What is your e-mail address?

My e-mail address is:

Do you have a password?

Forgot your password? Click here
close

IG: U.S. Visit RFID needs better security controls

Use of radio frequency identification tags within the U.S. Visitor and Immigrant Status Indicator Technology program has been applied with privacy protections but has not been adequately configured and tested to ensure that those protections are effective, according to a new report from the Homeland Security Department inspector general.

The RFID tags currently are being used on Form I-94 documents issued to foreign visitors at several U.S. land ports of entry. As of December 31, 2005, US Visit had issued 149,414 RFID-enabled Form-I-94s to travelers, DHS Inspector General Richard Skinner said.

The RFID on the Form I-94s was designed with privacy protections, the inspector general said. Specifically, the RFID tag, which is a small computer chip, contains only a number. This number must be viewed within US Visit's secure database to obtain personal information on the visitor.

Overall, the inspector general judged these privacy protections to be effective, and to present no 'high or medium' information security vulnerabilities.

However, the report identified vulnerabilities in US Visit's password management and user access system that allows US Visit employees to access the personal information contained in the database.

'U.S. Visit has not properly configured its Automated Identification Management System database to ensure that data captured and stored is properly protected,' the inspector general wrote.

Furthermore, US Visit has not prepared and tested contingency plans to make sure that the database can be restored following a disruption, the report said.

Alice Lipowicz is a staff writer for Government Computer News' sister publication, Washington Technology.

About the Author

Alice Lipowicz is a staff writer covering government 2.0, homeland security and other IT policies for Federal Computer Week. Follow her on Twitter: @AliceLipowicz.

Reader Comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Your Name:(optional)
Your Email:(optional)
Your Location:(optional)
Comment:
Please type the letters/numbers you see above

GCN eNewsletters

Editorial Webcasts

  • Service Consolidation: How to Avoid Basic Pitfalls of Shared Services Register Now

    This is the first webcast of the Series “Future First: Three Steps to Data Center Transformation”. Plan to attend this webcast to support your agency efforts to design a practical roadmap for consolidation of resources and shared services to meet current and emerging program demands. Learn from those who are doing to help you evaluate services in your current operations that may lend themselves to future shared service arrangements. Read more