<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: usaascs]]></title>
    <link>http://securityratty.com/tag/usaascs</link>
    <description></description>
    <pubDate>Sun, 13 Apr 2008 16:23:28 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Excel Spreadsheet on the web exposes Army officers and civilians]]></title>
      <link>http://securityratty.com/article/3579588fd6b1623770eef27c0456e961</link>
      <guid>http://securityratty.com/article/3579588fd6b1623770eef27c0456e961</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/4/08

Organization
United States Army

Contractor/Consultant/Branch
United States Army Acquisition Support Center (&quot;USAASC

Victims
Colonels and...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/usaasc.jpg" align="right" height="101" width="104"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/4/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.army.mil/">United States Army</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://asc.army.mil/default.cfm">United States Army Acquisition Support Center ("USAASC")</a> <br><br><span style="font-weight: bold;">Victims:</span><br>"Colonels and civilians who managed programs within ASC"<br><br><span style="font-weight: bold;">Number Affected:</span><br>"about two dozen"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"name, rank, program and organization" and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"A spreadsheet containing a "hidden" column of Social Security numbers belonging to about two dozen officers and civilian employees of one Army agency was left on the agency's website for five months after being notified of the presence of the personal information."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.federalnewsradio.com/?nid=169&amp;sid=1380599">Federal News Radio</a> <br><a href="http://asc.army.mil/docs/press/webstatement_4-4-08.pdf">USAASC response</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Patience Wait, Federal News Radio<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A spreadsheet containing a "hidden" column of Social Security numbers belonging to about two dozen officers and civilian employees of one Army agency was left on the agency's website for five months after being notified of the presence of the personal information. <br><span style="font-style: italic;">[Evan] Let's get this straight.&nbsp; The USAASC was notified about it five months ago and nothing was done about it?&nbsp; How do you explain that?</span><br><br>The Army's Acquisition Support Center has temporarily shut down its website to scrub the information from the spreadsheet&nbsp;&nbsp;&nbsp; <br><br>"We regret that this error occurred. We have temporarily taken the web site down to make the necessary corrections. We will bring the website back online once the corrections have been verified," an Army spokesman responded in an email.<br><br>"We are also in the process of informing the individuals on the spreadsheet that their information was made available to the public." <br><br>The spokesman's email stated that the agency was investigating why the information had been included on the spreadsheet to begin with, and why it was still on the website five months after ASC was notified of its presence.<br><br>A computer expert who works for a federal contractor was surfing the web while doing research and found the spreadsheet in November.<br><br>The file contained a list of Colonels and civilians who managed programs within ASC. Visible columns listed their name, rank, program and organization. <br><br>In Microsoft Excel, however, every column is labeled with a letter of the alphabet, and the columns in this spreadsheet read, "A-B-D-E," indicating that column C was hidden. A simple command, "unhide," revealed the column of Social Security numbers. <br><br>FederalNewsRadio has obtained a copy of the email sent by the expert to ASC warning of the presence of the SSNs. The agency responded to the expert that the matter was being turned over to its executive officer for "review and correction."<br><span style="font-style: italic;">[Evan] This is interesting.</span><br><br>But the information was still present on ASC's Web site on April 3, five months to the day after ASC promised it would be corrected.<br><br>FederalNewsRadio contacted one person on the list, to confirm the number shown next to his name was in fact his Social Security number.<br><br>The man declined to directly confirm the number, but he was clearly shocked, and asked several questions, including requesting the link so he could see it for himself.<br><br>While only a handful of people were affected by the lapse, it is a violation of federal policy.<br><br>"It is a big issue," says Ari Schwartz, vice president of the Center for Democracy and Technology. "It would seem to be a violation of the [Office of Management and Budget] memo that just went out that said agencies should be cutting down on the use of Social Security numbers, as well as the Privacy Act."<br><br>Cate and Schwartz both agreed that PII leaked over the Internet is much more dangerous than widely publicized incidents involving lost and stolen laptops containing similar information, because once on the web, data lives forever. <br><br>In response to an article written by FederalNewsRadio.com on Friday, April 4, 2008, regarding an error made by the United States Army Acquisition Support Center (USAASC) in a posting to its Web site, we would like to reassure those whose personal information may have been inadvertently listed that we have taken action to both remove the information from USAASC’s Web site and verify that no other personal information remains available on the Web site. <br><br>USAASC and its staff members serving our country around the world, sincerely regret the error made and the additional delay incurred in taking corrective action. <br><br>In accordance with federal directives, as well as a matter of policy and practice, USAASC works diligently to safeguard both sensitive data and personal information. <br><br>At USAASC, we are confident that we have appropriately addressed this issue and instituted new policies so that such an oversight will not occur in the future. <br><br>Again, we regard people’s personal information as extremely private and worthy of the highest level of protection and we greatly appreciate the understanding of those involved. <br><br><span style="font-weight: bold;">Commentary:</span><br>The apology and responses by the USAASC sound sincere, but how do they explain the complete lack of attention to the original notification in November?&nbsp; The USAASC only responded once they were notified by the press. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/13/usaasc.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sun, 13 Apr 2008 16:23:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/personal information remains">personal information remains</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/army">army</category>
      <category domain="http://securityratty.com/tag/usaascs web site">usaascs web site</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/spreadsheet">spreadsheet</category>
      <category domain="http://securityratty.com/tag/usaasc response">usaasc response</category>
      <category domain="http://securityratty.com/tag/usaasc">usaasc</category>
      <source url="http://breachblog.com/2008/04/13/usaasc.aspx">Excel Spreadsheet on the web exposes Army officers and civilians</source>
    </item>
  </channel>
</rss>
