Search DominoPower's 11,443 Lotus-related article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
U.S. government agencies' cyber-security and record-keeping worse than previously thought (continued)

If a federal agency isn't sure whether an email message is a "record" or not, Figure A shows a handy decision tree that can help make the determination.

FIGURE A


Government workers can use this decision tree for determining whether an email message is a record. Roll over picture for a larger image.

Although it initially seemed there were no "uh-oh" moments reading about the four agencies' record-keeping practices, none of them got it right:

Three of the four agencies we reviewed had policies in place that generally complied with key aspects of NARA's regulations on email records management. At these agencies, the policies were each missing one of nine key elements. For example, one agency's policy did not specify, as required, that draft documents circulated via email may be federal records; agency officials indicated that they planned to address the omission in updated guidance. At the fourth agency [HUD], the policy was missing three of eight applicable requirements.

Figure B contains a nice chart that showcases where things broke down.

FIGURE B


This GAO table shows how the various agencies conformed to required policy. Roll over picture for a larger image.

If you look carefully at the chart, you'll notice the last line item. That one says:

Instruct staff on the management and preservation of email messages sent or received from nongovernmental email systems

Uh-oh.

Security risk at the Department of Homeland Security
Sometimes it seems like it wouldn't be a report about government computer systems without discovering at least one new security risk of relatively major proportions.

"Employees can open the Pandora's box of trouble that's everyone's email account."

The folks at Homeland Security have a whopper of a security flaw. According to the GAO report:

...although employees can currently access Web-based and Internet-accessible private email systems, the department is taking steps to restrict or remove this access.

Let's understand this a little more clearly. Right now, Homeland Security employees can, from within their federal offices, surf the Web, getting email from such places as AOL, Hotmail, and Gmail.

The entire apocalypse-in-a-box that is the Internet is allowed to tunnel through all of Homeland Security's security because employees can open the Pandora's box of trouble that's everyone's email account on the net.

But, you say, the department is taking steps. Fair enough, but we all know our government. Those steps are likely to take four or more years. In the meantime, Osama bin Hacker can just as easily send a virus or a trojan into the Department of Homeland Security's "secured" private network as he can to you or me.

Security risk at Federal Trade Commission
And this leads us to the Federal Trade Commission. I wasn't going to write about them, but between the time I started writing report and the time I got this far into the document, I got another email, this time pointing me to a new Web page at the FTC.

The Federal Trade Commission is the nation's primary consumer protection body and is the lead arm of the government dealing with identity theft issues. The FBI investigates identity theft as a crime, but the FTC deals with it in terms of consumer protection and policy.


« Previous  ·  1  ·  2  ·  3  ·  4  ·  5  ·  Next »
Other articles you might like
Home > Lotus Community > Editorials (71 articles)
   Five trends for 2010
   Say goodbye to the Uh-Ohs. Long live the Tens.
   The editorial strikes back
Home > Strategies > Security (19 articles)
   Incident report: denial of service attack against ConnectedPhotographer.com
   Centralised email encryption at the Domino server level
   Analysis: Spying Chinese temptress steals senior Brit's BlackBerry
Home > Strategies > Legal Issues (12 articles)
   Analysis: Spying Chinese temptress steals senior Brit's BlackBerry
   When the email flood inundates the Domino Server
   An interview with Roger Matus on email archiving and retrieval
Home > Special Reports > White House email controversy (25 articles)
   Analysis: Spying Chinese temptress steals senior Brit's BlackBerry
   The White House email controversy: it's time for a Special Prosecutor
   The worrisome implications of the Mexican theft of White House BlackBerry devices
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent DominoPower Articles
Syncing Notes with Android phones
Application development, William Shatner, and the origin of the universe
Learn Domino Designer 8.5 for free
The (near) future of Sametime, Quickr, Connections, and Symphony
Inside the IBM Innovations lab
Lotusphere 2010: Hot fixes and cool news for Notes, Domino, and LotusLive
Lotusphere 2010: mobility and collaboration
Latest Lotus Headlines
Xpages not loading? JVM errors? - Solution
How to implement an iCalendar feed into your Notes calendar with XPages
DWA Hotfixes for Domino 8.5.1FP1 - A Gotcha
IBM Adds DB2 to Lotus Foundations SMB Package
SNTT : XPages onclick Ghosts in the machine
Ports used by Lotus Sametime 8.5 servers
Exploring a Domino Date Bug
>> Read all the news
More from the ZATZ journals
Computing Unplugged: Online safety for virtual learning
David Gewirtz Online: CNN commentary and analysis
OutlookPower: Seek and find: Strategies to locate filed-away emails fast
-- Advertisement --

Find unused Lotus Notes groups and clean up your address book
Have you ever wanted to get rid of old Lotus Notes groups that were cluttering up your address book, but you weren't sure if they were used? Find Unused Groups can help.

Find Unused Groups will check your ACL, mail, multi purpose and server groups to help you determine if they are used, and who uses them.

Learn how to easily clean up your address book.

-- Advertisement --

Mark your calendar for in-depth Lotus training, May 12-14, Boston
Join experts and peers May 12-14 in Boston for educational and networking events that deliver real-world Lotus training so you can increase productivity and efficiency in your company, advance your skills, and squeeze the most from your current environment. One registration gets you into THE VIEW's Admin2010 and Lotus Developer2010.

Register by April 10 to save $200.
ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Editor's Login