The FBI is apparently not great at keeping its own memory systems secure

USB Sticks
Vilken sticka innehåller malware? Det är inte helt lätt att veta (Image credit: Future)

The FBI has “significant weaknesses” in how it handles storage devices for digital media, as well as how it disposes of the media containing sensitive or classified information, a new report has claimed.

Findings from the Department of Justice’s Office of the Inspector General (OIG) say the FBI does not have adequate policies and procedures, or controls, to account for electronic storage media extracted from larger devices and thumb drives.

Furthermore, it does not label its electronic storage media with the appropriate NSI classification, or SBU levels.

New FBI directive

The law enforcement agency did not dispute the findings, and has instead promised to do better.

“Our audit found that the FBI is not properly securing classified NSI or SBU information and is neither marking all electronic storage media as required, nor accounting for this media consistent with FBI internal policies and Department of Justice (DOJ) guidance,” the report states. “The lack of accountability of this electronic storage media is compounded by inadequate internal physical access and security controls at the Facility, potentially placing these media at risk of loss or theft without the possibility of detection.”

Ultimately, the FBI needs to improve the internal physical access and security controls in relevant areas at the facility, the document claims.

In the audit, the OIG suggested the FBI revises its procedures to make sure all electronic storage media containing sensitive or classified information are appropriately accounted for, tracked, timely sanitized, and destroyed, to implement controls to make sure electronic storage media are properly marked with the right NSI classification level markings, and to overall strengthen its control and practice.

The FBI acknowledged the findings, BleepingComputer added, and said it was currently building a new directive, called “Physical Control and Destruction of Classified and Sensitive Electronic Devices and Material Policy Directive,” which should address these issues.

Via BleepingComputer

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
OneDrive on a Laptop
Microsoft One Drive for Business might not be storing your data as securely as you might hope
Hacker silhouette working on a laptop with North Korean flag on the background
FBI claims North Korean workers are hacking the US companies which hired them
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
data recovery
Ghost ransomware has hit firms in over 70 countries, FBI and CISA warn
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)