Could Snowden Have Been Stopped In 2009?
Hugh Pickens DOT Com writes "The NYT reports that when Edward Snowden was working as a CIA technician in Geneva in 2009, his supervisor wrote a derogatory report in his personnel file, noting a distinct change in the young man's behavior and work habits, as well as a troubling suspicion that Snowden was trying to break into classified computer files to which he was not authorized to have access. But the red flags went unheeded and Snowden left the CIA to become a contractor for the NSA so that four years later he could leak thousands of classified documents. In hindsight, officials say, the report by Snowden's supervisor and the agency's suspicions might have been the first serious warnings of the disclosures to come, and the biggest missed opportunity to review Snowden's top-secret clearance or at least put his future work at the NSA under much greater scrutiny. Had Booz Allen or the NSA seen Snowden's CIA file before hiring him, it almost certainly would have affected his employment says Dashiell Bennett. 'The weakness of the system was if derogatory information came in, he could still keep his security clearance and move to another job, and the information wasn't passed on,' says a Republican lawmaker who has been briefed on Snowden's activities. It's difficult to tell what would have happened had NSA supervisors been made aware of the warning the CIA issued Snowden in what is called a 'derog' in federal personnel policy parlance."
Fixed link: OT but informative: Timeline of Edward Snowden's revelations
I worked for a Federal Government Contractor. I administered a number of servers--the one with financial information and one with Classified information. I found another employee trying to break into my servers on a few occasions and reported this security breach to management. The CIO said "Good catch" but did nothing to the employee. (Well the CIO did give a promotion to the offending employee.) As a manager, this person set up a rogue server between Security Audits and continued his attempts to break into my servers on a regular basis. I continued to tell management and added notifications to Cyber-Security. Nothing was ever done about these attempted breaches.
Federal Government Contractors do not report problems to the Federal Department if they can help it. The Feds will investigate and that means a huge disruption of operations, productivity and costs the contractor a lot of money. So, problem people are left unreported, unchallenged, and on-the-payroll. It sucks to work for a Federal Government Contractor when you/your job are experiencing internal threats but it is Standard Operating Procedure (SOP).