Air Force

January 10, 2014

AFNet PII breaches still concern

afnet1
PETERSON AIR FORCE BASE, Colo. — More than one month after Air Force Space Command’s implementation of lock-out procedures for individuals found to have inappropriately transmitted Personally Identifiable Information, PII breaches still remain a significant issue.

While the average number of daily incidences of PII breaches have decreased there is still a lot of work to be done to prevent future PII incidents, said Gen. William L. Shelton, the commander of Air Force Space Command.

“We’ve all got to work harder to eliminate PII violations,” Shelton said. “In November more than 5,000 individuals were affected by a single PII breach. PII that is not properly protected becomes vulnerable to interception by an adversary. That creates the risk of the information being used to target individual users to gain their credentials and potentially gain access to our networks. From an individual perspective, it can also lead to identity theft. We can’t stand the network or the personal consequences, so we must stop PII breaches on the AFNet (Air Force Network).”

During the six month period from May through October the Air Force averaged approximately 3.3 reports affecting 1,935 members per day. Since launching the new policy and process, that average has dropped to approximately 2.7 reports affecting 991 members per day.

“The most common violations we are seeing are people transmitting personnel rosters from .mil to .com addresses and vice versa,” said Col. Douglas Coppinger, the 67th Cyberspace Wing vice commander, the wing whose mission encompasses the detection of PII breaches. “While quite often these breaches are not of malicious intent, we need to better educate our Airmen on the protection of this type of information.”

One tool available for protecting information is provided by the Software Protection Initiative established by the Under Secretary of Defense for Acquisition, Technology and Logistics in December 2001. The SPI has the mission of marginalizing a threat actor’s ability to steal and exploit critical Department of Defense intellectual property found in application software.

Users have multiple tools at their disposal to protect PII if encrypting e-mail is not feasible, but electronic transmission of sensitive PII is operationally required. Users can leverage approved DOD file exchange services through AMRDEC SAFE, file encryption wizards, or simply use Microsoft Office password protection.

“Once personnel understand what information can be sent home and how to protect it, this provides Airmen clear lanes in the road they can follow, and provides commanders the framework to properly address infractions of those set rules,” Coppinger said.

afnet2

Continuing force-wide education on the protection of electronic information is a top priority for AFSPC and those responsible for protecting the AFNet.

“We are working with leaders across the Air Force to educate and address PII breaches,” said Maj. Gen. James K. McLaughlin, the 24th Air Force commander. “As the technology we use to protect the Air Force Network improves, we have gained better visibility of information crossing through and leaving the network. As a matter of fact, we already detect 100 percent of all pieces of PII crossing through the AFNet. What we’re doing now is making a concerted effort to hold people accountable, helping to ensure all AFNet users are handling this important information properly.”

The AFSPC lock-out procedures were put in place based upon AFSPC’s responsibility to operate and defend the AFNet and each individual user’s responsibilities that comes with access to the network. AFMAN 33-152, User Responsibilities and Guidance for Information Systems, requires special handling for PII data.

AFNet users should contact their unit Privacy Manager as well as refer to Air Force Instruction 33-332, The Air Force Privacy and Civil Liberties Program, for additional information on safeguarding PII.




All of this week's top headlines to your email every Friday.


 
 

 
Page-One

Red Flag launches into 2015

U.S. Air Force photo by Staff Sgt. Siuta B. Ika Two maintainers assigned to the 748th Aircraft Maintenance Squadron, Royal Air Force Lakenheath, England, work on the wing of an F-15 Eagle during Red Flag 15-1 at Nellis Air Forc...
 
 
U.S. Air Force photo by Johnny Saldivar

RED HORSE overhauls JB San Antonio runway

U.S. Air Force photo by Johnny Saldivar Col. David Drichta, 12th Operations Group commander, Brig. Gen. Bob LaBrutta, 502nd Air Base Wing and Joint Base San Antonio commander, City of Seguin Mayor Don Keil, Col. Matt Isler, 12t...
 
 
U.S. Air Force photo by Master Sgt. Kevin J. Gruenwald

40 years of Red Flag at Nellis

U.S. Air Force photo by Master Sgt. Kevin J. Gruenwald A flight of F-15 Eagles and F-16 Fighting Falcons Aggressors fly in formation over the Nevada Test and Training Ranges June 5, 2008. The proposal for Red Flag came in early...
 

 
U.S. Air Force photo by Staff Sgt. Siuta B. Ika

Airman pulls woman from burning vehicle

U.S. Air Force photo by Staff Sgt. Siuta B. Ika Tech. Sgt. Justin Mahana, 823rd Maintenance Squadron support section chief, poses in front of an HH-60G Pave Hawk at Nellis Air Force Base, Nev., Jan. 20. On Jan. 6, Mahana pulled...
 
 

Airman leads way in combating sexual assault

NELLIS AIR FORCE BASE, Nev. — Rape is a dirty word. But it’s not the word that is dirty, it’s the action. At a U.S. Air Force Warfare Center reporting unit, one Airman is going above and beyond to combat this violation to the Air Force, its Airmen and its mission. And the service’s leadership...
 
 

Air Force senior leadership addresses need to stabilize RPA enterprise

WASHINGTON — During a State of the Air Force address held at the Pentagon,Jan. 15, Secretary of the Air Force Deborah Lee James announced immediate preliminary steps to develop a get-well plan to improve the health of the MQ-1B Predator and MQ-9 Reaper enterprise in light of extensive combatant commander operational needs. “(Intelligence, surveillance and...
 




0 Comments


Be the first to comment!


Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>


Directory powered by Business Directory Plugin