Major Security Breach Reported to Congress By Federal Bank Regulator

Nossaman LLP
Contact

Recently, the Office of the Comptroller of the Currency (OCC) informed Congress that it had suffered a major information security incident.

The agency reported that, in November 2015, a former employee downloaded over 10,000 records onto two thumb drives before retiring.  The breach was first detected in September 2016 during an internal review of employee downloads.  Following investigation, the agency determined that the breach was a “major incident” requiring reporting to Congress under the Federal Information Security Modernization Act of 2014 (FISMA).

Under FISMA, as clarified by the October 30, 2015 Office of Management and Budget (OMB) Memorandum 16-03, a federal agency is required to notify Congress within 7 days of discovery of a “major” security incident.  Per OMB Memo 16-03, a “major incident” is one which:

1) Involves information that is classified or otherwise protected under certain categories; and

2) Is not recoverable or not reasonably recoverable; and

3) Has some functional impact to the mission of an agency; or

4) Involves exfiltration, modification, deletion or unauthorized access to either:

a) 10,000 or more records or users affected; or

b) any record of special importance.

OCC determined that the breach in question was a “major incident” because it involved protected information that was not recoverable, and the unauthorized removal involved a large number of files, exceeding 10,000.

Currently, there is no indication that the information involved included any non-public personally identifiable information, or that it has been disclosed to the public or otherwise misused in any way.  Notice of the breach was also given to the Director of the Office of Management and Budget, the Secretary of Homeland Security, and the head of the Government Accountability Office.  The important lesson for government agencies is to understand the parameters of FISMA, and the reporting requirements when a major incident has occurred.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Nossaman LLP | Attorney Advertising

Written by:

Nossaman LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Nossaman LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide