Veterans Affairs

VA still mum on IT security questions

Placeholder Image for Article Template

Lawmakers remain dissatisfied with the Department of Veterans Affairs' answers to inquiries regarding IT security practices, and a briefing between department officials and representatives of various oversight bodies ended with VA officials again declining to respond to questions.

According to a Capitol Hill official, the briefing was conducted Dec. 3 at the Cannon House Office Building and included VA's Assistant Secretary for Congressional and Legislative Affairs Joan Mooney, Chief of Staff Jose Riojas, members of VA's Office of Inspector General, representatives from the Government Accountability Office, and Democratic and Republican members of the House Veterans' Affairs Committee.

The briefing also included a panel of cybersecurity experts who offered their assessments of VA's IT security issues.

The Hill official said the meeting was a continuation of a yearlong effort to "convince the department to resolve a number of serious IT security vulnerabilities" identified by the Veterans' Affairs Committee's Oversight and Investigations Subcommittee and confirmed by GAO and VA's OIG.

When given the opportunity to respond to various assessments and criticisms of VA's IT security posture, VA officials declined to comment, continuing a narrative that is becoming frustrating for Congress.

"Committee members are hopeful that VA, having been presented with a detailed list of its specific network security vulnerabilities, will take this opportunity to work with [the committee] to resolve these IT challenges," the Hill official said.

The committee's questions to VA regarding its perceived weaknesses in IT security began in June 2012, and committee members have made more than 100 requests for information since then. The committee launched a more vigorous effort after a June 4 hearing that featured conflicting testimony from VA officials regarding at least nine state-sponsored data breaches.

Beginning Oct. 22, the committee delivered a series of inquiries to VA's Office of Information and Technology with more than 100 questions on IT security, including how the agency safeguards more than 20 million veterans' personally identifiable information.

VA missed early-November deadlines for each request, and VA Secretary Eric Shinseki's last-ditch effort to have the OIG expand its 2013 Federal Information Security Management Act audit to address the questions failed when OIG officials notified him that they had already completed the audit.

Thus far, VA's only formal response to Congress' multiple inquiries was a Nov. 22 memo from CIO Stephen Warren. In his response, Warren attempted to explain VA's position and said the department would continue to work on providing Congress with answers.

Those answers have yet to come, and the Hill official warned that Congress' questions, which concern the safety of millions of veterans' personal information, are not going to go away.

VA officials did not respond to FCW's requests for comment.

About the Author

Frank Konkel is a former staff writer for FCW.

Featured

  • Cybersecurity

    DHS floats 'collective defense' model for cybersecurity

    Homeland Security Secretary Kirstjen Nielsen wants her department to have a more direct role in defending the private sector and critical infrastructure entities from cyberthreats.

  • Defense
    Defense Secretary James Mattis testifies at an April 12 hearing of the House Armed Services Committee.

    Mattis: Cloud deal not tailored for Amazon

    On Capitol Hill, Defense Secretary Jim Mattis sought to quell "rumors" that the Pentagon's planned single-award cloud acquisition was designed with Amazon Web Services in mind.

  • Census
    shutterstock image

    2020 Census to include citizenship question

    The Department of Commerce is breaking with recent practice and restoring a question about respondent citizenship last used in 1950, despite being urged not to by former Census directors and outside experts.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.