Welcome And Why This Matters

SPEAKER_01

Welcome to the CISSP Cybertraining Podcast. Where we provide you the training and tools you need to pass the CISSP exam first. Hi, my name is Sean Gerber. I'm your host of the Action Act Informative Podcast. Join me each week as I provide the information you need to pass the CISSP exam and grow your cybersecurity knowledge. All right, let's get started.

SPEAKER_00

Hey, y'all Sean Gerber with CISSP Cyber Training, and hope you all are having a beautifully blessed day today. Today's Monday. And today is the Monday, July 5th, the day after the 4th of July and the 250th anniversary of the United States. So hope you all had a wonderful weekend. I hope it was relaxing. I hope you didn't lose any appendages in your fireworks escapades. But you know, we are here today, and Monday is gonna be a

The Whistleblower Claim And Timeline

SPEAKER_00

good day. Uh so today we're gonna be talking about some various aspects related to an article I saw from NPR. Now, this again, what we're gonna talk about here is aspects that have not been corroborated. There are, as we'll go through the different points of this, it's still under investigation, so nothing has happened. And this can become very politically charged. The bottom line is that everybody in Washington is trying to get at each other. We all know it. It doesn't matter what side of the fence you are on, they've got dysfunction at the highest levels. And so this is just going to highlight potentially some more dysfunction that affects all of us. So, what is this? What is this article about? So it's how Doge, Department of Government Efficiencies, and the Social Security data whistleblower mapped out and had a bit of a challenge. And we're going to get into this. This came out in March 11th of 2026 through MPR. So, as we all know, every living American Social Security number, date of birth, place of birth, parents' names, is potentially sitting on a personal thumb drive with some doge employee. So that's a claim at the center of this new whistleblower's complaint that's got Congress and the Social Security Administration's own inspector general running two separate investigations at this moment. So we that's a big deal, especially if they're both running it. So there's something that's going to come up, and it'll be like I always say before, where there's smoke, there's fire. Now, there may not be a very big fire, or it could be a monster, but we will see as time plays out. So if you're studying for the CISSP, which I assume if you're listening to this podcast, you are. Stop and pay attention to this one. Okay, this is a isn't a hypothetical exam scenario. This is domain two asset security, playing out in real time on the front page with personal data of hundreds of millions of people on the line. And if you're listening to this in the United States, yeah, probably you. So it's affecting everybody. So I'm going to walk you through what's being reported, and then we're going to go break down exactly which domain two controls were supposedly ignored and why this matters to you. Whether you're sitting for the CISSP exam or you're sitting in a CISO chair, this is going to affect you in some form or fashion. Okay, so what exactly is being reported? So here's the timeline as it is reported. Back in January of 2026, the Social Security Administration admitted in an ongoing court case that Doge employees, again, Department of Government Efficiency, had secretly and improperly shared sensitive personal data back in 2025. The agency admitted it couldn't even verify how far the violations went back. So that's a problem when you can't even verify that. The two doge staffers were referred to a federal watchdog for potential hatch act violations tied to the use of data for political purposes. So then in 2025, the Social Security's former chief data officer, Charles Borges, filed his own whistleblower complaint, and he alleged that Doge staffers copied a dataset covering more than 300 million Americans into a virtual database. So we all know there's over 350 million in the United States, so I was probably part of the 50 million that didn't get copied. Yeah, right. So they went into a virtual database outside of their normal security protocols, right? So the protocols have been set up, but somebody didn't follow them. So in March of 26th, this escalated again, and a new whistleblower reported first by the Washington Post, alleged that a former Doge software engineer claimed to have retained copies of two of the most sensitive databases the government holds. One is Numident, N-U-M-I-D-E-N-T, which contains social security numbers, dates of birth, places of birth, and parents' names for almost every living American. So that's a big deal, right? And the death master file, records of individuals who have been reported as deceased. So we know that IT folks, and we've, if you're listening to this, you're dealing with them in some form or fashion, are hoarders. Yes, they love to take data and never give it back. And they just like that. For some sort of control reason, they do. And this is probably another situation where, yeah, somebody claimed it and took it. So this whistleblower alleges that the employee claimed at least one of these databases was held on a personal thumb drive. Yay, baby. It claimed to have retained the so-called God-level access to the Social Security Administration even after leaving. So he maintained high levels of privilege access after leaving the organization. So, colleagues, he basically he told colleagues that he wanted to share this data with his private sector employer. That is just not good. I'd be willing to bet this person is probably a younger individual that decided that I would be using this. Now I say that because I'm but I know older people have done it too. It's just one of those things. They don't necessarily always think through the consequences of making these choices. I've had to fire a couple people that were doing this very similar type of thing. They decided for whatever reason that they wanted to keep a bunch of information on a thumb drive. It was just a bad idea. So the Social Security Administration is disputing this. The government, the spokesman spokesperson from the government talking to the MPR, said the allegations were strongly refuted by all named parties and said even the Washington Post couldn't verify the claims. So MPR notes that it does not independently review the whistleblower's complaint either. So again, they're throwing something out there. Now, whether or not they're using it like a trial balloon and throwing something up to see what sticks, you just don't know. But here's what's not in dispute. The Social Security's own Social Security Administration's own inspector general notified Congress on March 6th that it's reviewing an anonymous complaint about a potential misuse of Social Security data. And Congressional Democrats, member Robert Garcia on the House Oversight Committee, and then Senator Ron Wyden of the Senate Finance, and Representatives Larson and Neil on the ways and means have all opened their own expanded inquiries. Now, okay, what does this come down to? It's political, right? There's unfortunately we are the folks that get to deal with this political nonsense because both sides of the House can't figure out what they're doing. And so at the end of the day, we end up having to play the games around this. Unfortunately, there's a lot of information. If this is true, it was taken from the U.S. government. Somebody's head needs to roll, and this is not a good thing. But hopefully the investigation will help address this. So Charles Borges, the former chief data officer, put it bluntly. If these new claims are true, he said you cannot close Pandora's box again. And he's basically saying this was a structural failure of the entire U.S. identity system. And it is. Now it's not just another data breach. That's that's their point in this. And I would agree because of the key factors they have in there. The entire database for all folks, right, that have a social security number and the death database are great ways to be able to do a bunch of bad social engineering. But also, we also know this. Our data has been compromised so many times, I can't count the number. The problem is all of this is in one database, so you can really consider that the data information that is in it is probably pretty good. So that's the story. So now let's put on our domain two hat and let's figure this out.

Training Updates And Cohort Plug

SPEAKER_00

But before we do, I wanted to quick do a quick shout-out for CISSP Cyber Training. A lot of great content out there on my free products as well as my subscription products out there, the essentials in the pro version. Just released some new quiz that for the essentials in pro version. Also, just file finalized finalized, finalized. My cohort number one just closed uh bringing anybody on and it was completely sold out. So I got cohort number two will be kicking off in September. This thing is going to be awesome. I feel very confident that the folks that are gonna be taking it are gonna be very happy with the product that they're gonna be getting out of it. So pretty good stuff. And if you head on over to CISSP Cyber Training, check out what's there and decide if it's something you want. If at a minimum there's a free stuff, go check it out. That stuff will be good for you as well.

Domain 2 Asset Security Framing

SPEAKER_00

Okay, so domain two of the CISSP CBK is asset security. So on the exam, it shows up as data classification, data ownership, custodianship, data states, provisioning, the data lifecycle, and asset retention. So those are the big words, right? But in the real world, it's the difference between we protected this and what we're watching unfold with the Social Security Administration at this moment. So let's go through the failures point by point.

Classification And Ownership Breakdowns

SPEAKER_00

Classification and handling. So Numident and the Death Master file aren't just sensitive. In any sane classification scheme, these are top-tier data mechanisms. And the kind that map directly to identity theft, fraud, and national security exposure at a scale most organizations have never thought to think about. So it's pretty big. So domain two teaches that the data owner, we talk about data owner a lot at CISP cyber training, defines the classification and the classification then drives the handling requirements. The requirements are who can touch it? Where can it live? How can it move? And what controls apply. Every one of these alleged actions here, copying to a personal thumb drive, replicating into an outside database that's sitting outside your organization, retaining access after departure, you're not good, is a handling requirement violation for data that should have had the strictest handling rules the government has. And we knew this going into it, there was going to be potentially some challenges with Doge, especially when you bring all these new people in. That doesn't mean just because you brought them in, they have issues. It probably would have happened anyway. But again, these are important far parts for you to keep in mind related to domain two. So domain two draws a clear line between the data owner accountable for the data classification and its classifications, and the custodians who handle the day-to-day technical protection on the owner's behalf. So the allegation of a former employee could retain God level access after leaving the organization is an ownership and accountability failure on the highest levels. Data ownership isn't just a little title on an org chart. It means someone who's accountable for knowing exactly who has access, revoking the access if the moment's needed, and then being able to prove it. I will tell you that I as when I was working as a CISO, I had more than one situation where we had data owner issues and we had people, the owners or data that was leaving the organization and nobody knew why. And the owners didn't know why. The owners didn't really feel that they were in charge or had the decision rights to make the call on it. So again, this is a big, big deal. So when it comes right down to the Social Security Administration's own admission is that they couldn't even verify the extent of the violation. So this tells you right there, in that no uncertain terms, the accountability chain broke down. Nobody knows. The left hand doesn't know what the right hand is doing. So now we're going to get into the data lifecycle and secure disposal.

Lifecycle Disposal And Purpose Limits

SPEAKER_00

Domain two covers the full data lifecycle. Create, store, use, share, archive, and destroy. The alleged retention of copies on a personal thumb drive after employment ended is a lifecycle failure at the very last stage. Disposal. So once someone's role ends, or once the data has served its authorized purpose, and this is a key part, you've got to remember it served its authorized purpose. It means you don't hoard, you keep it. Domain two says it needs to be securely destroyed or returned with that destruction verified. So I still have a copy on a drive somewhere, should be structurally impossible for data like this. Then Mr. Borges's comment about not being able to close Pandora's box is really a plain English description of a disposal and data remnants failure at the national scale, and not being able to control the data leaving your organization. So domain two also covers protecting data at rest in transit and in use, and then provisioning the resources securely, meaning system storage and access are set up with security baked in from the beginning. From the start, it isn't an afterfact. Anytime you're thinking green field, that's when it's baked in. So copying a federal identity database onto an outside virtual server or onto a removable media, such as a thumb drive, moves that data out of its authorized, right, the place where it was under protection, provision environment entirely. And at that point, none of the Social Security Administration's controls, such as encryption at risk, network monitoring, access logging, that none of that goes with it, right? This is exactly the scenario where asset security practices exist to prevent data from leaving its organizational boundaries. Now we'll say on adding a little bit to all of this is that having a good data loss prevention program can help a lot. And there obviously is a lot of failures that occurred here, a lot of control failures that did not happen that could have been avoided. But having good thought-out process of defense in depth can do a lot to mitigate these kinds of issues. So you need to really truly have an understanding of your organization and the data within it. Now, early reporting alleged Doge staff shared Social Security data with political advocacy groups to basically cross-reference against voter rolls. And this new complaint alleges that the intent to share data with a private sector employer. This is just all sneaky, sneaky stuff, right? So domain two requires that data be used only for the purpose it was collected, not for political purposes. And what it was collected for, what it was classified for, and that any third-party sharing go through a defined, approved data handling and sharing agreements. You should have these agreements in place for any data that is leaving your organization, and you should have them well defined to understand that your employees know what to do in the event something like this was to happen. So sharing identity data for an unrelated political or commercial purpose is a textbook, textbook, purpose limitation violation, regardless of who's doing it and why. And again, it comes down to the fact of do you why did you do this? What was the purpose? Did someone tell you to do it, or did you just decide to do it on your own? So let's walk through how the government data gets

FIPS 199 Impacts And DLP Controls

SPEAKER_00

classified. And this is based on extended content from the FIPS 199 impact tiers. So we're talking about low, moderate, and high. And the limited adverse effects is when you're dealing with anything that has a low impact to your organization. And again, based on FIPS 199. Moderate is where you have severe or adverse effects if compromised. And then finally, you have high. This is where severe or catastrophic effect if it is compromised. So the high confidentiality impact rating is supposed to auto-trigger stronger controls, such as encrypted removable media, stricter logging, tighter change control, and if a thumb drive would have been used using data loss prevention technologies, this data would be held and stopped. And so the trigger basically comes right down to though, is that if this data was never encrypted, then the trigger would have never fired. So it's an important part of any organization is that you do have a solid data loss prevention program in place as well. So let's go into again back to the owners.

Roles And Where Lifecycle Failed

SPEAKER_00

We're going to get into the three parts of this that are who is accountable. You have the owner, the custodian, and the processor. So the data owner is the accountable for the classification and approving access and purpose. This would have been the Social Security Administration's chief data officer, Mr. Borgers. Now, the data custodian, this is the person who technically manages the system and enforces the controls, whatever the owner would define. Now, dealing in the classified world in my back previous life, we had custodians that would then manage the data the classified systems. And they were defined on what they were, and they worked specifically with the data owners to ensure that the data that was there was properly classified. The data processors, these are the folks that handle on the owner's behalf bounds out of scope, purpose, and time limits. This is where the Doge access should have stayed, is that the data processor, and that's where the person that would have been controlling it. But what it proves is that there probably wasn't a processor who was monitoring and managing the data as it was leaving the organization. So again, you really truly need to have all of this baked out. So now data lifecycle, where it potentially broke. So create, that was probably okay. Store, yeah, that was good. But when it came to a flagging piece of this where it was using it. So if someone's using it, this is where access reportedly granted for efficiency review is far narrower than the unrestricted lookup and export. So if you're using data, you should have a very tight window on what you can actually do. Then when you're dealing with sharing, this is where you alleged copying outside of the Social Security Administration had no approved retention schedule. A thumb drive is not an archive, and there should have been some level of data loss prevention on all of this. Any file that would leave that database, it blows my mind that there would have not been more uh warning bells going off. And then when you're dealing with archive, right? So the data that's archiving, do you keep a thumb drive to archive that information? And then finally destroy. This is where allegedly retained access and copies after departure means the destruction was never ever executed. And the other question is, how did why did they even get a thumb drive into that building? None of that stuff should have even occurred. There should have been no way that a person could actually get in there with media. In a previous life, when I was working in a facility's where manufacturing, we actually would super glue the USB sticks closed. So you couldn't even use them. Now, granted, could somebody dig it out? Yes, but we made it so it was painful enough that you would be pretty noticeable if you're pulling a knife out trying to dig out a USB stick. So something there

NIST 800-88 Sanitization Plus Quick Review

SPEAKER_00

to consider. So secure disposal based off NIST 888, this is where you're dealing with media sanitization levels. So you have clear, purge, and destroy. So clear is where you have a logical delete and basic overwrite. Data often still forensically recoverable when it's in the clear place. Now the key to keep in mind is that if you're doing a local delete or basic overwrite, the data will still be remnant on those systems. Purge is where you have physical or logical techniques rendering the recovery infeasible, even with lab tools. So they've made it in a situation where it should be relatively impossible for you to get the data off of those devices. And then there is destroy, which is what I love. And that's where you pull a hammer out and you just beat the dickens out of it. This is the physical destruction of the media itself, required when the media leaves the organization's control. Any hard drives that leave your organization should be shredded in most cases. They should be pulled out of anything and then put into a shredder of some kind. So a personal thumb drive leaving custody custody makes the clear, purge, and destroy impossible to enforce. You can't sanitize a device you don't control. That's why you can't lose Pandora's box again, isn't just a metaphor. So domain two quick hit review. So let's go over some questions specifically related that you can understand and some things to think about. Question Who assigns data classification? It's the data owner. What are the three sanitization levels? Purge, clear, and destroy. What governs third party access? A formal data sharing and interconnection agreement. And that's an important like a third party program. If you have a third-party risk program, it will have this third party access and it'll have that defined within there. That agreement will be there. Another question is NIST publication for media sanitization. It's the NIST special publication 800-88. What's a custodian versus a processor? A custodian manages internally pro internally. Processor handles data externally under an agreement that is built and baked out. And then the last one, what is the data remnants? This is residual data recoverable after a standard deletion.

Exam Mindset And Program Takeaways

SPEAKER_00

Okay, so here's the exam angle. When you see a scenario question about asset security, the exam wants you thinking like a manager, not like a technician. It is not, was there a firewall and who owned this data? Was it classified correctly? Did handling match that classification? And was the lifecycle, especially disposal, actually enforced? Here's the practitioner angle. This is what happens when those controls that you come up with that exist on paper but are not operationally enforced. Classification without enforcing handling rules is just a label. Ownership without accountability is just a name on a slide. And a data lifecycle without verified, enforced, disposable means is data effectively never dies. It lives on forever in a hoarder's thumb drive. So if you're building or running a security program, this story is a gift. And I mean that. I use these types of stories all the time with my senior leaders. So use it. Ask your own leadership: do we actually know where every copy of our most sensitive data lives right now? Could we prove it in an audit? If the answer is no, well, you've just found your next project, right? So it's going to be ready for you to get this thing going. So that's the Social Security Administration data story through a domain two lens. I wanted to make sure I tie these articles to what you see in the CISSP. So whatever the investigations ultimately find, the asset security lessons here are already worth understanding and studying. If you want to go deeper on domain two, classification, ownership, life cycle, retention, all of it in exam ready form, that's exactly what we're covering inside the CISSP Sprint. Cohort 2 enrollment is open now and the early bird rate. So head on over to CISSP Cyber Training to grab a seat for my September launch of Cohort 2. Thanks again for listening. I hope you guys enjoy this. Go study domain two, like your career depends on it, because it just might. For there's a lot of people in the Social Security Administration, it might be affecting their careers a little bit. So have a great day, and we'll catch you on the flip side. See ya.

Closing Requests And Free Questions

SPEAKER_00

Thanks so much for joining me today on my podcast. If you like what you heard, please leave a review on iTunes as I would greatly appreciate your feedback. Also, check out my videos that are on YouTube and just head to my channel at CISSP Cyber Training, and you will find a plethora or a conocopia of content to help you pass the CISSP exam the first time. Lastly, head to CISSP Cyber Training and sign up for 360 free CISSP questions to help you in your CISSP journey. Thanks again for listening.