Fed Watchdog Flags Gaps in Security Incident Oversight
The Federal Reserve's Office of the Inspector General has found significant gaps in how its divisions coordinate to identify and resolve information security incidents. A recent report highlighted a sensitive information security incident that remained unresolved for over a year due to unclear responsibilities among Fed divisions.
The incident involved a former staffer in the Division of International Finance who potentially removed hundreds of documents containing sensitive and classified information from the board and the Federal Open Market Committee using an unencrypted USB device. The employee triggered 279 data loss prevention alerts, with 111 potentially involving FOMC classified information.
According to the report, multiple Fed divisions responded to and handled the matter differently, resulting in a general lack of clarity about how to proceed in addressing the incident. This lack of clarity contributed to the incident remaining unresolved for over a year.
The Inspector General's report noted that the same employee had attempted to export classified Fed documents in previous years. In 2021, the Division of International Finance was notified that the employee had copied sensitive FOMC classified files to an unencrypted USB device.
Going forward, the Fed's inspector general recommends strengthening incident-handling controls to prevent future information security incidents involving the unauthorized removal of sensitive information by departing employees. The Fed said it plans to implement processes and protocols to clarify roles and strengthen the escalation of alerts by the first quarter of 2027.