Letter to the Honorable Betsy DeVos, Secretary of US Department of Education - Protection of Personally-Identifiable Information

Letter

Dear Madam Secretary:

The federal government has a responsibility to protect the personally-identifiable information (PII) Americans entrust it with each day. The stakes are particularly high at the Department of Education, an agency responsible for securing 139 million unique social security numbers and other sensitive information of students, parents and custodians across the country. Protecting that information is of paramount importance.

The Department maintains 184 information systems, more than 120 of which are operated by contractors or subcontractors. 1 Most of the names, addresses, social security numbers, and other PII on those systems are connected with the federal student aid programs authorized under Title IV of the Higher Education Act, which affects tens of millions of new Americans each year. These programs are primarily need-based, requiring applicants (students and their parents or custodians) to provide the Department with PII and other sensitive information. The Department also manages a significant portfolio of assets ($1.3 trillion) to support those student aid programs, for which it must also ensure appropriate security and continuous operations.2 In short, the Department is responsible for both a wealth of information on millions of Americans and substantial financial assets.

Despite this critical need, cybersecurity at the Department is far short of where it should be. The Department's Inspector General (IG) has identified information security as a "major management challenge," 3 and the Government Accountability Office (GAO) testified that the Department is one of 12 agencies for which information security controls constitute a"significant deficiency." 4 In its FY2016 Federal Information Security Management Act (FISMA) audit, the IG scored the effectiveness of the Department and Federal Student Aid
(FSA) cybersecurity programs at 53 percent, or "generally not effective." 5 While the IG credited the Department in making some progress to strengthen its information security programs, the IG found in FY2016 that "weaknesses remained and the Department and FSA's information systems continued to be vulnerable to security threats. " 6

Until December 2016, the Department had a grade of "F" on the Committee's Federal Information Technology Acquisition Reform Act (FIT ARA) scorecard. 7 It has since improved to a C+ but continues to receive an F in the subcategories on "Transparency and Risk Management" and "CIO Authorities." 8

To help ensure the Department safely maintains and secures PII and other sensitive data, the Committee initiated oversight in the 114 th Congress that identified a number of issues and concerns for the Department to address, many of which persist as vulnerabilities. 9 Those include:

* In FY2015, the I G found several unauthorized connections that used outdated secure connection protocols, and in FY2016 the IG found the Department continued to use outdated secure connection protocols for many of its connections. 10 As a result, those who connect to the Department to retrieve or submit data could be unwittingly providing sensitive information to a malicious actor or be subject to a "man-in-the middle" type
attack. This is an especially problematic finding given the number of individuals that connect to the Department, such as colleges and universities, loan servicers and guaranty agencies, and students or guardians.

* The Department disclosed it was operating 54 unsupported software systems. 11 These are systems whose vendors no longer provide the services and updates necessary to keep the software running efficiently and securely. Many unsupported software systems have widely known vulnerabilities that an adversary could easily find and then leverage to gain unauthorized access to the Department's systems.

* In 2015, the IG conducted a successful penetration test-a hack conducted by security experts-of the Department's network without being detected by exploiting configuration weaknesses. 12 Despite this, the IG's FY2016 audit found configuration management policies and procedures were not current with NIST and Department guidance ( a condition also found in the FY2014 and FY2015 audits). Although a successful
penetration test is not always cause for alarm, that it went undetected and unmitigated is of great concern.

* The IG's FY2016 audit found the Department had no mechanisms to restrict the use of unauthorized devices physically connected to its network-an open issue since the IG's FY2011 audit. Failure to restrict unauthorized devices could allow malicious users to bypass two-factor authentication, obtain Departmental Internet protocol addresses, and gain access to Departmental internal resources, all potentially without the Department knowing. 13

* In November 2015, GAO testified the Department had a higher than average number of reported incidents that were policy violations related to mishandling of data in storage or transit compared to other federal agencies (26 percent at the Department compared to 1 7 percent at other major federal agencies with policy violations). 14 One of the largest threats to any organization's cybersecurity is the insider threat-employees and contractors who either intentionally or unintentionally misuse the organization's ITresources, allowing adversaries to get in the organization's systems.

* The IG found in its FY2016 audit that the Department had not established a process for assessing the knowledge, skills, and abilities of individuals with significant security responsibilities. 15

* The Department scored a negative 14 percent on the 2015 Office of Management and Budget CyberSprint for total users using strong authentication-one of only three federal agencies to decrease. 16
o In February 2016, the Department testified that progress had been made, stating that 95 percent of its users were employing two-factor authentication as of January 31, 2016, and that it projected to achieve 100 percent compliance by March 2016. 17
o However, the IG found in its FY2016 FISMA audit that the Department did not consistently and effectively implement two-factor authentication for non­ privileged users for accessing internal resources. In addition, while the Department reported 82 percent using two-factor Personal Identity Verification (PIV) or NIST Level of Assurance 4 credential, the OCIO was unable to provide evidence to support the underlying accounts and the IG could not validate the extent to which the Department uses two-factor authentication. 18

* The IG also found that nine external network connections did not use two-factor authentication (or 19 percent). This issue was identified in both the FY2014 and FY2015 audits. Although the Department stated that this issue was addressed in December 2015, the IG was still able to find remote connections that did not require two-factor authentication. 19

* The IG found in FY2016 that 66 of the 214 Department authorized active connections it tested (30 percent) failed to adhere to mandated encryption standards. 20

* A number of the Department's key systems are in need of attention:
o The Common Origination and Disbursement (COD) system is essential to the annual delivery of $150 billion federal student aid funds to Title IV eligible colleges and universities. 21 The IG tested the COD application during its FY2014 FIS MA audit and reported several vulnerabilities, some of which were "high severity," with the expectation that the issues should be addressed immediately. 22 However, during testing for the FY2016 audit, the IG reported that the samevulnerabilities were present and the Department had not yet mitigated them. 23 Overall, the IG's vulnerability scans identified 5 high vulnerabilities, 29 medium,
and 9 low.
o The Central Processing System (CPS) stores over 139 million unique Social Security Numbers of students and parents that have participated in the federal student aid system, 24 however, the Department reported in the November 2015 hearings that CPS was not equipped for Personal Identity Verification ("PIV ­enabled" system) for "strong" multifactor authentication. 25 Further, the former Chief Information Officer for the Department- the individual responsible for agency-wide information security under FISMA-could not say why the CPS system was not PIV-enabled, 26 exposing a possible deficiency in the relationship between the agency CIO and the FSA CIO. The CIO also testified that CPS operates with outdated programming language (one million lines of COBOL), the use of which increases operations and maintenance costs while making securing the system more difficult. 27
o The IG testified that within the National Student Loan Database System (NSLDS) there are 97,000 accounts or users with access to this significant data, yet only 5,000 of those who have an account have undergone a background check, 28 and the Department disclosed this system is also operating in part with outdated
programming language (six million lines of COBOL). 29

In recent years, the Department's FIS MA audits have shown repeat findings and recommendations, indicating that problems are going uncorrected. The FY2016 audit was no exception, containing 11 findings, 5 of which were repeat findings from previous FIS MA audits. The FY2016 audit also made 15 recommendations, 6 of which are repeat recommendations. 30 This raises questions that warrant additional oversight by the Committee, especially given the volume of personal and sensitive information the Department stores about individuals and the hundreds of billions of dollars at stake.

To assist the Committee, please provide the following documents and information as soon as possible, but no later than 5:00 p.m. on April 13, 2017:

1. The Department's plan for addressing each outstanding finding and recommendation made by the IG's FY2016 FISMA audit, including target dates for completion;

2. Identify the actions, including a description thereof, that the Department has taken to reduce the prevalence of policy violations since FY2016;

3. Identify the 54 software systems that remain unsupported, as well as any additional software systems not previously identified by the Department that are currently unsupported; and

4. A description of the state of deployment of Continuous Diagnostic and Mitigation (CDM) 3 tools as of March 1, 2017.

When producing documents to the Committee, please deliver production sets to the Majority Staff in Room 2157 of the Rayburn House Office Building and the Minority Staff in Room 24 71 of the Rayburn House Office Building. The Committee prefers, if possible, to receive all documents in electronic format. An attachment to this letter provides additional information about responding to the Committee's request. Please note that Committee Rule 16(b) requires counsel representing an individual or entity before the Committee or any of its
subcommittees, whether in connection with a request, subpoena, or testimony, promptly submit the attached notice of appearance to the Committee.

The Committee on Oversight and Government Reform is the principal oversight committee of the House of Representatives and may at "any time" investigate "any matter" as set forth in House Rule X.

If you have questions about this request, pleae contact Katie Bailey or Mike Flynn of the Majority staff at (202) 255-5074, and Katie Teleky or Tim Lynch of the Minority staff at (202) 225-5051. Thank you for your prompt attention to this matter.

Sincerely,


Source
arrow_upward