Related to Sentinel
ESOC provides oversight I believe
(from 2019)
*note
"Neither ESOC nor the vendor of the application was aware of the existence, origin, or purpose of this database. OIG analysis of the text messages in the database compared to ESOC productions
of text messages during the same time periods when the collection tool was functional identified a significant number of text messages found in the database that were missing from the ESOC
production. Furthermore, the Subject Matter Expert with whom the OIG consulted in connection with its forensic analysis of the devices identified additional potential security vulnerabilities
regarding the collection application. The OIG has provided these findings to the FBI. "
PROCEDURAL REFORM RECOMMENDATION FOR
THE FEDERAL BUREAU OF INVESTIGATION
SYNOPSIS
The Federal Bureau of Investigation (FBI), Enterprise Security Operations Center (ESOC) uses a commercial, off-the-shelf, automated application to wirelessly collect text messages sent to or from FBI-issued mobile devices. The application is supposed to collect the messages and store them so they are retained by ESOC. ESOC would then have the ability to produce text messages during the discovery process of criminal and civil matters, as well as for internal investigations. During the Office of the Inspector General’s (OIG) work that resulted in the report, A Review of Various Actions by the Federal Bureau of Investigation and Department
of Justice in Advance of the 2016 Election,
https://www.justice.gov/file/1071991/download (Preelection Review), the OIG found issues with the reliability of the collection application. In addition, unknown to the FBI, the OIG found that FBI text messages were saved to a database on the devices, some of which were not captured by the collection application. The OIG identified this, and other concerns, as security vulnerabilities. The OIG described these issues in its Report of Investigation: Recovery of Text Messages from Certain FBI Mobile Devices,
https://oig.justice.gov/reports/2018/i-2018-003523.pdf, in which we stated that the OIG would be submitting a procedural reform recommendation to the FBI relating to the retention of electronic
communications. We are now doing so.
DETAILS
The Problem
The OIG requested from the FBI text messages of, among others, two employees in connection with the Pre-election Review. When the OIG received the text message production from FBI, there was a time period of several months for which FBI did not produce text messages for mobile devices used by the two FBI employees. The FBI informed the OIG that it was aware that there were deficiencies in its collection application and that it was changing the model of the mobile device issued to FBI employees as part of a regular technical refresh and to mitigate the problem. However, the OIG later learned that, even after upgrading to new devices, the data collection tool utilized by the FBI was still not reliably collecting text messages from approximately 10 percent of more than 31,000 FBI-issued mobile devices. In addition, during the OIG’s forensic examination of FBI mobile devices that were used by the two employees, the OIG discovered a database on the mobile devices containing a plain text repository of a substantial number of text messages sent and received by those devices.
2
Neither ESOC nor the vendor of the application was aware of the existence, origin, or purpose of this database. OIG analysis of the text messages in the database compared to ESOC productions of text messages during the same time periods when the collection tool was functional identified a significant number of text messages found in the database that were missing from the ESOC production. Furthermore, the Subject Matter Expert with whom the OIG consulted in connection with its forensic analysis of the devices identified additional potential security vulnerabilities regarding the collection application. The OIG has provided these findings to the FBI.
https://oig.justice.gov/reports/2019/i1902.pdf
What is this application?
Who is the Vendor?
Is the System comprismised?
cont