Documents / FOIA release
This is a report of investigation by the Central Intelligence Agency's Office of Inspector General, dated 18 July 2014. It covers Agency access to Senate Select Committee on Intelligence staff files on RDINet, the network built for the Senate review of the rendition, detention and interrogation program. The report found that five Agency employees improperly accessed the SSCI Majority shared drive and that three IT staff lacked candor. It also found no factual basis for the CIA crimes report against SSCI staff.
“The Advance”3 pages
Read from the scan by GLM-OCR; expect the odd misread word.
# UNCLASSIFIED//FOUO The Honorable Eric Holder, searches to retrieve documents on their portion of the system. That search tool had a security vulnerability, now remedied, that could be exploited to allow non-employees to breach the firewall and retrieve documents on the part of the system to which they were not authorized access. An incomplete audit indicates that at least one non-employee exploited that vulnerability to retrieve a number of CIA documents on the portion of the system to which he or she did not have authorized access. (U//FOUO) The information made available to me indicates that in the November 2010 timeframe, the non-employee conducted a search that appeared intended to reach into part of the computer system to which the non-employee did not have authorized access. In such a circumstance, the system was designed to bring up on the workstation screen a page that advised the non-employee was not authorized to access that document. This page, however, had the security vulnerability that has since been discovered and remedied. The security vulnerability was that the page also contained a "URL" that indicated where the document was located on the system and if an individual copied the URL and pasted it into the browser's address bar, the individual could gain access to the document, copy it, bring that copy across the firewall, and paste it into a folder on his or her side of the firewall. The information made available to me indicates the non-employee copied the URL, pasted it directly into the browser's address bar, and accessed the document. (U//FOUO) The information made available to me further indicates that this non-employee repeated this activity numerous times in order to access, copy, and bring across the firewall CIA documents to which he or she did not have authorized access. If the system worked as designed, on each occasion, the non-employee would have received on the workstation screen a page informing him or her that he or she did was not authorized to access the document. This non-employee copied all of these documents into a file or folder on the portion of the system to which he or she had authorized access. Thereafter, at least four other non-employees accessed and printed these CIA documents on multiple occasions. It is not clear whether any of these other four non-employees may also have exploited the security vulnerability.
Not linked to a story yet.
FOIA release, from the cia-readingroom collection. The PDF is mirrored here; the original link is above. The text was read from the page images by GLM-OCR; expect the odd misread word. 57 pages are in the text index: search them above, or from the library's search.