A whistleblower lawsuit was made public that alleged Penn State did not sufficiently handle sensitive information and submitted falsified records on Monday.
This lawsuit was first filed on Oct. 5, 2022, with allegations brought by Matthew Decker, the chief information officer for Penn State’s Applied Research Laboratory from November 2015 to March 2023 and the interim vice provost of Penn State in 2016.
Decker was recruited to bring the cybersecurity and IT environment of the Applied Research Laboratory into “control and compliance.”
Since the ARL was separate from the campus of Penn State “physically, logically and operationally,” Decker had no responsibility for bringing the research departments of Penn State into compliance with the Defense Federal Acquisition Regulation Supplement (DFARS).
According to the “Safeguarding Covered Defense Information and Cyber Incident Reporting” section of DFARS, it is required that contractors like Penn State provide “adequate security” for covered defense information that is found on its internal information systems.
This covered defense information is known as “Controlled Unclassified Information” (CUI), and although it is not classified, it is considered sensitive information that may include “technical data, patents or information relating to the manufacture or acquisition of goods and services.”
According to the lawsuit, some time after Decker’s term as interim CIO concluded on Sept. 1, 2016, he discovered that the university had...
Read Full Story:
https://news.google.com/rss/articles/CBMi1AFodHRwczovL3d3dy5wc3Vjb2xsZWdpYW4u...