Fed Board's Slow Response to Data Removal Raises Security Concerns
The Federal Reserve's Office of Inspector General (OIG) has flagged concerns about the central bank's diligence in resolving an information security situation from 2024. The OIG issued a management alert prior to completing its planned audit, citing gaps in the board's ability to respond swiftly to potential information removal incidents.
The incident involved a departing division of international finance employee who potentially removed classified and sensitive information, including Federal Open Market Committee (FOMC) data. The employee had announced plans to retire and requested to remove files before their departure, but the Fed board was unaware of these travel plans.
The OIG learned of this incident in July 2025, a year after the employee retired. The watchdog offered recommendations to prevent and address future incidents, including enhancing governance of the Fed's information security program and strengthening enforcement.
The OIG's report highlighted systemic concerns about the offboarding process, including information security risks and control breakdowns. The board's governance of its information security program and enforcement of controls lack clarity, driven by conflicting understanding of escalation and resolution responsibilities.