IG faults Energy Department for not fully implementing HSPD-12

Energy has spent $15 million on implementation over 7 years

Despite seven years of effort and $15 million spent, the Energy Department has not fully implemented the physical and logical access controls required under “HSPD-12,” according to a new report from DOE Inspector General Gregory Friedman.

Energy also has not issued HSPD-12 credentials to many of the 40,000 contractor personnel at its five field sites, the report said.

Two of the field sites, Oak Ridge National Laboratory and the East Tennessee Technology Park, were partially done, and three others had not started yet.

Under HSPD-12 (Homeland Security Presidential Directive-12), federal agencies were required to establish credentialing systems for their workers and contractors for building access and also for access to computers and equipment.

The inspector general also said four of the field sites were failing to provide credentials to contractors who do not hold security clearances, which is contrary to the directive. All together, about 11,000 individuals without security clearances who require routine access to work sites for at least six months had not been issued their credentials as required, Friedman wrote in the report.

Friedman faulted the department for not providing effective guidance.

“We noted what we considered to be a lack of a coordinated approach among programs and sites related to implementation of HSPD-12 requirements,” Friedman wrote. “In particular, we found that guidance provided by management was fragmented and often inadequate to meet the goals of the initiative. In addition, ongoing efforts suffered from a lack of coordination among programs and sites to determine the cost, scope and schedule of work required to implement HSPD-12 requirements. Further, several programs and sites visited had not established budgets in anattempt to obtain funding to support HSPD-12 activities.”

The inspector general offered four recommendations for improvements, and Energy officials agreed with all of them.

However, the DOE managers noted that for certain contractors, such as construction workers restricted to certain areas who do not use data systems, providing an HSPD-12 credential is not cost effective.

The inspector general said while he generally supported that approach for low-risk situations such as this, it would be best to consult with the Office of Management and Budget on any deviations from the rules.

Writing in response to the report, Kenneth Powers, associate administrator for management and budget for the Nuclear Security Administration, noted that HSPD-12 mandate was not fully funded and that has contributed to delays in implementation.

About the Author

Alice Lipowicz is a staff writer covering government 2.0, homeland security and other IT policies for Federal Computer Week.

The Fed 100

Save the date for 28th annual Federal 100 Awards Gala.

Featured

  • computer network

    How Einstein changes the way government does business

    The Department of Commerce is revising its confidentiality agreement for statistical data survey respondents to reflect the fact that the Department of Homeland Security could see some of that data if it is captured by the Einstein system.

  • Defense Secretary Jim Mattis. Army photo by Monica King. Jan. 26, 2017.

    Mattis mulls consolidation in IT, cyber

    In a Feb. 17 memo, Defense Secretary Jim Mattis told senior leadership to establish teams to look for duplication across the armed services in business operations, including in IT and cybersecurity.

  • Image from Shutterstock.com

    DHS vague on rules for election aid, say states

    State election officials had more questions than answers after a Department of Homeland Security presentation on the designation of election systems as critical U.S. infrastructure.

  • Org Chart Stock Art - Shutterstock

    How the hiring freeze targets millennials

    The government desperately needs younger talent to replace an aging workforce, and experts say that a freeze on hiring doesn't help.

  • Shutterstock image: healthcare digital interface.

    VA moves ahead with homegrown scheduling IT

    The Department of Veterans Affairs will test an internally developed scheduling module at primary care sites nationwide to see if it's ready to service the entire agency.

  • Shutterstock images (honglouwawa & 0beron): Bitcoin image overlay replaced with a dollar sign on a hardware circuit.

    MGT Act poised for a comeback

    After missing in the last Congress, drafters of a bill to encourage cloud adoption are looking for a new plan.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group