iTnews
  • Home
  • News
  • Technology
  • Security

How a US department overhauled untenable security

By Darren Pauli
Jul 25 2011 6:00AM
Follow google news

Once deemed the most insecure in North America.

When a US court ordered IT staff at the Department of the Interior to disconnect 85,000 staff from the internet in 2001, heads rolled.

How a US department overhauled untenable security

It took four days to comply with the order, initially made in an attempt to keep hackers from accessing $US1 billion ($AU923.5 million) in Native American royalties managed by the department.

The decision came as a double blow to the department, which the same year was given a security score of 12 out of 100 by the US Congress - a "very very low F-grade", according to the man hired to clean it up.

It took the next six years and a federal court defence from a former chemical engineer and coal mine inspector Hord Tipton to convert one of the US' oldest civilian agencies into one of its most secure.

He ultimately saved hundreds of millions of dollars but the job wasn't easy.

The department remained embroiled in the longest-running legal fight in US history, a 149-year case with Native American communities who argued the government had squandered $US137 billion from the trust fund over more than a century.

The communities - and the US District Court - feared a further billion could be lost if the department's IT infrastructure wasn't tied down.

The plaintiffs asked that a penetration test be conducted on the systems of the Bureau of Indian Affairs. It was granted.

"They walked in the front door," Tipton told SC on a lightning trip to Sydney.

Of course, it would have been easy. Despite a multi-million dollar IT security budget, the bureau and wider department lacked even basic security structures. No firewalls or anti-virus applications.

"These people in the bureau were scientists, and they demanded unfettered internet access," Tipton explained. "And that meant no firewalls."

The District Court ruled that internet be severed to not just the offending bureau, but the entire department.

For bureau heads, it might have initially come as a relief; no more online distractions for its employees. But, as Tipton told it, a subsequent fortnight delay in delivering tens of thousands of pay checks to employees was only the start of a long line of problems.

The clean up

The Department of the Interior, known as 'the department of everything', manages over 500 million acres of government-owned land equal to approximately one fifth of the country's land mass.

More than a quarter of the nation's electricity is produced on land and seas managed by the department. It overseas oil reserves and the great Yellowstone National Park; some 500 dams including Hoover Dam and icons such as the Washington Monument.

Its networks and security controls were similarly disparate.

When Tipton stepped into the job, the department used 18 operating systems, 14 web portal solutions, 35 gateways, 153 financial payment systems and separate development systems for each bureau. It also had kilometres of un-used fibre and telephone lines.

Tipton took to the IT cleanup operation wielding an indomitable razor.

He began with the department's new relationship database, dubbed 'ALMERS', that had failed after 15 years of development at a cost of $US10 million a year. Any changes to the system required code to be re-written.

"It used to take five minutes and cost about US$10 to get a license to cut your own Christmas tree. After ALMERS, it took four hours and cost US$75," Tipton said.

It was promptly "taken out the back and shot".

A single Microsoft contract, replacing scores of disparate operating system and software licenses, saved $US40 million in the first year alone.

The department's 35 gateways were slashed to two (saving $US100 million) and disused networking lines, described as "T1s to nowhere", were consolidated to save $US500 million.

Disobedient bureaus that shunned the shared infrastructure model had their budgets cut. One agency that spent $US100,000 on building a duplicate in-house system had the same amount slashed from its coffers and redirected to the department.

The lesson was learnt quickly, and agencies soon fell into line.

He estimated that the clean up saved about $US150 million on information security spending alone.

Security overhaul

The court-ordered internet blackout allowed agencies to light back up as they improved information security.

Tipton installed 252 point-to-point network links and "workarounds" between offices to keep the department operational.

He also forced the department's 225 information security staff to become Certified Information Systems Security Professionals (CISSP), or "get used to counting cattle".

Tipton himself passed after four months of cramming, despite not having a background in information security.

Incredibly, the offending bureau had successfully argued remain online, regardless of upgrades to its security.

The same court that berated the department was later impressed with information security overhaul, and lifted the internet blackout.

A department which once earned a government security rate of 12 receive a radically improved score of 79 out of 100 four years later. Tipton led it to become the first civilian agency in the country to receive the top rating for data resiliency.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:
certificationisc2managementpolicysecurityus government

Related Articles

  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
  • Anthropic opens Claude Mythos Preview AI program to Australia Anthropic opens Claude Mythos Preview AI program to Australia
Join our WhatsApp Channel

Partner Content

Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
You meet the security standard. Shame no one can see it
Promoted Content You meet the security standard. Shame no one can see it
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Promoted Content Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Microsoft backs down on legal threats against 0day disclosing researchers

Microsoft backs down on legal threats against 0day disclosing researchers

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.