iSecurity logo

 The Security Universe at Your Fingertips
   FREE registration is now open for the March 8, 2012 virtual show!

Security Newswire

TSA Security Breach: What's Next?

After a TSA operating manual was published online, what is next? How does TSA recover and ensure that security will not be breached at America's airports?
 
 
The 93-page instruction manual was written for airport screeners, providing details on how screening is conducted and the limitations of X-ray machines. It was posted on a Web site for government contractors, with sensitive parts redacted -- but the redacted information was not properly protected, and the information was restored by people familiar with the computer program. The manual was dated May 2008, but the TSA said it was never implemented and has been revised six times, although it did not elaborate on the extent of the revisions. It said the report was removed as soon as it learned of the problem, but the full, unredacted version of the report appeared on at least one Web site Sunday and was distributed more widely Tuesday.
 
 
Chris Wacker, senior vice president for Laserfiche, told Security magazine that the person who released the document did not understand how to properly redact an electronic document. The TSA simply drew black rectangles over the sensitive areas. The PDF still contained the sensitive text in the text layer of the document. This means that anyone can simply select all in the document, copy and paste somewhere else to see all the text. It only requires basic computer literacy to circumvent the redaction, he said.
 

If the TSA had been using a certified electronic document management solution, he suggested, this problem would have been much less likely to have happened. Redaction can be set up to automatically “burn in” the redaction whenever a document is exported. This means that it is not possible to circumvent the redaction, because the text is removed from the image and from the text layer. This lapse, he said, shows a profound lack of understanding of electronic documents at the TSA.
 
 
A DHS official noted that the erroneous posting is more a PR nightmare than a security hazard because TSA manuals are popular within the aviation society. TSA officials told CNN that the agency was conducting an internal review of the case. "TSA has many layers of security to keep the traveling public safe and to constantly adapt to evolving threats. TSA is confident that screening procedures currently in place remain strong," the agency announced in a statement.
 
Yet, yesterday, TSA put five of its employees on administrative leave.
 
 
What's next for travelers and airport security? At a hearing on Wedesday, Homeland Security Secretary Janet Napolitano told a Senate Judiciary Committee that “the traveling public was not at risk.” The agency has instituted an internal review of the incident "to see what else needs to be done so that the incident never recurs," she said, and the Department of Homeland Security has asked its inspector general to conduct an independent review "to make sure that we are being rigorous and very disciplined on what is posted and what is not."
 
You must register or login in order to post comments.

Multimedia

Videos

Image Galleries

Stanley Customer Appreciations Event at ASIS 2011

Customers enjoyed the annual Stanley customer appreciation event during ASIS 2011 in Orlando.

Podcasts

The New Age of Video Surveillance
In this podcast, Bill Lawrence, director of Service Solutions and Platforms for ADT Security Services, explains the growing interest in video surveillance by both government agencies as well as businesses of every stripe. He discusses what any organization should consider before investing heavily in the technology. Lawrence is a 25-year veteran of both the information technology and physical security industries, with extensive experience in network video surveillance and physical security convergence.
More Podcasts

Security Technology

What has been the biggest impact of security technology on security officers?
See Poll Results Poll Archive

THE SECURITY STORE

comptiahighriseproductphoto
CompTIA Security+ Certification Study Guide
CompTIA's Security+ certification is a globally-recognized, vendor neutral exam that has helped over 60,000 IT professionals reach further and higher in their careers. The current Security+ exam (SY0-201) focuses more on being able to deal with security issues rather than just identifying them.
More Products

Clear Seas Research

Clear Seas ResearchWith access to over one million professionals and more than 60 industry-specific publications,Clear Seas Research offers relevant insights from those who know your industry best. Let us customize a market research solution that exceeds your marketing goals.

Vertical Sector Focus: Critical Infrastructures

criticalhomepagethumbFrom terrorism to vandalism, it’s preparedness, response, training and partnerships. Learn about some of the critical security issues facing this sector.

Visit the Critical Infrastructure page to read more.  

STAY CONNECTED

facebooklogo twitterlogo  linkedinlogo