- Blaming people for accidents is stupid. Throwing them into prison for accidents is even stupider.
- Proper security is designed in a way that people can make mistakes and it doesn't mean the end of the world.
Him knowing better about this isn't really a response to OP's initial comment of being against a lengthy prison sentence.
The prison sentence accomplishes absolutely nothing. You're just ruining a person's life as they were retiring and breaking a family apart. Makes no sense if this was indeed an accident.
If he emailed a classified document, there is absolutely no way in hell that was an accident. You are never, ever, ever supposed to put classified information onto an unapproved system. This is like saying, "Oh, I forgot which pedal does which, so I slammed the gas instead of the brakes and killed someone, but it was an accident so I shouldn't go to jail." No, you're definitely going to jail, you 'forgetting' how to drive doesn't mean you didn't ruin someone's life.
(There's a small chance that he could have wrote something classified from his brain into the body of an email and sent it. People don't get sent to jail for this, provided it's a one-time incident. If he's getting charges pressed it was pretty egregious. The term "gross negligence" comes to mind.)
And it really could be that critical. Classified information is classified because it can be damaging. If you leak the names of people spying for you in foreign countries, they might be captured or even killed. How do you "design the system" to allow for that "mistake"?
Finally, the prison sentence lets people know that security is serious. There are many rules and it takes effort to follow them. People get lazy and cut corners when there aren't consequences.
Exactly that, how is it possible to have access to Highly-secret stuff but also to your personal email? Something is not right here.
Well then it's like i said....there is something wrong ;)
You could be told classified information, go home that day, and tell your wife the same thing. There is literally nothing they can do to prevent that except make sure people know there are consequences to doing so.
There are many such examples. Classified CDs is a good one. There are many rules related to classified CDs, but at some level you have to trust your people are following these rules. This is why getting a clearance is more difficult than the average job interview, and why people from the Intel communities take leaks so personally. It has to be part of the culture.
Funny that no one in a financial institute has access to private mail (Switzerland), USB is deactivated, to Surf the Web you need another laptop, no one has access to backups (Mainframe etc) without the knowledge of the CEO but maybe the data is more worth?
But yes at the end of the day you have to trust your peoples....but private email from your working-machine....that's borderline dangerous.
I hope not ;)
People do stamp on the wrong pedal sometimes…if it's genuinely an accident I haven't heard about people going to jail?
Maybe a better one is a forklift operator dropping something on someone because they didn't do their company-mandated safety training and pressed the wrong button. It was an accident, the guy didn't mean to hurt anyone, but he did because he was negligent and there has to be consequences for that.
I literally don't get this "revenge" view point. Maybe we're just going to disagree here. The same way punishments don't work on dogs, children, etc. They also don't "stop" security incidents from happening.
Your example is bad because proper access controls would:
1. Be designed in such a way that humans can follow them and that humans __do__ follow them.
2. If humans can't follow them, then humans shouldn't be involved at all.
There are so many examples in this thread of "well this is against security training, but everyone does it anyway". That's a bad design. That's created for selective enforcement and makes the entire thing a joke.
EDIT: Sorry @dang I know I keep editing my comments a lot and you probably don't like that, but the more I think about it the more ridiculous these claims are the more miffed I get. Seriously, to all these people telling me that the NSA is just incompetent because someone went out of their way to commit a crime, imagine the following scenario: you tell someone a piece of classified information, they then walk over to an unclas computer and type that sentence in verbatim into their Gmail and hit 'Send'. Please design a crypto system, ACL, network architecture, workflow, any technical solution that could practically prevent that from happening across hundreds of organizations and probably millions of employees. I would bet you a lot of money you cannot.
1. Undoes the damage done by the leak.
2. Prevents further leaks happening in the future.
The only thing it does is ruin a person and their families life as they were entering retirement.
On the subject of classification, that has no excuse.