Federal News Service
HEADLINE: HEARING OF THE SELECT COMMITTEE ON HOMELAND SECURITY
SUBJECT: PROGRESS IN ADDRESSING MANAGEMENT CHALLENGES AT THE DEPARTMENT OF HOMELAND SECURITY
CHAIRED BY: REPRESENTATIVE CHRISTOPHER COX (R-CA)
WITNESS JAMES M. LOY, DEPUTY SECRETARY, DEPARTMENT OF HOMELAND SECURITY
LOCATION: 2318 RAYBURN HOUSE OFFICE BUILDING, WASHINGTON, D.C.
TIME: 10:30 A.M.
BODY:
REP. COX: Good morning. A little over a year has passed since the Department of Homeland Security opened for business on March 1st, 2003. With the stroke of a pen, the president and the Congress created the third largest cabinet department, and with it a remarkably lengthy "to-do" list. The task that we set before the leaders of this new department required creative thinking and extraordinary energy, as we're now keenly aware, also definite persistence.
The Homeland Security Act not only created entirely new functions, such as intelligence fusion, infrastructure protection and cyber security, that had to be built from scratch, but also required the merger of 22 government agencies into one coherent whole. That's a management challenge of the first magnitude.
Secretary Ridge, and you, Admiral Loy, have taken command of not one but many distinct organizations, each with its own operating culture and mission, and you've had to undertake this complex merger in a near-constant heightened alert environment, and while under unprecedented scrutiny from the administration, the Congress, and the American public. There has been no greater challenge to leadership in any of our federal agencies, and I want commend the secretary, and you, Admiral Loy, for the remarkable progress that you've made in one short year.
Some of the Department of Homeland Security's accomplishments over the past year have been visible. Others have taken place behind the scene. Everyone has been able to see our airports, seaports and borders hardened, and a good deal of publicity has surrounded the federal government's grants of billions of dollars for states, local governments and first responders to help prepare our communities for terrorist attacks. Less visible but just as important is the dramatic improvement in intelligence and information-sharing among federal agencies and their state and local partners.
Today we've asked Admiral Loy to join us to talk about all of these accomplishments and the many remaining management challenges. While the operational and analytical elements of the department have been busy preventing and protecting us from terrorist attack, the department's managerial leadership have been developing an overarching strategic plan to guide the department's future. You have been working on integrating legacy systems and procedures in order to achieve a more centralized, mission-focused structure. This integration is critical to the long-term success of the department and its mission to make America safer. It will be there for a continuing focus of congressional oversight.
Admiral Loy is the deputy secretary and the functional equivalent of chief operator office, is leading this effort. By all accounts, your leadership is visionary and firm. Thank you, on behalf of the American people, for your dedication and hard work, and we welcome your testimony today.
The Management Directorate, which Admiral Loy oversees, has been tasked with consolidating administrative support systems department- wide, and enhancing interoperability of the many legacy IT systems within the department. We hope to learn more today about the effectiveness of these efforts and to offer our support to ongoing efforts to consolidate and integrate DHS operations as quickly as possible.
This committee has an important role to play in working with the department during this merger integration process. By focusing on milestones and setting goals for management improvements, this committee can help the department to implement your strategic plan-a plan that is in place and that will build upon the successes of the past year. We look forward to working with you, Admiral Loy, on setting achievable goals and milestones for implementing your strategic plan, and in making sure that this plan is tied to the five- year budget that you will be submitting to Congress later this month.
We also look forward to working with you as we continue to develop our DHS authorization bill. The committee clearly wants this authorization to be an institutionalized means of helping the department now and over the long term. As you know, one of the ideas that we've discussed is elevating the department's cross-cutting management functions into your office in order to provide clearer lines of authority and responsibility with respect to IT, personnel, procurement, and finance functions. We will work with you to ensure that these and other reforms we may adopt help you to do your job, which is our goal.
I thank you again for your appearance today, and now recognize the ranking member, Mr. Turner from Texas, for an opening statement.
-BREAK OF TRANSCRIPT-
REP. COX: The gentleman's time is expired. The gentle lady from California, the ranking member on the Subcommittee on Cybersecurity, Science and Research and Development, Ms. Lofgren, is recognized, for eight minutes.
REP. ZOE LOFGREN (D-CA): Thank you, Mr. Chairman, and thank you, Admiral Loy. There are many things I'd like to ask you about today, and I'm not sure there will be time to ask them all. But I do want to focus in on the Cybersecurity Subcommittee. Over the past year and a half, members of the subcommittee have spent a lot of time looking at what I think are sometimes very complex issues involved in securing the nation's critical cyber infrastructure. And, as we've done that, we've looked at the department's commitment to pursuing a sound strategy on cybersecurity. And I think members of the subcommittee have serious concerns about our accomplishments in that area. We are concerned that we are not doing an adequate job, in all honesty. And, recently-well, the concerns really lie with whether we are sufficiently implementing the national strategy to secure cyberspace, whether staffing is adequate-I think that was mentioned earlier-not only in terms of the actual number of staff, but the number of temporary employees, the turnover, and also the placement of the division sort of buried down in the bowels of the bureaucracy, and whether it's getting the attention that we need; and, furthermore, concerns about channels of communication between that division and the top levels of the department. And in fact last week Chairman Cox, Ranking Member Turner, Chairman Thornberry and myself sent a letter to Secretary Ridge regarding the cybersecurity mission at the department. Have you seen this letter? Are you aware of the letter?
MR. LOY: Yes, ma'am, we have gotten the letter.
REP. LOFGREN: And we have asked, the four of us, for a response by Monday, May 10th. Do you think the department will be able to meet this deadline that we've asked them to meet?
MR. LOY: I certainly won't-it's now very much clear in my mind that that was the deadline that you're asking for, Ms. Lofgren. We'll try very hard to do that. And I'll take that back as I go back today.
REP. LOFGREN: Okay, thank you very much. And I will just-I hate to be a nag, but I also wanted to raise an issue, because it's happened repeatedly that we have asked Mr. Luskofsky (sp) and others to follow up with questions that we have not had answers to at the department, and we just don't get answers. It's like the questions go in; it's a black hole. Months go by. We never get answers. And I'm wondering, in your management capacity, if you could check and see what is the problem there on getting answers back to the committee.
And also, again, we take our oversight commitment very seriously, and I'm proud to say the Cyber-Security and Science Subcommittee has operated in a very bipartisan manner. We not only have Chairman Thornberry worked as a team, but our staffs have worked as a team. We see this as not a party mission but an American mission.
We never get testimony in a timely manner from people within the division. The rules are that it be 48 hours in advance. Sometimes we get it an hour before the hearings begin. That is really not-and it's happening over and over again, even after we complain. And it does not give the committee time to fulfill its obligations of oversight. So I'd like you also, if you would, please, to find out what is the problem there so that we can get that corrected.
I'd also like to talk just a little bit, (just not?) the Cyber- Security Subcommittee, but about the Immigration Service, former Immigration Service, in that function. I also serve on the Immigration Subcommittee in the Judiciary Committee, and that whole function has been troubled for many years, as you've acknowledged.
But I am fearful that we're not making the progress that we should make, in all honesty. The president has indicated he wants the backlog to be decreased. In fact, the backlog is growing. It is not shrinking; it is growing. And the time for processing is growing.
And that actually-although sometimes it may seem that it's not a security issue-I mean, these are petitions of American citizens for their husbands or wives or adoptions; you know, it's a whole mish- mash-but the fact that it is not-that our processes are not computerized sufficiently does, I think, pose a threat to the United States.
In September of 2003, the GAO did a report and pointed out that in order to get information about financial information, that the INS would have to go and do hand counts to get-that's on page four of the GAO report-hand counts to answer the questions.
What that tells us is that if on paper, I mean, they can't actually get a computerized report in January of that same year, the GAO again pointed out that the application workload has to be corrected, that the visa operations needed attention, and that it's weakness in technology management that is very much a problem.
Now, you mentioned U.S. Visit, and I think that is a very good start. But I want to bring some concerns to your attention, because I think we are storing some problems for down the road.
Two years ago I asked the NIST what it would cost for them to set a biometric standard that could be utilized, and they said they didn't have-it wasn't a funded activity, but that for about $2 million-they had the lab capacity-they could provide the biometric standards.
Well, that never happened. They were never funded. DHS had funds but they never actually provided the funds to NIST. And as of this moment, those biometric standards have not actually been developed, nor adopted. Consequently, we are now engaging in an effort that is going to lead to a multiplicity of biometric standards that may or may not be suitable for a common data base.
For example, U.S. Visit is using two index figures. However, the international biometric that we are pursuing with machine-readable passports is going to be facial recognition. The two are not going to provide a common data base. Furthermore, it's not necessarily going to be compatible with the watch list.
And what we need-and I think the sooner we do this, the better-is that we need to have some common standards or a multiplicity of standards. There's no reason we can't have more than one biometric. But we need to have some standardization or else we will end up in two or three years with a system-wide problem similar to what we have with the INS.
I would also urge-and I may actually even offer, as amendments to our authorization, that we insist that the INS do something-I keep calling them the INS out of habit-that they computerize. I mean, we can track our FedEx package online, but you cannot find out where your application is for your spouse if you're an American citizen with repeated asking over two or three years.
They are filing by name and a number still. But they ought to be filing matters by biometrics, because you can have duplication of names but you cannot have duplication of biometrics. And it ought to be the same biometrics as being utilized by our national security agencies, by the FBI, by the State Department.
All of these things are highly doable. It's just a matter of management and making them happen. And so I don't know you, but you have a reputation as a manager. I'm asking you, really pleading with you, to exert some management control in this area to make it happen, because I think until we-and we can integrate these legacy systems. I mean, we can get off the shelf, actually, to integrate these legacy systems, which is why I say this is a management issue. It's not a technology issue.
And I hope that you will, next time I see you, be able to tell me that we have solved these problems. And I look forward to the answers to our question on Monday.
Thank you very much.
MR. LOY: Thank you. May I just for a moment, sir? Thanks, Ms. Lofgren. Very, very excellent questions and issues across the board as you describe them. Just a moment on several of them.
First, with respect to cyber, both the secretary and I have recognized that we have perhaps not found organizationally the right focus that cyber deserves, if you will. And I think of (SCADAS?) and so many other systems that are so dependent there that it's one of those things that, as I think about consequences, it sort of jumps off the chart, like does nuclear, like does bio and other such things.
So we are thinking very, very along the same lines, if you will. I had a meeting two weeks ago where I called together folks from industry, folks from observers that could help us help the chairman, if you will, of our NCSD, our National Cyber-Security Division, inside IAIP.
There's a great book called "Black Ice" that, if you haven't read, it's what prompted me to have this meeting, because it sort of was a confirming scare tactic, almost. We are taking cyber very, very seriously. And over the course of the next weeks, we will be going in the directions that you're describing as needed.
I apologize, ma'am, for the responsiveness commentary that you're describing, and I promise you that I will go back, find this letter, see if it's possible to answer on Monday, and if not, call you and let you know that to be the case.
On CIS issues, again, this is something the department inherited. As you keep using the phrase INS, I keep saying they're not there anymore. We have really broken INS into three pieces, and the ICE piece is working very well. The pieces that found their way into CBP are working very well. The piece that continues to offer services to the immigrant population is where the managerial concentration needs to be to press on. So that's where I'm going.
REP. LOFGREN: If I-I know my time has expired. The three divisions cannot work well unless they all work well. For example, the terrorists that came in and that helped destroy the towers should never have been admitted, because they had applied for a change of status, student visa off their visitor's visa. Had that been computerized instead of on a piece of microfiche sitting in a box, the officer at entry would have denied them entry.
MR. LOY: You're right, the --
REP. LOFGREN: And I don't fault the officer. He didn't have the data. And so you can't do the job unless it's all working together.
MR. LOY: All those challenges are very real. The IT end of CIS is something we're working on hard. We've just hired a new CIO to help them in that process of sorting out what they need to do. And integrating that, as both the chairman and Mr. Turner have indicated, into the bigger picture of IT integration department-wide is part of our challenge.
REP. COX: The gentlelady's time has expired. The gentleman from Arizona, the chairman of the Subcommittee on Emergency Preparedness and Response, Mr. Shadegg, is recognized for five minutes.
REP. JOHN SHADEGG (R-AZ): Thank you, Mr. Chairman. First, let me thank my colleague, Mr. Shays, for deferring to me. I need to be elsewhere, and so he agreed to let me go first, and I appreciate that.
Admiral, I want to thank you for being here. I want to thank you for your testimony. I frequently say, both here and at home, that you and the secretary have, I think, the second- and third-toughest jobs in Washington DC. I give the president the toughest job. But I quite frankly think standing up a new department is phenomenally difficult. Trying to bring together the agencies you have to bring together, get them working together in a concerted fashion, is very difficult.
I appreciate your bringing to that task the expertise and the knowledge and the dedication that you have. I appreciate your work in the war on drugs in the past, where I think our paths first crossed. I also want to thank you for the Arizona Border Control Initiative. It has made a huge difference.
MR. LOY: It really has.