Documents / FOIA release
This is a report of investigation by the Central Intelligence Agency's Office of Inspector General, dated 18 July 2014. It covers Agency access to Senate Select Committee on Intelligence staff files on RDINet, the network built for the Senate review of the rendition, detention and interrogation program. The report found that five Agency employees improperly accessed the SSCI Majority shared drive and that three IT staff lacked candor. It also found no factual basis for the CIA crimes report against SSCI staff.
“The Advance”3 pages
Read from the scan by GLM-OCR; expect the odd misread word.
# UNCLASSIFIED/DRAFT ATTORNEY-CLIENT PRIVILEGED good ideas, and that he would pursue them. I again thanked him for his thoughtfulness. The conversation was cordial throughout. Addendum re Feinstein letter of January 23, 2014 I share a few thoughts about Sen. Feinstein's letter—in particular, it's most important implicit assertion, that the Agency is not permitted to access the SSCI side of the CIA system for purposes of security monitoring and to ensure the safety of classified materials. That assertion is simply incorrect. Throughout the life of the SSCI review CIA has in fact performed security monitoring and exerted compliance control over RDI Net, including on the SSCI side of the system. The Agency monitors the entire system as it does all CIA systems, and SSCI awareness of this fact is reflected in the security warnings and disclaimers that SSCI staffers see as they access their side of the system. The security briefing provided to SSCI staffers makes it clear that such monitoring / (b)(3) was to be expected. Of course, it must be so. After all, SSCI has never attempted to exert any sort of security protocols or monitoring over the system. To my knowledge, no SSCI security officer has ever accessed the system or requested permission to do so. If SSCI is right in claiming that CIA lacks the authority to maintain security of the system and its compliance with Agency regulations and applicable law, then we have created a system in which no one has that responsibility. Even the Director lacks the authority to establish a system for maintaining extremely sensitive, classified documents and exempt it from all security monitoring and compliance. In point of fact, of course, DCIA Panetta did not purport to do so here. While SSCI asserted the right to complete hegemony over its side of the system, the Agency did not accept that demand. The Committee cannot establish otherwise by repeatedly citing its unacknowledged and unapproved assertion of complete control. I am told that like many issues of contention between the Agency and the Committee (such as the ultimate ownership of the documents being provided to the SSCI, which the Committee still claims should be given over for permanent storage on the Hill following conclusion of the Review) Agency leadership at the time chose to defer "open warfare" over the issue of security by not making it an explicit provision in letter exchanges between the Agency and Sen. Feinstein. But at no point did the Agency abdicate its responsibility to maintain security over the system—and my own view is that, in any event, it could not have lawfully done so. Finally, and perhaps of greatest significance, the "stand alone" nature of the system was only important, as the letter from Sen. Feinstein explicitly admits, "because it was recognized to contain SSCI work product." The preliminary audit conducted in this instance, which took place because there was a reasonable basis to believe that a violation of regulation or law had occurred, did not involve the review of any work product. It was
Not linked to a story yet.
FOIA release, from the cia-readingroom collection. The PDF is mirrored here; the original link is above. The text was read from the page images by GLM-OCR; expect the odd misread word. 57 pages are in the text index: search them above, or from the library's search.