." It would also catalog public information such as news stories and look for derogatory information posted to social media websites that "may suggest ill intent, vulnerability to blackmail, compulsive behavior, allegiance to another country or change in ideology" of the individual, according to the bill.

[ It looks like there's good reason for this bill. See Think Hackers Are IT's Biggest Threat? Guess Again. ]

"There are systemic failures in the current process that are jeopardizing our ability to protect our nation's secrets and our secure facilities," McCaskill said in a press release. "Senator Collins and I aren't ones to identify a problem and just talk about it – we are determined to offer concrete solutions, and that's what this bill is all about."

McCaskill is chair of the Homeland Security and Government Affairs subcommittee on financial and contracting oversight, and a senior member of the Senate Armed Services Committee. Collins serves on the Senate Intelligence Committee, and Heitkamp and Ayotte both hold seats on the Homeland Security Committee.

A number of law enforcement, professional and corporate associations have endorsed the legislation, including the Federal Managers Association, the International Association of Chiefs of Police, and the technology industry trade association TechAmerica.

"This legislation is a critical step forward in updating the security clearance process that must reflect not only the current environment, but also the many technological advances that are available to those maintaining our nation's security," said Trey Hodgkins, TechAmerica senior VP, Global Public Sector, in a statement and in letters of support sent to all four senators.

"Industry agrees that when someone applies to be considered for a position of trust, whether contractor or government employee, that a thorough examination of their past and present activities, including their digital and paper trails, is in all of our best interests."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Ramon S
50%
50%
Ramon S,
User Rank: Apprentice
11/2/2013 | 12:15:24 PM
re: Senate Bill Proposes Random Audits Of Security Clearances
Too bad and clearly not in the interest of the public. What we need is a bill that encourages more workers with security clearances to come forward in a responsible way as Snowden did. If anything Snowden's disclosures improve US security by reigning in the NSA and others before even more distrust towards the US is generated.
Sadly, those people who run this country have no clue and no interest to protect the USA and its residents.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/30/2020
'Act of War' Clause Could Nix Cyber Insurance Payouts
Robert Lemos, Contributing Writer,  10/29/2020
6 Ways Passwords Fail Basic Security Tests
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/28/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How to Measure and Reduce Cybersecurity Risk in Your Organization
In this Tech Digest, we examine the difficult practice of measuring cyber-risk that has long been an elusive target for enterprises. Download it today!
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27652
PUBLISHED: 2020-10-29
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
CVE-2020-27653
PUBLISHED: 2020-10-29
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
CVE-2020-27654
PUBLISHED: 2020-10-29
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp.
CVE-2020-27655
PUBLISHED: 2020-10-29
Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.
CVE-2020-27656
PUBLISHED: 2020-10-29
Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.