CBP Initiates IT Access Control Overhaul Following Inspector General's Vulnerability Report
U.S. Customs and Border Protection (CBP) has begun an overhaul of its IT access control systems in response to an audit by the Department of Homeland Security’s (DHS) Office of Inspector General (OIG). The OIG report found significant vulnerabilities, including that over 76,000 CBP network users, comprising employees, contractors, and other personnel, had access to a highly privileged service account. This oversight allowed any user to alter CBP account passwords, change system access permissions, modify security configurations, and potentially take over accounts with access to sensitive data. The OIG also noted that CBP failed to review and remove access for separated personnel or those who changed roles, and struggled to identify privileged accounts accurately. CBP attributed these issues to human error and difficulties in tracking account changes over time. In response, CBP has revoked identified excessive privileges, performed validation scans, and set an end-of-August deadline for implementing new sec...