News

Congress: Terror Threat System Full of Flaws

A U.S. House subcommittee is charging that a $500 million IT project intended to "connect the dots" on terrorists and help prevent another 9/11 is a failure

By Patrick Thibodeau, Computerworld

August 28, 2008CSO

A U.S. House subcommittee is charging that a $500 million IT project intended to "connect the dots" on terrorists and help prevent another 9/11 is a failure; it can't even handle basic Boolean search terms, such as "and," "or" and "not."

Allegations of waste and mismanagement were outlined in a staff memo and letter (download PDF) from the Subcommittee on Investigations and Oversight, which is part of the Committee on Science and Technology. The material was released last week in what is a usually a quiet month for Congress during its August recess.

The bulk of the subcommittee's charges come from a memo (download PDF) prepared by subcommittee staff about a data integration project called Railhead, which is intended to help intelligence and law enforcement agencies uncover terrorist plots.

Railhead, due to be ready by year's end, was supposed to combine and upgrade existing databases called TIDE (Terrorist Identities Datamart Environment; download PDF) and improve terrorism-fighting capabilities. But the project is in such bad shape -- suffering from delays and cost overruns -- that Subcommittee Chairman Brad Miller (D-N.C.) said, "There may be current efforts under way to close down Railhead completely."

Miller's comment was included in a letter he wrote to Edward Maguire, inspector general for the Office of the Director of National Intelligence. Miller said he wants Maguire to investigate the project.

"The end result is a current system used to identify terrorist threats that has been crippled by technical flaws and a new system that, if actually deployed, will leave our country more vulnerable than the existing yet flawed system in operation today," wrote Miller.

The subcommittee makes a case for investigation through a variety of documents it obtained, including user-group meeting minutes, e-mails, internal blog postings and technical reports that raise issues with various aspects of the project. The lead systems integrator for Railhead is The Boeing Co.'s Space and Intelligence Systems Mission division.

Among the issues Miller wants the inspector general to probe is how Railhead is being used. His letter raises questions about money used by Boeing to renovate a building.

Railhead software was tested by the Hewlett-Packard Quality Center, which found that it "passed 148 tasks, but did not complete 26 others and failed 42," he said. Specific problems included a failure to create reports, as well as "find non-exact matches for key entities, such as a suspected terrorist's name," the memo said. "Incredibly, it also failed to demonstrate the ability to use basic Boolean search terms such as and, or and not."

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WEBCAST
The Surest Path to Effective and Efficient Compliance

VeriSignIn this webcast, we explore why and how — with best practices, practical tips and solutions that work — to ease your compliance challenge.

» View the webcast

Featured Sponsors
Sponsored Links

Revolutionizing Endpoint Security with a Single Agent

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

The Case for Business Software Assurance ~ Securing Your Applications

Configuration Assessment: Choosing the Right Solution

Envision Identity-Based Access Control for the Datacenter

Rolling the dice with your security? Take the Self-Assessment Test now

Digital Identity Protection and Data Security Get Personal

Solving Online Credit Fraud Using Device Reputation

Think your data is safe? Think again. It's time to Outthink the Threat. Get eBook now

IDC Defines an Identity and Access Management Submarket

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era

Data Protection: Challenges for the Traveling User

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

IS/IT Project Mgt. Credentials From Villanova - 100% Online

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Key strategies for C-level executives and security staff

Envision Identity-Based Access Control for the Datacenter

Using Likewise to Comply with PCI Data Security Standard

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

Diebold: Frost & Sullivan Global Physical Security Systems Integrator of the Year

Welcome to the age of Service-Oriented Security (SOS)

Enabling Compliance with Converged Mainframe Security and Storage