SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Politics : Formerly About Advanced Micro Devices

 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext  
From: jlallen12/26/2013 8:02:53 AM
   of 1581546
 
Chief Information Security Officer for Obamacare: I Told HHS the Website Wasn’t Safe

Posted By David Inserra On December 23, 2013 @ 2:32 pm In Capitol Hill,Front Page,Obamacare | No Comments

According to news reports, a government security expert at the heart of Healthcare.gov told Members of the House Oversight Committee that she informed HHS that the website was too dangerous to use [1].

In the days leading up the Obamacare rollout, Teresa Fryer, the Chief Information Security Officer at the Centers for Medicare and Medicaid Services (CMS), which oversees Healthcare.gov, recommended “a denial of Authority to Operate (ATO)” because she viewed it as “a high risk.” Despite her expertise on security issues and her responsibility for the security of the website, Fryer’s multiple warnings were overruled by her superiors.

As a result, the website went forward, not only with crippling errors that stopped the website cold, but also with critical security risks. The government defines a “high risk” [2] as that which could have a “severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.” While a CMS spokesperson has said that the security measures are in place and no successful attacks have occurred, Fryer knows the truth of cybersecurity: You may have been hacked or have a serious vulnerability in your system and not even know about it. These “unknown risks” can’t be fixed or mitigated because no one even knows they exist.

So not only were there known “high risks,” but the system wasn’t even fully tested to find other potential threats. Indeed, since the website launched, Fryer said that other “moderate” and “low” security risks were found, and others may still be out there.

Armed with this knowledge of known and unknown threats, Fryer reportedly recommended that the website not go live. Fryer not only told her boss, the now-retired Chief Information Officer of CMS Tony Trenkled, but she also briefed Secretary of Health and Human Services Kathleen Sebelius’s top information officers including Healthcare.gov’s chief project manager, HHS’s chief information security officer, and the HHS Deputy Assistant Secretary for Information Technology. They decided to ignore her [2] warnings, despite the potentially “catastrophic” danger that it posed to Americans’ personal information. [3]

Perhaps even worse, Secretary Sebelius testified before Congress on Oct 30 and told Congress that “I can tell you that no senior official reporting to me ever advised me that we should delay. We have testing that did not advise a delay. So not—not to my knowledge.”

This means one of two things: Either Secretary Sebelius did know and lied to Congress, or her staff is incredibly incompetent for not informing her of a risk of this magnitude. With consistent disregard for the rule of law [4] and Americans’ security [5], privacy, and wallets [6], it should be clear that Obamacare is wrong for the U.S. [7]

Article printed from The Foundry: Conservative Policy News Blog from The Heritage Foundation: http://blog.heritage.org

URL to article: http://blog.heritage.org/2013/12/23/chief-information-security-officer-obamacare-told-hhs-website-wasnt-safe/

URLs in this post:[1] she informed HHS that the website was too dangerous to use: http://oversight.house.gov/wp-content/uploads/2013/12/Teresa-Fryer-ATO.pdf

[2] “high risk”: http://www.cbsnews.com/news/high-security-risks-found-after-healthcaregov-launch/

[3] danger that it posed to Americans’ personal information.: http://blog.heritage.org/2013/10/02/cyber-failures-in-obamacare-exchanges-dangerous-to-your-wallet-and-privacy/

[4] rule of law: http://blog.heritage.org/2013/12/05/senator-reids-special-obamacare-staff-exemption/

[5] Americans’ security: http://blog.heritage.org/2013/12/16/obamacare-navigators-encourage-fraud-safe-private-information-report-warns/

[6] wallets: http://blog.heritage.org/2013/11/23/see-everything-familys-cutting-pay-obamacare/

[7] wrong for the U.S.: http://www.heritage.org/research/reports/2013/12/10-broken-obamacare-promises
Report TOU ViolationShare This Post
 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext