Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Montana Agencies Left Private Information on Discarded Computers, Audit Shows
AP ^ | AP-ES-05-25-05 1234EDT

Posted on 05/25/2005 9:48:53 AM PDT by TheOtherOne

Montana Agencies Left Private Information on Discarded Computers, Audit Shows

By Bob Anez Associated Press Writer
Published: May 25, 2005 HELENA, Mont. (AP) - State agencies failed to remove private information before retiring outdated state computers, risking public disclosure of Social Security and credit card numbers, medical records and income taxes, a new report discloses.

The legislative audit, obtained Tuesday, blamed unclear state policy for the computer hard drives not being properly "scrubbed" before the machines were donated to school districts, given to other state agencies or sold to the public.

"The state lacks a single clear policy instructing departments on information removal, assigning responsibility for defining sensitive data, and assigning responsibility for performing data removal and certifying the task has been accomplished," the auditors said.

Janet Kelly, Department of Administration director, said in a written response that her agency immediately began crafting a more concise policy to ensure private information held by the government is not made public.

"The resulting language will require that all data must be irretrievably removed from the hard drive," she said.

Jeff Brandt, acting chief information officer for the state, said Tuesday the new policy should be complete by mid-July. In the meantime, he said, a warning has gone out to all information technology officials throughout state government.

"We're telling folks to not make any assumptions about options for scrubbing disks," he said. "Err on the side of making darn sure they are scrubbed."

Brandt said the information discovered by the auditor's office was never divulged, so the people to whom it pertains need not be concerned. However, he acknowledged the state has no way of knowing if other data on other computers discarded by the state was disclosed over the years as the machines changed hands.

The state has about 11,000 desktop computers and regularly disposes of aging machines. Last year alone, 51 agencies got rid of more 2,300 computers. Most are given to school districts.

State policy requires all agency information be removed from the computers "in such a manner that it cannot be recovered" after the machine leaves a department. But the audit noted that part of the policy also refers to removal of "meaningful information," wording that appears to make the policy inconsistent.

A 1996 policy mandated each computer be certified that removal of all data has occurred, but that same requirement is not contained in the current policy, the report said.

Mark Athearn, who heads the state surplus property office, said his office has stopped collecting computers until the revamped state policy is in place.

Auditors obtained 18 discarded state computers and found 12 of them contained information related to the department that had used them. The hard drives contained software that should have been removed, legal hearing notes, meeting files, citizen e-mails to department staff, and permit application information.

Eight of the machines also held confidential data, including 386 Social Security numbers, financial records for 182 people, 84 business files and job applicant information.

The audit said all agencies contacted were aware of the policy requiring hard drives be cleaned before computers are discarded, but some departments were using tools that did a poor job of completely removing the information.

AP-ES-05-25-05 1234EDT


TOPICS: News/Current Events
KEYWORDS: encription; govwatch; lazygovtofficials; privacy

1 posted on 05/25/2005 9:48:53 AM PDT by TheOtherOne
[ Post Reply | Private Reply | View Replies]

To: TheOtherOne

http://dban.sourceforge.net/ to download "Darik's Boot and Nuke". It's free and it will remove ALL the data on a hard disk.


2 posted on 05/25/2005 10:00:06 AM PDT by Abcdefg
[ Post Reply | Private Reply | To 1 | View Replies]

To: Abcdefg

I find that soaking the drive in a salt water solution, and then thowing it away with some nasty food crap all over it usually keeps anyone from trying my old drives. (it is low tech, but it works!)

I think this is an interesting topic, especially when read in light of the courts new views on encryption.

http://www.freerepublic.com/focus/f-news/1409947/posts


3 posted on 05/25/2005 10:09:17 AM PDT by TheOtherOne
[ Post Reply | Private Reply | To 2 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson