<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>security - The Black Vault</title>
	<atom:link href="https://www.theblackvault.com/documentarchive/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.theblackvault.com/documentarchive</link>
	<description>Discover the Truth</description>
	<lastBuildDate>Fri, 05 Apr 2024 13:49:34 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>

<image>
	<url>https://www.theblackvault.com/documentarchive/wp-content/uploads/2020/06/cropped-siteicon-2-150x150.jpg</url>
	<title>security - The Black Vault</title>
	<link>https://www.theblackvault.com/documentarchive</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">87123917</site>	<item>
		<title>Declassified FBI Cyber Threat Assessment Illuminates 2008 Digital Dangers</title>
		<link>https://www.theblackvault.com/documentarchive/declassified-fbi-cyber-threat-assessment-illuminates-2008-digital-dangers/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=declassified-fbi-cyber-threat-assessment-illuminates-2008-digital-dangers</link>
		
		<dc:creator><![CDATA[John Greenewald]]></dc:creator>
		<pubDate>Fri, 05 Apr 2024 13:49:34 +0000</pubDate>
				<category><![CDATA[Federal Bureau of Investigation (FBI) Collection]]></category>
		<category><![CDATA[Cyberterrorism]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[MDR]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://www.theblackvault.com/documentarchive/?p=19347</guid>

					<description><![CDATA[<p>After a seven-year effort to obtain information from the Federal Bureau of Investigation (FBI) through a Mandatory Declassification Review (MDR), The Black Vault has finally succeeded in acquiring a previously unreleased document, albeit heavily redacted. Before this release, only brief citations were found in other files, also released to The Black Vault by the FBI. [...]</p>
<p>The post <a href="https://www.theblackvault.com/documentarchive/declassified-fbi-cyber-threat-assessment-illuminates-2008-digital-dangers/">Declassified FBI Cyber Threat Assessment Illuminates 2008 Digital Dangers</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>After a seven-year effort to obtain information from the Federal Bureau of Investigation (FBI) through a Mandatory Declassification Review (MDR), The Black Vault has finally succeeded in acquiring a previously unreleased document, albeit heavily redacted. Before this release, only brief citations were found in other files, <a href="https://documents2.theblackvault.com/documents/fbifiles/1389336-000.pdf" target="_blank" rel="noopener">also released to The Black Vault</a> by the FBI.</p>
<p><a href="https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-40-00.png"><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-19348" src="https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-40-00.png" alt="" width="672" height="211" srcset="https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-40-00.png 672w, https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-40-00-300x94.png 300w, https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-40-00-150x47.png 150w, https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-40-00-450x141.png 450w, https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-40-00-600x188.png 600w" sizes="(max-width: 672px) 100vw, 672px" /></a></p>
<p>This request (case number 1363960-000), filed on December 16, 2016, asked for a review of the FBI&#8217;s Cyber National Threat Assessment for the year 2008, as found in the reference citation above. The document, dated June 22, 2009, is an intelligence assessment by the FBI.</p>
<p>The document provides an in-depth analysis of the cyber threats to the United States, focusing on remote system intrusions or unauthorized access against the nation and its critical infrastructure. It covers the period from June 30, 2007, to July 1, 2008, while also incorporating earlier material for context. The assessment addresses various aspects of cyber threats, including tactics, techniques, and procedures used against process control systems, financial institutions, government networks, and the supply chain. It also explores the potential use of tools and technologies such as IPv6 and virtual worlds by malicious actors.</p>
<p>One of the key highlights of the document is the emphasis on the persistent threat posed by botnets. The assessment states, &#8220;Botnets continue to pose a threat to US critical infrastructures. These networks of compromised computers can be used to wage denial of service attacks against targeted online entities, conduct phishing and spamming campaigns, and steal passwords and other login credentials&#8221;.</p>
<p>The document also sheds light on the evolving nature of cyber threats, noting that attackers continuously develop new methods to exploit vulnerabilities. It mentions that &#8220;Attackers typically collect passwords, login credentials, keystrokes, credit card numbers, and personally identifying information from botnet victims&#8221;, highlighting the diverse objectives of cyber attackers.</p>
<figure id="attachment_19349" aria-describedby="caption-attachment-19349" style="width: 240px" class="wp-caption alignright"><a href="https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-44-34.png"><img decoding="async" class="wp-image-19349 size-medium" src="https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-44-34-240x300.png" alt="" width="240" height="300" srcset="https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-44-34-240x300.png 240w, https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-44-34-150x188.png 150w, https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-44-34-450x563.png 450w, https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-44-34-600x750.png 600w, https://www.theblackvault.com/documentarchive/wp-content/uploads/2024/04/2024-04-05_06-44-34.png 620w" sizes="(max-width: 240px) 100vw, 240px" /></a><figcaption id="caption-attachment-19349" class="wp-caption-text">In parts of the file, it remains heavily redacted</figcaption></figure>
<p>The document remains heavily redacted, citing exemptions such as (b)(1), (b)(3), (b)(6), (b)(7)(C), and (b)(7)(E). These exemptions under the Freedom of Information Act (FOIA) and the Privacy Act, which justify the withholding of information from public disclosure, are defined as the following:</p>
<ul>
<li>(b)(1): Information that is classified to protect national security.</li>
<li>(b)(3): Information exempted from disclosure by other statutes.</li>
<li>(b)(6): Information that would constitute a clearly unwarranted invasion of personal privacy.</li>
<li>(b)(7)(C): Information that could reasonably be expected to constitute an unwarranted invasion of personal privacy.</li>
<li>(b)(7)(E): Information that would disclose techniques and procedures for law enforcement investigations or prosecutions.</li>
</ul>
<p>As noted in the release letter, the redactions were made by the United States Air Force – Office of Special Investigations (AFOSI), National Security Agency (NSA), Office of the Director of National Intelligence (ODNI), and United States Cyber Command (USCYBERCOM).</p>
<p>The heavy redactions in the document indicate the sensitivity of the information related to national security and law enforcement techniques, even after 15 years since it was originally written.</p>
<h3>Document Archive</h3>
<p><img decoding="async" src="https://www.theblackvault.com/images/pdf.gif" /> <a href="https://documents2.theblackvault.com/documents/fbifiles/1363960-000.pdf">FBI intelligence Assessment, FBI Cyber National Threat Assessment – 2008, dated 22 June 2009</a> [30 Pages, 10.3MB]</p>
<div class="ead-preview"><div class="ead-document" style="position: relative;padding-top: 90%;"><div class="ead-iframe-wrapper"><iframe src="//docs.google.com/viewer?url=https%3A%2F%2Fdocuments2.theblackvault.com%2Fdocuments%2Ffbifiles%2F1363960-000.pdf&amp;embedded=true&amp;hl=en" title="Embedded Document" class="ead-iframe" style="width: 100%;height: 100%;border: none;position: absolute;left: 0;top: 0;visibility: hidden;"></iframe></div>			<div class="ead-document-loading" style="width:100%;height:100%;position:absolute;left:0;top:0;z-index:10;">
				<div class="ead-loading-wrap">
					<div class="ead-loading-main">
						<div class="ead-loading">
							<img decoding="async" src="https://www.theblackvault.com/documentarchive/wp-content/plugins/embed-any-document/images/loading.svg" width="55" height="55" alt="Loader">
							<span>Loading...</span>
						</div>
					</div>
					<div class="ead-loading-foot">
						<div class="ead-loading-foot-title">
							<img loading="lazy" decoding="async" src="https://www.theblackvault.com/documentarchive/wp-content/plugins/embed-any-document/images/EAD-logo.svg" alt="EAD Logo" width="36" height="23"/>
							<span>Taking too long?</span>
						</div>
						<p>
							<div class="ead-document-btn ead-reload-btn" role="button">
								<img loading="lazy" decoding="async" src="https://www.theblackvault.com/documentarchive/wp-content/plugins/embed-any-document/images/reload.svg" alt="Reload" width="12" height="12"/> Reload document							</div>
							<span>|</span>
							<a href="https://documents2.theblackvault.com/documents/fbifiles/1363960-000.pdf" class="ead-document-btn" target="_blank">
								<img loading="lazy" decoding="async" src="https://www.theblackvault.com/documentarchive/wp-content/plugins/embed-any-document/images/open.svg" alt="Open" width="12" height="12"/> Open in new tab							</a>
					</div>
				</div>
			</div>
		</div><p class="embed_download"><a href="https://documents2.theblackvault.com/documents/fbifiles/1363960-000.pdf" download>Download [10.30 MB] </a></p></div><p>&nbsp;</p><p>The post <a href="https://www.theblackvault.com/documentarchive/declassified-fbi-cyber-threat-assessment-illuminates-2008-digital-dangers/">Declassified FBI Cyber Threat Assessment Illuminates 2008 Digital Dangers</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">19347</post-id>	</item>
		<item>
		<title>LANL&#8217;s Security Inspection: A Declassified 2003 Analysis of Safeguards and Accountability</title>
		<link>https://www.theblackvault.com/documentarchive/lanls-security-inspection-a-declassified-2003-analysis-of-safeguards-and-accountability/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=lanls-security-inspection-a-declassified-2003-analysis-of-safeguards-and-accountability</link>
		
		<dc:creator><![CDATA[John Greenewald]]></dc:creator>
		<pubDate>Sun, 12 Nov 2023 05:16:56 +0000</pubDate>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[DOE]]></category>
		<category><![CDATA[Inspection]]></category>
		<category><![CDATA[los alamos]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://www.theblackvault.com/documentarchive/?p=18698</guid>

					<description><![CDATA[<p>A previously classified document, &#8220;Independent Oversight Inspection of Safeguards and Security of the Los Alamos Site Office and Los Alamos National Laboratory,&#8221; published in February 2003, has been further released after a Mandatory Declassification Review (MDR) filed by The Black Vault. The document provides an in-depth examination of the safeguards and security programs at the [...]</p>
<p>The post <a href="https://www.theblackvault.com/documentarchive/lanls-security-inspection-a-declassified-2003-analysis-of-safeguards-and-accountability/">LANL’s Security Inspection: A Declassified 2003 Analysis of Safeguards and Accountability</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>A previously classified document, &#8220;Independent Oversight Inspection of Safeguards and Security of the Los Alamos Site Office and Los Alamos National Laboratory,&#8221; published in February 2003, has been further released after a Mandatory Declassification Review (MDR) filed by The Black Vault. The document provides an in-depth examination of the safeguards and security programs at the National Nuclear Security Administration&#8217;s (NNSA) Los Alamos Site Office (LASO) and Los Alamos National Laboratory (LANL) conducted in late 2002.</p>
<p>The inspection, carried out by the Office of Independent Oversight and Performance Assurance (OA), was comprehensive and performance-oriented, covering six key areas: classified matter protection and control, personnel security, physical security systems, nuclear material control and accountability (MC&amp;A), protective force, and protection program management​​​​.</p>
<p>Notably, the inspection occurred concurrently with separate investigations by the DOE Inspector General, the FBI, UC, and Congress into allegations of missing government property and misuse of laboratory credit cards. However, these investigations did not influence the OA&#8217;s inspection scope, focusing instead on the protection of special nuclear material and classified information​​.</p>
<p>A significant revelation during the inspection was related to LANL&#8217;s inventory of accountable classified matter, where a hard drive was initially unaccounted for but later resolved. This incident, among others, was thoroughly scrutinized during the inspection, underlining the depth and rigor of the OA&#8217;s evaluation process​​.</p>
<p>The document meticulously details the inspection&#8217;s findings, conclusions, and assigned ratings to various security aspects of LASO and LANL. It highlights the strengths and weaknesses of the respective programs, with an emphasis on areas requiring immediate and sustained management attention​​.</p>
<p>For instance, while many security program elements at LANL were functioning effectively, there were identified weaknesses, particularly in the MC&amp;A program. These deficiencies included flaws in the physical inventory process and inadequate oversight by the LANL MC&amp;A Group, necessitating immediate corrective actions​​.</p>
<p>The report also underscores the need for a fully staffed Security Management Team to provide adequate direction and oversight, a challenge exacerbated by the reengineering of NNSA and the redistribution of responsibilities from the Albuquerque Operations Office to LASO. This staffing issue poses a significant risk to the efficacy of the federal oversight of safeguards and security programs at LANL​​.</p>
<p>In conclusion, the document acknowledges the steady progress made by LANL in addressing past security deficiencies, while emphasizing the necessity for continued management support and attention to maintain and enhance the security environment. The majority of the protection program elements at LANL were found to be effectively implemented, with some sub-elements demonstrating near-flawless performance. However, the document does not shy away from highlighting areas needing urgent improvement, particularly in the MC&amp;A program, to restore its previous high performance standards​​.</p>
<p>The ratings assigned to the various safeguard and security areas reflect a predominantly effective performance across most domains, with the notable exception of the MC&amp;A program, which was flagged as needing improvement​​.</p>
<p>This declassified document is a testament to the intricate balance of maintaining national security while ensuring transparency and accountability in the management of critical national assets. It provides valuable insights into the complexities of security management at one of the nation&#8217;s most sensitive nuclear facilities.</p>
<h3>Document Archive</h3>
<h4><img decoding="async" src="https://www.theblackvault.com/images/pdf.gif" /> <a href="https://documents2.theblackvault.com/documents/doe/DOE-MDR-2017-0005.pdf">Independent Oversight Inspection of Safeguards and Security of the Los Alamos Site Office and Los Alamos National Laboratory, February 2003</a> [98 Pages, 22MB]</h4>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<hr />
<p>&nbsp;</p><p>The post <a href="https://www.theblackvault.com/documentarchive/lanls-security-inspection-a-declassified-2003-analysis-of-safeguards-and-accountability/">LANL’s Security Inspection: A Declassified 2003 Analysis of Safeguards and Accountability</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18698</post-id>	</item>
		<item>
		<title>History of NRO Security Breaches, January 7, 1974</title>
		<link>https://www.theblackvault.com/documentarchive/history-of-nro-security-breaches-january-7-1974/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=history-of-nro-security-breaches-january-7-1974</link>
		
		<dc:creator><![CDATA[John Greenewald]]></dc:creator>
		<pubDate>Fri, 03 Jul 2020 15:09:00 +0000</pubDate>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Spy Satellites and the NRO]]></category>
		<category><![CDATA[National Reconnaissance Office]]></category>
		<category><![CDATA[NRO]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://www.theblackvault.com/documentarchive/?p=11846</guid>

					<description><![CDATA[<p>Background The National Reconnaissance Office (NRO) began in 1961, but operated in secret for decades before it was officially acknowledged. Before the existence was declassified, in 1974, they evaluated numerous incidents where the agency was talked about within the press. The concern was how the Soviets, or the media, would react. This document was first [...]</p>
<p>The post <a href="https://www.theblackvault.com/documentarchive/history-of-nro-security-breaches-january-7-1974/">History of NRO Security Breaches, January 7, 1974</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3>Background</h3>
<p>The National Reconnaissance Office (NRO) began in 1961, but operated in secret for decades before it was officially acknowledged. Before the existence was declassified, in 1974, they evaluated numerous incidents where the agency was talked about within the press. The concern was how the Soviets, or the media, would react.</p>
<p>This document was first released to the National Security Archive (also archived below) and was heavily redacted. In August of 2019, I filed a Mandatory Declassification Review (MDR) request to have it reviewed. To my surprise, all redactions were lifted and it was released in full minus one name at the end of the report.</p>
<h3>Document Archive</h3>
<p style="text-align: left;"><img decoding="async" src="https://www.theblackvault.com/images/pdf.gif" /> <a href="https://documents2.theblackvault.com/documents/nro/EOM-2019-00077.pdf">History of NRO Security Breaches, January 7, 1974</a> [6 Pages, 1MB]</p>
<div class="ead-preview"><div class="ead-document" style="position: relative;padding-top: 90%;"><div class="ead-iframe-wrapper"><iframe src="//docs.google.com/viewer?url=https%3A%2F%2Fdocuments2.theblackvault.com%2Fdocuments%2Fnro%2FEOM-2019-00077.pdf&amp;embedded=true&amp;hl=en" title="Embedded Document" class="ead-iframe" style="width: 100%;height: 100%;border: none;position: absolute;left: 0;top: 0;visibility: hidden;"></iframe></div>			<div class="ead-document-loading" style="width:100%;height:100%;position:absolute;left:0;top:0;z-index:10;">
				<div class="ead-loading-wrap">
					<div class="ead-loading-main">
						<div class="ead-loading">
							<img decoding="async" src="https://www.theblackvault.com/documentarchive/wp-content/plugins/embed-any-document/images/loading.svg" width="55" height="55" alt="Loader">
							<span>Loading...</span>
						</div>
					</div>
					<div class="ead-loading-foot">
						<div class="ead-loading-foot-title">
							<img loading="lazy" decoding="async" src="https://www.theblackvault.com/documentarchive/wp-content/plugins/embed-any-document/images/EAD-logo.svg" alt="EAD Logo" width="36" height="23"/>
							<span>Taking too long?</span>
						</div>
						<p>
							<div class="ead-document-btn ead-reload-btn" role="button">
								<img loading="lazy" decoding="async" src="https://www.theblackvault.com/documentarchive/wp-content/plugins/embed-any-document/images/reload.svg" alt="Reload" width="12" height="12"/> Reload document							</div>
							<span>|</span>
							<a href="https://documents2.theblackvault.com/documents/nro/EOM-2019-00077.pdf" class="ead-document-btn" target="_blank">
								<img loading="lazy" decoding="async" src="https://www.theblackvault.com/documentarchive/wp-content/plugins/embed-any-document/images/open.svg" alt="Open" width="12" height="12"/> Open in new tab							</a>
					</div>
				</div>
			</div>
		</div><p class="embed_download"><a href="https://documents2.theblackvault.com/documents/nro/EOM-2019-00077.pdf" download>Download [973.31 KB] </a></p></div><h3>Archived Versions</h3>
<p><a href="https://nsarchive2.gwu.edu//NSAEBB/NSAEBB257/19740107.pdf">Original Release to the National Security Archive</a></p>
<div class="ead-preview"><div class="ead-document" style="position: relative;padding-top: 90%;"><div class="ead-iframe-wrapper"><iframe src="//docs.google.com/viewer?url=https%3A%2F%2Fnsarchive2.gwu.edu%2FNSAEBB%2FNSAEBB257%2F19740107.pdf&amp;embedded=true&amp;hl=en" title="Embedded Document" class="ead-iframe" style="width: 100%;height: 100%;border: none;position: absolute;left: 0;top: 0;visibility: hidden;"></iframe></div>			<div class="ead-document-loading" style="width:100%;height:100%;position:absolute;left:0;top:0;z-index:10;">
				<div class="ead-loading-wrap">
					<div class="ead-loading-main">
						<div class="ead-loading">
							<img decoding="async" src="https://www.theblackvault.com/documentarchive/wp-content/plugins/embed-any-document/images/loading.svg" width="55" height="55" alt="Loader">
							<span>Loading...</span>
						</div>
					</div>
					<div class="ead-loading-foot">
						<div class="ead-loading-foot-title">
							<img loading="lazy" decoding="async" src="https://www.theblackvault.com/documentarchive/wp-content/plugins/embed-any-document/images/EAD-logo.svg" alt="EAD Logo" width="36" height="23"/>
							<span>Taking too long?</span>
						</div>
						<p>
							<div class="ead-document-btn ead-reload-btn" role="button">
								<img loading="lazy" decoding="async" src="https://www.theblackvault.com/documentarchive/wp-content/plugins/embed-any-document/images/reload.svg" alt="Reload" width="12" height="12"/> Reload document							</div>
							<span>|</span>
							<a href="https://nsarchive2.gwu.edu/NSAEBB/NSAEBB257/19740107.pdf" class="ead-document-btn" target="_blank">
								<img loading="lazy" decoding="async" src="https://www.theblackvault.com/documentarchive/wp-content/plugins/embed-any-document/images/open.svg" alt="Open" width="12" height="12"/> Open in new tab							</a>
					</div>
				</div>
			</div>
		</div><p class="embed_download"><a href="https://nsarchive2.gwu.edu/NSAEBB/NSAEBB257/19740107.pdf" download>Download [38.69 KB] </a></p></div><p>&nbsp;</p><p>The post <a href="https://www.theblackvault.com/documentarchive/history-of-nro-security-breaches-january-7-1974/">History of NRO Security Breaches, January 7, 1974</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">11846</post-id>	</item>
		<item>
		<title>USPS Investigation: Security Risks in the Capital District Management Advisory Report, January 27, 2014</title>
		<link>https://www.theblackvault.com/documentarchive/usps-investigation-security-risks-capital-district-management-advisory-report-january-27-2014/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=usps-investigation-security-risks-capital-district-management-advisory-report-january-27-2014</link>
		
		<dc:creator><![CDATA[John Greenewald]]></dc:creator>
		<pubDate>Fri, 18 Nov 2016 23:10:49 +0000</pubDate>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Government Accountability & I.G. Reports]]></category>
		<category><![CDATA[inspector general]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[United States Postal Service]]></category>
		<category><![CDATA[USPS]]></category>
		<guid isPermaLink="false">http://www.theblackvault.com/documentarchive/?p=3443</guid>

					<description><![CDATA[<p>Background The U.S. Postal Service&#8217;s security program is designed to reduce the incidence of crime against employees, the mail, and other assets, as well as maintain the integrity of the Postal Service .. The Postal Service faces a variety of security challenges and threats that it must take seriously. Our objective was to determine whether [...]</p>
<p>The post <a href="https://www.theblackvault.com/documentarchive/usps-investigation-security-risks-capital-district-management-advisory-report-january-27-2014/">USPS Investigation: Security Risks in the Capital District Management Advisory Report, January 27, 2014</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3>Background</h3>
<p>The U.S. Postal Service&#8217;s security program is designed to reduce the incidence of crime against employees, the mail, and other assets, as well as maintain the integrity of the Postal Service .. The Postal Service faces a variety of security challenges and threats that it must take seriously. Our objective was to determine whether the Capital District had an effective anonymous mail program in place to prevent potentially dangerous mail from entering the. mailstream and a workplace violence program to mitigate violence.</p>
<p>We developed an enhanced security risk model to identify high-risk districts that warrant further review. We analyzed data related to anonymous mail, which<br />
is ___________________________________________________________________________.</p>
<p>We also analyzed data related to workplace violence; suspicious and potentially dangerous mail; and Voice. of the Employee survey results covering fiscal year 2012, Quarter 3, to fiscal year 2013, Quarter 2.</p>
<h3>What the OIG Found</h3>
<p>The Capital District did not have an effective anonymous mail program in place to prevent potentially dangerous mail from entering the mailstream and a workplace violence program to mitigate violence. For example, the Capital District had an average anonymous mail testing failure rate of ___ percent. In addition, Capital District employees did not always follow policy when handling anonymous and potentially dangerous mail and did not always comply with workplace violence prevention requirements to effectively mitigate violence in the workplace.</p>
<p>The greatest opportunity to limit inappropriate use of the mail is during the earliest point in the Postal Service&#8217;s distribution system. Potentially dangerous mail or an act of workplace violence could put employees, mail, assets, and the public at risk and negatively impact the Postal Service&#8217;s brand. Enforcement of good security practices is essential to an efficient and economical operation.</p>
<h3>What the OIG Recommended</h3>
<p>We recommended management clarify employee roles and responsibilities, require personnel to take additional training, implement anonymous mail program best practices, complete the workplace violence self-audit tool, and establish controls to ensure personnel comply with anonymous mail and workplace violence requirements.</p>
<h3>The Report</h3>
<p><img decoding="async" src="https://www.theblackvault.com/images/pdf.gif" /> <a href="https://documents.theblackvault.com/documents/ig/HR-MA-14-003FinalDetermination.pdf">Report Number HR-MA-14-003 &#8211; Security Risks in the Capital District Management Advisory Report &#8211; dated January 27, 2014</a> [39 Pages, 5.9MB]</p>
<p>https://documents.theblackvault.com/documents/ig/HR-MA-14-003FinalDetermination.pdf</p><p>The post <a href="https://www.theblackvault.com/documentarchive/usps-investigation-security-risks-capital-district-management-advisory-report-january-27-2014/">USPS Investigation: Security Risks in the Capital District Management Advisory Report, January 27, 2014</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3443</post-id>	</item>
		<item>
		<title>DoD Instruction 0-3600.02 &#8220;Information Operations (IO) Security Classification Guidance,&#8221; November 28, 2005</title>
		<link>https://www.theblackvault.com/documentarchive/dod-instruction-0-3600-02-information-operations-io-security-classification-guidance-november-28-2005/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dod-instruction-0-3600-02-information-operations-io-security-classification-guidance-november-28-2005</link>
		
		<dc:creator><![CDATA[John Greenewald]]></dc:creator>
		<pubDate>Tue, 01 Nov 2016 20:41:14 +0000</pubDate>
				<category><![CDATA[Department of Defense Collection]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[classified]]></category>
		<category><![CDATA[department of defense]]></category>
		<category><![CDATA[DOD]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://www.theblackvault.com/documentarchive/?p=3299</guid>

					<description><![CDATA[<p>Background This Instruction: 1.1 . Reissues reference (a) to implement policy, assign responsibilities, and prescribe guidance on the classification methodology for Information Operations (10) programs and capabilities within the Department of Defense. 1.2. Establishes guidance for proper protection of 10 activities. 1.3. Identifies and provides classification guidance on categories of IO activities. While this Instruction [...]</p>
<p>The post <a href="https://www.theblackvault.com/documentarchive/dod-instruction-0-3600-02-information-operations-io-security-classification-guidance-november-28-2005/">DoD Instruction 0-3600.02 “Information Operations (IO) Security Classification Guidance,” November 28, 2005</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3>Background</h3>
<p>This Instruction:</p>
<p>1.1 . Reissues reference (a) to implement policy, assign responsibilities, and prescribe guidance on the classification methodology for Information Operations (10) programs and capabilities within the Department of Defense.</p>
<p>1.2. Establishes guidance for proper protection of 10 activities.</p>
<p>1.3. Identifies and provides classification guidance on categories of IO activities. While this Instruction identifies the classification or classification ·range for specific items of classified information, it is not intended to be used as an itemized guide for applying Special Access Program (SAP) prota;tive measures. If required, SAP protective measures shall be in addition to the protections that are cited in this Instruction. 1.4. Addresses the relationship between the protection level for 10 activities and the security classification for specific elements of information within these activities. It clarifies information and requirements from a number of sources to identify the appropriate protection architecture for IO activities.</p>
<p>1.5. Constitutes authority and, in the absence of an approved program classification guide that provides specific classification instructions, shall be cited as the basis for derivative classification about, or declassification of, DoD information and material involved in 10.</p>
<h3>DoD Instruction 0-3600.02</h3>
<p>As of October 2016, this version is the latest.</p>
<p><img decoding="async" src="https://www.theblackvault.com/images/pdf.gif" /> <a href="https://documents.theblackvault.com/documents/dod/14-F-1161.pdf">DoD Instruction 0-3600.02 &#8220;Information Operations (IO) Security Classification Guidance, November 28, 2005</a> [22 Pages, 4.9MB]</p>
<p>https://documents.theblackvault.com/documents/dod/14-F-1161.pdf</p><p>The post <a href="https://www.theblackvault.com/documentarchive/dod-instruction-0-3600-02-information-operations-io-security-classification-guidance-november-28-2005/">DoD Instruction 0-3600.02 “Information Operations (IO) Security Classification Guidance,” November 28, 2005</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3299</post-id>	</item>
		<item>
		<title>Federal Bureau of Investigation (FBI) Foreign Government Information Classification Guide</title>
		<link>https://www.theblackvault.com/documentarchive/federal-bureau-investigation-fbi-foreign-government-information-classification-guide/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=federal-bureau-investigation-fbi-foreign-government-information-classification-guide</link>
		
		<dc:creator><![CDATA[John Greenewald]]></dc:creator>
		<pubDate>Wed, 22 Jun 2016 23:40:52 +0000</pubDate>
				<category><![CDATA[FBI Files / Domestic & Foreign Intelligence]]></category>
		<category><![CDATA[Federal Bureau of Investigation (FBI) Collection]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[classification]]></category>
		<category><![CDATA[foreign]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[world governments]]></category>
		<guid isPermaLink="false">http://www.theblackvault.com/documentarchive/?p=2540</guid>

					<description><![CDATA[<p>Background The Federal Bureau of Investigation (FBI) Foreign Government Information Classification Guide (FGICG) provides guidance concerning the classification and level of protection afforded to foreign government information. The FGICG is not intended to provide specific guidance concerning the handling, safeguarding, transport, declassification and downgrading, destruction, or administration of classified material, whether in paper or electronic form. Specific guidance concerning these topics [...]</p>
<p>The post <a href="https://www.theblackvault.com/documentarchive/federal-bureau-investigation-fbi-foreign-government-information-classification-guide/">Federal Bureau of Investigation (FBI) Foreign Government Information Classification Guide</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3>Background</h3>
<p>The Federal Bureau of Investigation (FBI) Foreign Government Information Classification Guide (FGICG) provides guidance concerning the classification and level of protection afforded to foreign government information. The FGICG is not intended to provide specific guidance concerning the handling, safeguarding, transport, declassification and downgrading, destruction, or administration of classified material, whether in paper or electronic form. Specific guidance concerning these topics is available in Executive Order (EO) 13526, &#8220;Classified National Security Information;&#8221; Department of Justice (DOJ) Security Program Operating Manual (SPOM); FBI Security Policy Manual (SPM); FBI Automatic Declassification Guide; FBI Foreign Dissemination Manual (FDM); Federal Register, Part V, National Archives and Records Administration (NARA), Information Security Oversight Office (ISOO) Final Rule (32 CFR Parts 2001 and 2003); and other documents referenced herein.</p>
<p>The duration of classification, classification markings, and other requirements of EO 13526, are to be applied to information classified pursuant to this guide, in accordance with the SPM and other approved FBI policies and procedures.</p>
<h3>Declassified Documents</h3>
<p><img decoding="async" src="https://www.theblackvault.com/images/pdf.gif" /> <a href="https://documents.theblackvault.com/documents/fbifiles/FBI-G1Guide.pdf">Federal Bureau of Investigation (FBI) Foreign Government Information Classification Guide, June 20, 2012</a> [66 Pages, 2.9MB]</p>
<p>https://documents.theblackvault.com/documents/fbifiles/FBI-G1Guide.pdf</p>
<p>&nbsp;</p><p>The post <a href="https://www.theblackvault.com/documentarchive/federal-bureau-investigation-fbi-foreign-government-information-classification-guide/">Federal Bureau of Investigation (FBI) Foreign Government Information Classification Guide</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2540</post-id>	</item>
		<item>
		<title>VUPEN / NSA Contracts</title>
		<link>https://www.theblackvault.com/documentarchive/vupen-nsa-contracts/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=vupen-nsa-contracts</link>
		
		<dc:creator><![CDATA[John Greenewald]]></dc:creator>
		<pubDate>Sat, 28 Feb 2015 18:26:26 +0000</pubDate>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[National Security Agency (NSA) Collection]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[National Security Agency]]></category>
		<category><![CDATA[NSA]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[VUPEN]]></category>
		<guid isPermaLink="false">http://www.theblackvault.com/documentarchive/?p=823</guid>

					<description><![CDATA[<p>In September of 2013, news surfaced that the National Security Agency (NSA) entered a one year contract with the French security firm VUPEN, for a one-year subscription to the company’s “binary analysis and exploits service”. According to their website: &#8220;VUPEN is the leading provider of defensive and offensive cyber security intelligence and advanced vulnerability research. While [...]</p>
<p>The post <a href="https://www.theblackvault.com/documentarchive/vupen-nsa-contracts/">VUPEN / NSA Contracts</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>In September of 2013, news surfaced that the National Security Agency (NSA) entered a one year contract with the French security firm VUPEN, for a one-year subscription to the company’s “binary analysis and exploits service”.</p>
<p>According to their website:</p>
<blockquote><p><em><strong>&#8220;VUPEN is the leading provider of defensive and offensive cyber security intelligence and advanced vulnerability research. While other companies in the vulnerability intelligence industry mainly act as brokers who buy vulnerabilities from third-party researchers and then sell them to their customers, all VUPEN&#8217;s vulnerability intelligence results exclusively from our internal and in-house research efforts conducted by our team of world-class researchers.&#8221;</strong></em></p></blockquote>
<p>With this news, I filed a FOIA request for ALL current contracts between VUPEN and the NSA.  Below are the responsive documents &#8212; many declassified for the first time on this request.</p>
<p><img decoding="async" src="https://www.theblackvault.com/images/pdf.gif" alt="" /> <a href="https://documents.theblackvault.com/documents/nsa/nsavupen.pdf">NSA Contracts with VUPEN, released October 2013</a> [31 Pages, 6.99MB]</p>
<p><a href="https://documents.theblackvault.com/documents/nsa/nsavupen.pdf">https://documents.theblackvault.com/documents/nsa/nsavupen.pdf</a></p><p>The post <a href="https://www.theblackvault.com/documentarchive/vupen-nsa-contracts/">VUPEN / NSA Contracts</a> first appeared on <a href="https://www.theblackvault.com/documentarchive">The Black Vault</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">823</post-id>	</item>
	</channel>
</rss>
