Lawmakers ask White House to release internal cybersecurity review

WASHINGTON, DC – MARCH 19: House Oversight and Government Reform Committee Chairman Jason Chaffetz (R-UT) (R) and ranking member Rep. Elijah Cummings (D-MD) talk before a hearing about the Department of Homeland Security’s policies regarding apprehension, detention and release of illegal immigrants in the Rayburn House Office Building on Capitol Hill March 19, 2015 in Washington, DC. Immigration and Customs Enforcement Director Sarah Saldana testifies and faced aggressive questioning about her agencies policy of discretion in releasing people convicted of misdemeanors and felonies. (Photo by Chip Somodevilla/Getty Images)

The administration has been ramping up its cybersecurity efforts since the massive breach of Office of Personnel Management networks last year, including issuing a number of policies and directives for agencies to shore up their defenses.

But while most federal agencies’ cybersecurity is assessed yearly in the Federal Information Security Management Act (FISMA) reports, the Executive Office of the President (EOP) has yet submit a report.

Reps. Jason Chaffetz, R-Utah, and Elijah Cummings, D-Md., chairman and ranking member, respectively, of the House Committee on Oversight and Government Reform, sent a letter to White House Chief of Staff Denis McDonough July 26 requesting a copy of EOP’s FISMA report or, if it doesn’t exist, an explanation of why the office is exempt.

Read: Letter to White House Chief of Staff Denis McDonough

The letter notes all agencies are required by law to submit annual reports to the committee and Office of Management and Budget — which is a part of EOP — and that the term “agency” was intentionally defined broadly in the legislation, which specifically mentions EOP as an example.

“It is especially troubling that EOP has yet to submit its complete FISMA report to the committee, given the agency’s central role in overseeing other federal agencies’ FISMA compliance,” Chaffetz and Cummings wrote. “EOP should be setting an example for agencies in complying with federal information security requirements, not failing in its own compliance with the law.”

During a May 25 Oversight hearing, Federal CIO Tony Scott agreed it would set a bad example if EOP wasn’t complying with the law but asserted that isn’t the case.

“We’re not required by the law,” Scott said while being questioned by Rep. Mark Meadows, R-N.C. “Our legal counsel has given us that opinion,” he said, adding that he has conferred with advisers on this a number of times.

“Your legal counsel doesn’t make the law,” Meadows said.

“If we are required, it sets a bad example, you are correct,” Scott said. But, “Our intent is to comply with the law.”

In their letter, Chaffetz and Cummings also reminded the White House that it is subject to major incident reporting requirements under the latest FISMA update, which requires agencies to notify Congress within seven days of a significant cyber incident. The letter does not assert that any such incidents have occurred and are being withheld.

EOP and OMB did not immediately respond to requests for comment.

Chaffetz and Cummings sent similar letters to each of the major agencies cited in the CFO Act, as well as the Office of the Director of National Intelligence and the CIA reminding them of the upcoming 2016 reports and the December deadline to meet new requirements under the Federal Cybersecurity Enhancement Act.

About 

Aaron Boyd is an awarding-winning journalist currently serving as editor of Federal Times — a Washington, D.C. institution covering federal workforce and contracting for more than 50 years — and Fifth Domain — a news and information hub focused on cybersecurity and cyberwar from a civilian, military and international perspective.