I may be overly cynical of US government policies and procedures, but I read this as someone tried to use AWS or similar without permission.
The irony that the data had been uploaded to a physically secured, encrypted datacenter network from 27 DVDs in the possession of someone who could do whatever they wanted to with the contents of those DVDs without audit was not lost on me.
I don't reference this to imply it was good and proper use of the data; merely to note the difference between policy security and actual security.