Processing Classified Information on Portable Computers in the Department of Justice

Audit Report 05-32
July 2005
Office of the Inspector General


Table of Contents


EXECUTIVE SUMMARY

INTRODUCTION

FINDINGS AND RECOMMENDATIONS

  1. STANDARD 1.6 HAS INAPPROPRIATE REFERENCES AND IS INCOMPLETE

  2. Inappropriate References in Standard 1.6
    Separate Authority Governing Classified National Security Information and Sensitive Compartmented Information
    Incomplete Guidance and Instructions
    Conclusion
    Recommendations

  3. INCREASING EFFICIENCY WHEN PROCESSING CLASSIFIED INFORMATION ON PORTABLE COMPUTERS

  4. Removable Hard Drives and Operating System
    Type Accreditations
    Safeguards for Lost or Stolen Computers
    Labeling Requirements for Classified Information Media
    Recommendations

STATEMENT ON INTERNAL CONTROLS

APPENDICES

  1. Objectives, Scope, and Methodology
  2. Voting Members of the Committee on National Security Systems
  3. Classified Laptop and Standalone Computers Security Policy, Standard 1.6
  4. Chief Information Officer’s Response to the Audit Recommendations
  5. Office of the Inspector General, Audit Division, Analysis and Summary of Actions Necessary to Close Report