Congress

Education CIO in the hot seat on Capitol Hill

Wikimedia image: Department of Education.

Education Department CIO Danny Harris testified before the House Oversight and Government Reform Committee on Feb. 2. (Photo: Zach Noble, FCW)

Rep. Jason Chaffetz (R-Utah), the chairman of the House Oversight and Government Reform Committee, is concerned that the Department of Education could be ripe for the kind of data breach that hit the Office of Personnel Management.  And his concerns are exacerbated by the history of investigations into the personal conduct of longtime agency CIO Danny Harris.

At a Feb. 2 committee hearing, the Education Department largely closed ranks around Harris, as lawmakers called for him to be punished or even fired.  The members of Congress also questioned whether flagging morale and low cybersecurity marks at the agency could be related to Harris' behavior over the past decade.

"Mr. Harris has been the CIO [at Education] since 2008," Chaffetz said. "By virtually every metric, he is failing to adequately secure the department's systems."

That behavior includes operating home businesses (home theater equipment installation and car detailing) without reporting income to the IRS, helping a relative obtain a low-grade job at the agency, maintaining a close personal relationship with an agency contractor, and loaning money to agency employees.

"I believe there were significant lapses of judgment," testified Acting Secretary of Education John King. But ultimately, King testified that he had "confidence in his leadership."

All of the conduct concerns addressed in the hearing had been previously investigated and closed by the Education Department inspector general and Harris' superiors. Harris was not disciplined, but was put through four counseling sessions.

Still, lawmakers wondered why the consequences weren't more dire.

Rep. Ted Lieu (D-Calif.) said he was disappointed that Education officials chose not to punish Harris, and that King sheltered behind a wall of lawyer-approved statements instead of offering candid remarks.

Beside detailing and installation work, which Harris testified were more in the nature of hobbies than businesses, the CIO has also consulted for the city of Detroit and taught at Howard University at various points in his tenure.

"I can understand why there are problems at the Education Department [in cybersecurity] when you have so many outside jobs," said Rep. Carolyn Maloney (D-N.Y.).

Chaffetz pointed to the dismal employee feedback from within Education's office of the CIO as evidence of Harris' management shortcomings, saying, "There's a reason why you're scoring at the bottom of the heap."

Education also scored near the bottom of the heap on the November 2015 Federal IT Acquisition Reform Act  scorecard; it was one of three agencies to earn an ‘F.'

In the Feb. 2 hearing, Harris pledged security improvements.

He said Education should have 100 percent of its privileged users on two-factor authentication by March, once a vendor finishes re-architecting its data center, and non-privileged users should hit 100 percent for two-factor authentication by the summer.

Harris also said he plans to upgrade or retire 90 percent of the 54 software programs the agency is currently using that are no longer supported by their vendors.

Chaffetz, for his part, pledged to continue investigating Harris and Education, stressing that the agency houses sensitive personal information on half of the U.S. population.

About the Author

Zach Noble is a staff writer covering digital citizen services, workforce issues and a range of civilian federal agencies.

Before joining FCW in 2015, Noble served as assistant editor at the viral news site TheBlaze, where he wrote a mix of business, political and breaking news stories and managed weekend news coverage. He has also written for online and print publications including The Washington Free Beacon, The Santa Barbara News-Press, The Federalist and Washington Technology.

Noble is a graduate of Saint Vincent College, where he studied English, economics and mathematics.

Click here for previous articles by Noble, or connect with him on Twitter: @thezachnoble.


Featured

  • Contracting
    8 prototypes of the border walls as tweeted by CBP San Diego

    DHS contractors face protests – on the streets

    Tech companies are facing protests internally from workers and externally from activists about doing for government amid controversial policies like "zero tolerance" for illegal immigration.

  • Workforce
    By Mark Van Scyoc Royalty-free stock photo ID: 285175268

    At OPM, Weichert pushes direct hire, pay agent changes

    Margaret Weichert, now acting director of the Office of Personnel Management, is clearing agencies to make direct hires in IT, cyber and other tech fields and is changing pay for specialized occupations.

  • Cloud
    Shutterstock ID ID: 222190471 By wk1003mike

    IBM protests JEDI cloud deal

    As the deadline to submit bids on the Pentagon's $10 billion, 10-year warfighter cloud deal draws near, IBM announced a legal protest.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.