Clinton email flap highlights issues of shadow IT

US secretary of state Hillary Clinton (C) looks at her mobile phone after attending a Russia – US meeting on the sidelines of the 43rd annual Association of South East Asian Nations (ASEAN) Ministering Meeting in Hanoi on July 23, 2010. Asia-Pacific’s biggest security dialogue convenes in Vietnam with ructions over North Korea and friction between the United States and China likely to dominate proceedings. AFP PHOTO / POOL / Na Son Nguyen (Photo credit should read Na Son Nguyen/AFP/Getty Images)

As first reported by the New York Times earlier this week, Clinton used a personal email account throughout her four-year tenure at State, which came to light after aides officially submitted 55,000 pages of emails to the department and the National Archives and Records Administration.

The Times pointed out that Clinton is not the first government executive to use personal email but the exclusive use raises concerns.

“I can recall no instance in my time at the National Archives when a high-ranking official at an executive branch agency solely used a personal email account for the transaction of government business,” former NARA Director of Litigation Jason Baron told the Times.

While pundits and politicians are debating the ethics and legality of this, it also raises questions about the security of Clinton’s communications.

“This news is yet another example of the lines blurring between work and personal lives and should serve as a wake-up call to federal IT departments,” said Bob Stevens, vice president of federal systems at Lookout. “This trend towards mobility has clear benefits but it also adds a nuanced layer to not just email security, but all security.”

US Secretary of State Hillary Clinton (2nd R) checks her Blackberry phone alongside Korean Foreign Minister Kim Sung-hwan (R) as she attends the Fourth High Level Forum on Aid Effectiveness in Busan, Korea, November 30, 2011. AFP PHOTO / POOL / Saul LOEB (Photo credit should read SAUL LOEB/AFP/Getty Images)

Stevens noted that mobile devices, by their nature, move about and touch multiple networks as they do so. Since some networks are less secure than others, it becomes even more important to use secure programs and services to communicate.

“The reality is that every organization has a BYOD program — whether they think they do or not,” Stevens said. “Now’s the time to shore up the systems and enable mobility without sacrificing security.”

Subsequent reports revealed that Clinton maintained her own server, but whether that server was more or less secure than commercial or federal email offerings is still unknown.

The use of unauthorized apps and devices will proliferate until IT acquisition processes catch up to the speed of private sector innovation or the penalties for violating use policies become more severe.

“The tools out there are so cheap, it’s like whack-a-mole trying to keep up,” GSA CIO Sonny Hashmi said during a panel discussion on shadow IT in September.

More: CIOs adopt varied approaches to ‘shadow IT’

Hashmi said he leans toward allowing unauthorized tech, so long as the users report it and work with the CIO’s office to ensure it meets security requirements.

“If I create an environment where they get a beat-down for using shadow IT, they’ll hide it,” he said. “Then we’ll get into a much worse situation five years later with a major breach.”

It is unclear whether Clinton cleared her personal email server with State Department security officials.

About 

Aaron Boyd is an awarding-winning journalist currently serving as editor of Federal Times — a Washington, D.C. institution covering federal workforce and contracting for more than 50 years — and Fifth Domain — a news and information hub focused on cybersecurity and cyberwar from a civilian, military and international perspective.