Documents / FOIA release
This is a report of investigation by the Central Intelligence Agency's Office of Inspector General, dated 18 July 2014. It covers Agency access to Senate Select Committee on Intelligence staff files on RDINet, the network built for the Senate review of the rendition, detention and interrogation program. The report found that five Agency employees improperly accessed the SSCI Majority shared drive and that three IT staff lacked candor. It also found no factual basis for the CIA crimes report against SSCI staff.
Read from the scan by GLM-OCR; expect the odd misread word.
# SECRET//NOFORN were later physically separated into two secure reading rooms at the request of the SSCI. Each of these offices included secure CIA-provided computer workstations for the review of materials released by the CIA and for the creation of individual work product. 7. (U//FOUO) RDINet is a standalone network that has a limited connection to the Agency Data Network (ADN) for administration purposes, including the ingestion of system software patches and updates and for routine network monitoring (Exhibit B). The SSCI and CIA were provided shared storage areas on RDINet that physically reside on the same hard drive array. Separate electronic storage drives were established for both the CIA and the SSCI to save documents and their respective reports. The SSCI was also provided additional storage drives further segregated between the Majority and Minority staff. Access to data was restricted through the use of access control lists and logical rules associated with the software. This virtual separation was intended to control access by the various parties to the RDINet, e.g., to prevent general CIA RDINet users from observing or accessing SSCI data, and to prevent SSCI users from observing or accessing CIA data that had not been released to them. Lotus Notes was installed on the network to provide an internal RDINet email capability. The email server allowed for communication among all RDINet users, both CIA and SSCI, and had no connectivity to the ADN. 8. (U//FOUO) From inception, the Office of General Counsel (OGC) was charged by the Agency with overseeing and supporting the RDI Program review. 9. (U//FOUO) In October 2013, when General Counsel Stephen Preston departed, Robert Eatinger, Deputy General Counsel, was appointed the Acting General Counsel. Because Eatinger had previously recused himself from any RDI matters (b)(3) (b)(7)(c) Because of Eatinger's recusal regarding the RDI matter was unsupervised by the Office of General Counsel pertaining to this matter. 10. (U//FOUO) On 22 June 2009, SSCI staff members began their review of RDI materials at the secure facility. 11. (U//FOUO) In November 2012, the RDI team learned of a vulnerability with the Google appliance, related to configuration settings that had been in place since the initial installation in November 2009. OIG reviewed an April 2013 email between members of the RDINet IT staff detailing the existing settings, which indicated an access control deficiency for search results. The RDI IT team updated the Google appliance in April 2013 to reflect this change. Prior to this update, the settings provided to OIG showed that the Google appliance was not configured to enforce access rights or search permissions within RDINet and its holdings.
Not linked to a story yet.
FOIA release, from the cia-readingroom collection. The PDF is mirrored here; the original link is above. The text was read from the page images by GLM-OCR; expect the odd misread word. 57 pages are in the text index: search them above, or from the library's search.