DODIG-2015-046: Navy’s SIPRNET gaps confirmed, corrective actions unknown

Ninety Pages, Three Exemptions, Four Years

The audit was finalized on December 10, 2014. Carol N. German, Assistant Inspector General for Readiness and Cyber Operations, signed the transmittal memorandum on behalf of the Office of the Deputy Inspector General for Audit. The report runs to 90 pages and carries the designation DODIG-2015-046. Its full title, visible in the unredacted portions, is “Navy Commands Need to Improve Logical and Physical Controls Protecting SIPRNET Access Points.”

Shawn Musgrave of MuckRock News filed a Freedom of Information Act request under case number FOIA-2015-00203. The DoD Inspector General’s office logged it as received on December 19, 2014, nine days after the report was finalized. The FOIA response is dated September 12, 2018, approximately three years and eight months after receipt. Mark Dorgan, Division Chief of the FOIA Privacy and Civil Liberties Office, signed it. The response letter states no reason for the duration.

Three statutory exemptions cover the withheld material: 5 U.S.C. § 552(b)(6), protecting personal privacy; § 552(b)(7)(E), shielding law enforcement techniques; and § 552(b)(1), withholding classified information under Executive Order 13526, Section 1.4(g), covering vulnerabilities or capabilities of systems relating to national security. The (b)(1) exemption was applied under that executive order; the DoD OIG processed the redactions accordingly.

SIPRNET, 77,395 Users, and a Hewlett Packard Contract

SIPRNET, the Secret Internet Protocol Router Network, carried the Navy’s command-and-control communications at the classified Secret level. The audit examined security of the network’s access points across the continental United States and Hawaii.

Two categories of control were under review. Physical controls are the locks, guards, and window blinds that deter or delay access to network hardware. Logical controls are system-based mechanisms: firewalls, permission settings, usernames and passwords. Both applied to the Navy Marine Corps Intranet, which carried approximately 77,395 users at the time of the review and was accredited in October 2012 under DoD Instruction 8510.01. Hewlett Packard Enterprise Services operated the network under a continuity contract awarded in October 2011, expected to expire in September 2014, three months before the audit was finalized. The released document does not address what happened to that contract after expiration.

Two Findings, One Silence

The audit produced two sets of findings. Finding A carries the title “Navy Commands Did Not Effectively Protect SIPRNET Access Points,” which appears in the unredacted portions. Finding B is acknowledged in the document’s structure. The conclusions of both are stated; the supporting evidentiary material is almost entirely blacked out.

Recommendations went to four named officials: the Under Secretary of Defense for Intelligence, the Commander of U.S. Cyber Command, the Deputy Under Secretary of the Navy (Policy), and the Commander of U.S. Fleet Cyber Command/Tenth Fleet. Both the Under Secretary of Defense for Intelligence and the Commander of U.S. Cyber Command partially addressed Recommendation A-1 and were asked to submit additional comments by January 12, 2015. Whether those comments arrived is not recorded in the released document.

The report also records a complete absence of response to Recommendation A-6. The command to which it was directed is named in the report, but the name falls under a redaction. Under DoD Directive 7650.3, which governs resolution of Inspector General recommendations, unresolved findings are subject to a formal follow-on process. Whether that process was initiated for A-6 is not addressed in any publicly available document.

One further timing issue appears in the record. Draft comments on the report arrived from one management office after the January 12, 2015 deadline, too late for incorporation into the final version. The report states that if no additional comments were received, those late draft comments would stand as the formal management response. The released document does not confirm whether additional comments were later provided. Late responses of this kind are common in large-organization audits: extended internal review chains and competing workloads routinely push replies past stated deadlines. Nothing in the released document contradicts that explanation.

What the Record Cannot Say

A follow-up audit, DODIG-2019-063, dated March 18, 2019, found that Army, Navy, and Air Force officials had not corrected the problems identified in prior DoD OIG reports on SIPRNET access-point security. Which specific recommendations from DODIG-2015-046 remained open is not confirmed in the publicly available text of that follow-up.

From the released pages of DODIG-2015-046, several things cannot be established: the specific vulnerabilities described in Finding A and Finding B; whether Recommendation A-6 ever received a response; whether the late draft comments were formally accepted as a final management response; and the status of the Hewlett Packard Enterprise Services contract after its September 2014 expiration. The redactions were applied under the national security classification exemption. DODIG-2015-046 remains listed as classified on the DoD OIG’s reports page, and no declassification date appears in any document in the public record.