By IAITAM, Special for USDR
What questions should the Justice Department and Congress ask as they probe the lost emails of Lois Lerner at the IRS? The roadmap is clear to International Association of Information Technology Asset Managers (IAITAM) experts, who deal with issues of this sort on a daily basis.
Dr. Barbara Rembiesa, the president and founder of IAITAM, urges investigators at the DOJ and in Congress to focus on the following:
- What happened to the IRS’s IT Asset Managers who appear to have disappeared at a key juncture? At organizations such as the IRS, the ordering of a hard drive destruction and the documenting of the process would be handled by trained IT Asset Managers — professionals with special training and certification. IAITAM’s records show that at least three IT Asset Managers who were working at the IRS prior to the 13 May 2013 Inspector General Report were shuffled out from those positions around the time of that report. Investigators need to determine if these in-house IT Asset Managers were removed from the picture as the IRS email investigation heated up.
- Where is the documentation proving that Lois Lerner’s hard drive was wiped or destroyed? Proper IT Asset Management requires clear proof and records of destruction when drives are wiped or destroyed. Until that documentation is provided, the hard drives should be considered lost, not destroyed.
- Were the drives destroyed by an outside vendor or firm? If so, by who, and can they verify the destruction? For federal government agencies, this kind of arrangement, in which a specialized IT Asset Destruction (ITAD) firm is called in to complete a hard drive wipe or destruction, is not unusual. If an ITAD firm was relied upon by the IRS in the case of the Lerner drives, it would add an entire second layer of documentation of the decision-making process leading up to the hard drive destruction.
- What are the IRS’s specific policies and procedures on document retention when hard drives are damaged or destroyed? In large organizations, hard drives don’t just get bulk erased. The IRS almost certainly has specific policies and procedures for hard drive reclamation and/or destruction. If the process was followed properly, there will documentation evidencing failed attempts to recover data from the hard drives and proper handling for destruction.
- What is the disaster recovery policy at the IRS? Data loss at large organizations is not uncommon. What would be unusual is the lack of a way for data to be recovered. Investigators need to understand exactly what the IRS would typically do in this kind of situation, if it was done, and, if not, why not.
- Where are Lois Lerner’s emails from her Blackberry device? Are those secure? What is on the enterprise server? It is difficult to imagine that none of the emails in question were done on a mobile basis. If so, there may be a freestanding stream of email records that would not be impacted by the Lerner hard drive loss.
On June 26, 2014 IAITAM put out a release raising grave concerns about the plausibility of the IRS story about the Lerner hard drive. Go to http://bit.ly/iaitamnews for more information.
The International Association of Information Technology Asset Managers, Inc. is the professional association for individuals and organizations involved in any aspect of IT Asset Management, Software Asset Management (SAM), Hardware Asset Management, Mobile Asset Management, IT Asset Disposition and the lifecycle processes supporting IT Asset Management in organizations of every size and industry across the globe. IAITAM certifications are the only IT Asset Management certifications that are recognized worldwide. For more information, visit www.iaitam.org, or the IAITAM mobile app on Google Play or the iTunes App Store.