Documents / FOIA release
This Central Intelligence Agency FOIA release, dated 2025-06-12, collects 1976 CIA paperwork on Harold Weisberg's request (76-F-382) for records on Martin Luther King, Jr. It includes routing slips, an Operations Staff memorandum listing releasable press items and exempt cables, dispatches and memoranda, and a CI Staff reply citing a 1968 Office of Security memo on Coretta Scott King. It also contains a 16 May 1968 memo to the FBI reporting that Gerald Lee Richards, investigated in Japan, did not resemble suspect James Earl Ray.
“Anderson”8 pages
Read from the scan by GLM-OCR; expect the odd misread word.
Theft, fraud, sabotage, EDP equipment malfections, and human errors are considered the most common dangers.
On-line terminals connected to central processors from remote points are more exposed to violations and thefts. The increasing popularity of time-storing systems among large corporations and service bureaus has given rise to even more potential security breaches. Data transmitted over a communication line could be subject to wire tapping and a number of other hazards such as piggyback entry, thereby the intruder intercepts and compromises communication between a terminal and the processor until a legitimate user is inactive but still holding the line open. The intruder can even cancel the user's sign-off signal and continue operating in his name. A knowledgeable person could enter program changes from a terminal and play havoc with the system.
## Need for Protection
Due to the increasing popularity of computing services, the issue of control and security protection has become more important. It is evident that time-sharing systems present few obstacles to unauthorized parties. The security problem has been made much more critical by the growing number of people trained in computers and by the fading of the computer mystique. In addition, communication by means of time-sharing systems has no more protection than telephone conversations or Morse-coded methods, since the technological skills necessary to interpret computerized data are widespread. More and more companies are appointing security monitors from their EDP staffs to centralize security matters. Trade organizations such as the American Management Association and the Bank Administration Institute, computer firms, and research firms such as Advancement Management Research, Inc. find their seminars on computer security overcrowded by data processing managers and security officers from business and government.
## Target of Attacks
Computers have become an important source of information and, as a result, the target of many attacks. Some of the general information targets for industrial espionage are sales and service information, market analysis strategies, bid prices, corporate finance, stockholder information, legal negotiations, planned policy changes, expansion plans, product developments, personnel changes, payroll data, general administrative matters; and the list could be expanded even more.
## Threats
The case of an 18 year-old Cincinnati youth who used long distance telephone to tap the lines of a time-sharing system firm in Louisville, Kentucky, and extracted data from its ledgers, as well as records of its customers, is representative of the type of risk to which computer installations are exposed.
Accidents can have serious consequences such as the incident in which income tax return records for were erased by energy emitted from the radar of a nearby airport in Austin, Texas.
## Safeguards
It is important to consider that too much control and too many security safeguards can become bother- and costly. The measures to protect data from authorized access vary from one system to another. According to Richard F. Cross, Security Office for the Bank of New York, security systems should include each of the following segments: physical security; personnel security; procedural security; audit control; insurance; and any needed interfacing.
The quality and level of protection required depends on the sensitivity of the data handled. Nevertheless, control and security in a time-sharing environment should encompass the whole system, since it is well known that even the strongest control measures can be violated at the weakest point. These measures should be taken in the central processing unit, software, personnel, communication lines, the terminal, and its users.
## Methods and Provisions Central Processing Unit
The central processor is threatened mostly by sabotage, fire, water, theft, EDP equipment malfunctions, human accidental errors and environmental problems.
The computer center of any company is the heart of the organization, and protection of the equipment against these threats can be provided by a carefully planned computer room. Luis Scoma, President of Data Processing Security, Inc., recommends that the computer center be located out of the main traffic areas. It must be fireproof, dustfree, and waterproof and provided with temperature and humidity control and carbon dioxide fire extinguishers. Water lines should not run through the computer room. A separate, fireproof storage area should be provided for data files, documentation, and operating supplies. It should also have alarm devices sensitive to magnetism, humidity, heat, pressure, dust, theft, power blackout, etc. There should be strong access control including armed guards, fenced areas, TV monitors, personnel identification (visual, voice print, fingerprint, badge, passwords, etc.), well-performed maintenance service, and a number of extra provisions for protection.
Data Processing Security, Inc. has developed, for high security necessities, an electronically operated double door entry system for access control into the computer room. When a person enters the buffer zone, the door locks behind him while he is subjected to electronic search. If something is detected, the system freezes and automatically alerts the security guard. The second door can be opened only with a special badge key.
A carbon dioxide $ \left( \mathrm{C O}_{2} \right) $ fire extinguishing system, such as the one installed at the Chase Manhattan Bank's New York City headquarters, has proved useful. Engineered by Walter Kidde & Co., Inc., this system uses a battery of remotely located cylinders containing the liquid gas. When activated by smoke detectors, the gas discharges and builds up an inert atmosphere in the immediately surrounding area, extinguishing the fire without damaging equipment or data files. Employees can go back to work within five minutes after the fire has been put out and the ventilation systems restarted.
Another fire-fighting system which has been developed by the Ansul Company uses Halon extinguishing agents which are discharged in the form of a colorless, odorless, and non-toxic gas. "Since Halon agents do not work by diluting oxygen, they are well-suited for areas where humans are present.
The Guaranty Bank and Trust Co. of Worcester. Mass., has adopted another approach to fire-fighting, a system installed by Security Control Systems which detects fire, smoke and excessive temperatures and humidity fluctuations and causes a monitoring and Not linked to a story yet.
FOIA release, from the cia-readingroom collection. The PDF is mirrored here; the original link is above. The text was read from the page images by GLM-OCR; expect the odd misread word. 295 pages are in the text index: search them above, or from the library's search.