What is your e-mail address?

My e-mail address is:

Do you have a password?

Forgot your password? Click here
close

FAA will use software to identify sensitive data

The Federal Aviation Administration (FAA) plans to implement software designed to look for personally identifiable information in computer systems so the agency can have a more thorough inventory of its sensitive data, a FAA senior official has said.

A recent data breach at the FAA demonstrated how difficult it is for agencies with large infrastructures to know where all their sensitive data is and to assure its security, Dave Bowen, the FAA’s chief information officer, said Feb. 24 after a presentation at an industry event sponsored by TechAmerica.

Earlier this month, a hacker broke into an FAA computer server and stole the information from 48 files, two of which contained the personally identifiable information of 45,000 employees and retirees. The server probably had been used for testing purposes some time ago and had never been cleaned off, he said.

“We recognize that this is a problem, and we’re taking steps to remediate it," Bowen said. "We are going to be looking aggressively across our entire infrastructure. This file was just sitting out there; it didn’t really relate to a system."

Bowen added that using certification and accreditation (C&A) of computer systems to ensure they are secure would not have necessarily flagged the sensitive data. C&A is a process for evaluating system security compliance and risk management under the Federal Information Security Management Act.

The FAA will acquire a crawler-type of application that identifies personally identifiable information across the agency’s infrastructure, Bowen said. Then, the agency's CIO staff members can determine if the data is adequately protected, if it is necessary, or dispose of it appropriately if it is not necessary.

“Obviously, the situation has caught the attention of our senior executives, and I’m going to be briefing them on lessons learned,” he said. Law enforcement authorities continue to investigate the data theft, Bowen also said.

About the Author

Mary Mosquera is a reporter for Federal Computer Week.

Reader comments

Thu, Feb 26, 2009

wonder if the crawler they will use is able to find sensitive information in documents like Word, Excel, Powerpoint.

Thu, Feb 26, 2009

Does anyone know which system/program was hacked in to?

Thu, Feb 26, 2009 Loudoun Data Systems

Good proactive approach, however, I do agree with Data Geek, EXPECTATION should be defined and tested thoroughly. How about the systems managed by FAA Contractors?

Thu, Feb 26, 2009

I agree with Data Geek's comment. But I would like them to take it one step further: have all potential vendors participate in a pilot demonstration of their solution and add the performance evaluation in the pilot phase into the overall vendor evaluation before awarding a contract. In other words, a functioning pilot demonstration would be a requirement of the Request for Proposal.

Thu, Feb 26, 2009 Data Geek Texas

This sounds good, but how will they be able to distinguish between a personal cell phone number and a business cell phone number? Expectations should be clearly expressed before a lot of energy is focused in the wrong direction. Hopefully the desired objectives can be meet. A pilot should be conducted before a multi-million dollar purchase is made.

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Your Name:(optional)
Your Email:(optional)
Your Location:(optional)
Comment:
Please type the letters/numbers you see above

Editorial Webcasts

  • Service Consolidation: How to Avoid Basic Pitfalls of Shared Services Register Now

    This is the first webcast of the Series “Future First: Three Steps to Data Center Transformation”. Plan to attend this webcast to support your agency efforts to design a practical roadmap for consolidation of resources and shared services to meet current and emerging program demands. Learn from those who are doing to help you evaluate services in your current operations that may lend themselves to future shared service arrangements. Read more

Federal Computer Week eNewsletters

  • Subscribe to Newsletters Subscribe

    Federal Computer Week's eNewsletters deliver the latest policy and management news to your inbox.