Talk With an Expert

An Approach to Reducing Federal Data Breaches

An Approach to Reducing Federal Data Breaches (PDF, 5.68MB)Published: 17 May, 2016
Created by:
David Thomas

In 2015, The United States Office of Personnel Management (OPM) publicly disclosed a loss of 21.5 million Americans personally identifiable information (PII). What are the lessons learned from this breach and can other federal CIOs use these lessons within their own organization to prevent a similar loss of PII? An open source chronological timeline of events is presented leading up to the 2015 OPM disclosure and post disclosure events. The critical security controls (CSCs) that applied to the OPM breach are evaluated to demonstrate how each one could have reduced the risk of a breach or the scale of the breach. A practical application of an open source hashing tool is offered to the reader to implement within their organization. The result of reviewing the events that led to the OPM disclosure, the evaluation of the CSCs, and implementation of a practical approach can reduce the risk of another federal organization experiencing a breach similar to OPM.