Bribery case creates possible IT security nightmare in D.C.

13.03.2009
After being Thursday, the District of Columbia's top information security official is being held without bail, partly because of uncertainty about whether he still has the ability to access the district's IT systems.

That's just one of many potential security issues facing D.C. government officials after the and arrested Yusuf Acar, its acting chief security officer, and a second man in connection with an alleged bribery scheme.

For instance, Acar had access to personnel data and other confidential information in the district's systems as part of his job. Court documents submitted by the FBI claim that several other district employees were also involved in the bribery scheme. Security analysts warn that Acar and his alleged accomplices could have created backdoors into systems. And since the alleged scheme included misdoings on a purchase of security software, there may be questions about the quality of the district's security tools.

From an IT security standpoint, municipal officials in Washington have a nightmare on their hands, said Johannes Ullrich, chief technology officer at the SANS Institute's Internet Storm Center in Bethesda, Md.

As a security official in the IT department, Acar would have had widespread access to the district's networks and probably also its databases and password files, Ullrich said. In addition, he would have been privy to details about its user-access-control procedures. That level of access and knowledge could have enabled him to do a variety of things, virtually undetected, if he so chose, according to Ullrich.

Without a thorough forensics investigation, there's no telling whether anything nefarious was actually done to the district's systems, Ullrich noted. He said some of the classic actions that D.C. officials should look for include installing backdoors, stealing data and designed to destroy data after a specified period of time has elapsed. Another is tricking other users into installing malware or compromised devices on their systems.