
WASHINGTON, July 3 (UPI) -- Despite several high-profile compromises of private information, the U.S. Department of Defense is not protecting personal data adequately, a report says.
Officials assigned to protect personal data like Social Security numbers and other records at the Defense Department usually are not specifically trained in the requirements of the 1974 Privacy Act.
Moreover, the military departments and agencies manage the data separately in a decentralized system. While a single Pentagon office is supposed to ensure compliance with the law, it has "failed to ensure that DOD consistently
implemented Privacy Program policy for reporting, collecting, using, safeguarding, and maintaining personal information."
That is the conclusion of a recent investigation by the Defense Department inspector general.
"The personal information contained in DOD systems could be vulnerable to access by unauthorized personnel and individuals identified in systems of records vulnerable to identify theft and fraudulent activities. Effective oversight and administration of the DOD Privacy Act program is contingent on the allocation of sufficient resources and establishment of internal control mechanisms to verify accomplishments of the program's intent," states the June 13 report.
In an electronic era where much of that information is stored on computers and networks, the potential for compromised data is significant. A year ago, a laptop and external hard drive belonging to the Veterans Affairs Department and containing millions of Social Security numbers and birthdates of veterans and military personnel was stolen. It was eventually recovered intact.
"Federal agencies have a special duty to protect personally identifiable information. The increased focus on privacy following information losses at numerous federal agencies has resulted in (the Office of Management and Budget) placing additional requirements on already thinly resourced DOD privacy program staff, and the current decentralized program cannot provide an effective response. DOD privacy officials do not consistently implement safeguards and policies for protecting personal privacy information as required by the Privacy Act, and component privacy officers do not oversee privacy programs within their components."
|
|
|
|
|
|
| Additional Security Industry Stories | |
BAGHDAD, May 31 (UPI) --
Iraq's fourth energy auction has flopped, denting hopes of challenging Saudi Arabia as the world's top producer.
|
THOUSAND OAKS, Calif., May 31 (UPI) --
Teledyne Technologies is boosting its acoustic sensor and communication device offerings with the acquisition of Washington's BlueView Technologies.
|
Inventories of bank-owned foreclosures for sale vary increasingly by state as the latest local data suggests that lenders are beginning to release a long-awaited wave of more than one million backlogged foreclosures, primarily in states where a court...
|
Behind the impulse in Europe to form eurobonds or collectively insure bank deposits is the fear that Spain will require a very expensive fix.
|
| Stories | Photos | People | Comments |
View Caption