How 18F handles information security and third party applications
1–10 of 16 posts
Re: How 18F handles information security and third party applications
#2> 18F’s use of both OAuth 2.0 and Slack is not in compliance with GSA’s Information Technology Standards Profile, GSA Order CIO P 2160.1E. The order allows information technologies to be approved for use in the GSA IT environment if they comply with GSA’s security, legal, and accessibility requirements. Currently, neither OAuth 2.0 nor Slack are approved for use in the GSA IT standards profile.
> ...
> The OIG makes the following recommendations:
> 1. GSA should cease using Slack and OAuth 2.0 until and unless they are approved for use in the IT Standards Profile.
> 2. GSA should ensure that 18F complies with GSA Order CIO P 2160.1E.
Is 18F no longer using Slack or any other OAuth 2.0 integrations? That would be a shame. Are they working with GSA and the Office of Inspections and Forensic Auditing to clear Slack/OAuth 2.0?
[1]: https://www.gsaig.gov/sites/default/files/ipa-reports/Alert%...
Re: How 18F handles information security and third party applications
#3The 18F post says:
"we reviewed all Google Drive files shared between Slack and Drive, just to be sure nothing was shared that shouldn't have been. Our review indicated no personal health information (PHI), personally identifiable information (PII), trade secrets, or intellectual property was shared."
While the OIG report says:
"[the integration] permitted full access to over 100 GSA Google Drives, resulting in a data breach."
Re: How 18F handles information security and third party applications
#4Here's an important difference. The 18F post says: "we reviewed all Google Drive files shared between Slack and Drive, just to be sure nothing was shared that shouldn't have been. Our review indicated no personal health information (PHI), personally identifiable information (PII), trade secrets, or intellectual property was shared." While the OIG report says: "[the integration] permitted full access to over 100 GSA G…
> situations where persons other than authorized users with an authorized purpose have access or potential access to PII
Re: How 18F handles information security and third party applications
#5Re: How 18F handles information security and third party applications
#6This does not address the core complaint from the breach[1]: > 18F’s use of both OAuth 2.0 and Slack is not in compliance with GSA’s Information Technology Standards Profile, GSA Order CIO P 2160.1E. The order allows information technologies to be approved for use in the GSA IT environment if they comply with GSA’s security, legal, and accessibility requirements. Currently, neither OAuth 2.0 nor Slack are approved fo…
Re: How 18F handles information security and third party applications
#7This does not address the core complaint from the breach[1]: > 18F’s use of both OAuth 2.0 and Slack is not in compliance with GSA’s Information Technology Standards Profile, GSA Order CIO P 2160.1E. The order allows information technologies to be approved for use in the GSA IT environment if they comply with GSA’s security, legal, and accessibility requirements. Currently, neither OAuth 2.0 nor Slack are approved fo…
Re: How 18F handles information security and third party applications
#8Here's an important difference. The 18F post says: "we reviewed all Google Drive files shared between Slack and Drive, just to be sure nothing was shared that shouldn't have been. Our review indicated no personal health information (PHI), personally identifiable information (PII), trade secrets, or intellectual property was shared." While the OIG report says: "[the integration] permitted full access to over 100 GSA G…
Re: How 18F handles information security and third party applications
#9This does not address the core complaint from the breach[1]: > 18F’s use of both OAuth 2.0 and Slack is not in compliance with GSA’s Information Technology Standards Profile, GSA Order CIO P 2160.1E. The order allows information technologies to be approved for use in the GSA IT environment if they comply with GSA’s security, legal, and accessibility requirements. Currently, neither OAuth 2.0 nor Slack are approved fo…
I would imagine this is not so much that OAuth 2.0 is a problem so much as granting the "Drive" scope via OAuth 2.0 grants access to ALL Google Drive files the user has access to.
Re: How 18F handles information security and third party applications
#10The world needs a self-hosted Slack.