city of new orleans - nola. of new orleans email records retention final report april 15, 2010...

Download City of New Orleans - NOLA.    of New Orleans Email Records Retention Final Report April 15, 2010 Prepared for: City of New Orleans Office of Technology M. Harrison Boyd

Post on 26-May-2018

212 views

Category:

Documents

0 download

Embed Size (px)

TRANSCRIPT

  • City of New Orleans Email Records Retention Final Report April 15, 2010

    Prepared for:

    City of New Orleans Office of Technology M. Harrison Boyd 1300 Perdido St. New Orleans, LA 70112 Submitted by:

    SunBlock Systems, Inc. David Sun 1616 Anderson Rd. #350 McLean, VA 22102

  • SunBlockSystems EmailRecordsRetention Page2of27

    1 ExecutiveSummary..................................................................................................... 31.1 EmailSearch ......................................................................................................... 31.2 LTCReport ............................................................................................................ 31.3 ITOperationalIssues ............................................................................................ 4

    2 EmailSearch................................................................................................................ 62.1 EmailSourcesIdentified....................................................................................... 62.1.1 Serverbasedsystems.................................................................................... 62.1.2 DesktopandLaptopcomputers.................................................................... 72.1.3 BlackBerryhandhelddevices ....................................................................... 72.1.4 Backuptapes................................................................................................. 8

    2.2 DataPreservationMethodology ........................................................................ 132.2.1 Serverbasedsystems.................................................................................. 132.2.2 DesktopandLaptopcomputers.................................................................. 132.2.3 BlackBerryhandhelddevices ..................................................................... 142.2.4 Backuptapes............................................................................................... 14

    2.3 SearchResults .................................................................................................... 142.3.1 BlackBerryDevices...................................................................................... 142.3.2 DesktopandLaptopComputers ................................................................. 152.3.3 Servers......................................................................................................... 152.3.4 AlternativeSearchMethodology................................................................ 16

    2.4 EmailSearchFindings......................................................................................... 173 ReviewofLTCReport................................................................................................ 184 OperationalIssues .................................................................................................... 245 Appendix ................................................................................................................... 27

  • SunBlockSystems EmailRecordsRetention Page3of27

    1 Executive Summary SunBlockSystemswasretainedbytheCityofNewOrleanstosearchtheinformationtechnology(IT)infrastructureoftheMayorofNewOrleansinordertoidentifyandproduceemailssenttoandfromMayorC.RayNaginbetweenJuly20,2008andDecember1,2008,inclusive.Inaddition,SunBlockwasdirectedtoreviewtheEmailRecoveryProjectReportissuedbytheLouisianaTechnologyCouncilonJuly6th2009forirregularities.Lastly,SunBlockwasdirectedtodocumentanyIToperationalissuesencounteredaspartofourefforts.Thisreportdocumentsourfindings.

    1.1 Email Search SunBlockconductedathoroughreviewoftheMayorofNewOrleanssITinfrastructureandnumeroussystemswereidentifiedaspotentiallystoringMayorNaginsemaildata.Numerousservers,computersfromkeypersonnel,andBlackBerryhandheldswereforensicallyprocessedusingBitFlare,EnCase,andotherstandardcomputerforensicstools.Areviewofthesedevicesandsearchesforbackuptapesproducedvariousemailsbutdidnotprovideacomprehensivesourceofallmessages.Analternativesearchmethodologywasemployedtolocatemessages.AreciprocalmethodologywasutilizedthatreviewedemaildatafromallaccountsontheMayorsOfficeserversformessagesfrom/toMayorNagin.Usingthereciprocalmethodology,overtwomillionmessagesweresearched.UsingareviseddaterangeofJuly12008toDecember12008,thousandsofmessageswereidentifiedanddelivered.Basedonthesystemsinplace,itisunlikelythatanysignificantnumberofadditionalmessageswillbefound.

    1.2 LTC Report SunBlockwastaskedtoreviewthefindingsandreportissuedbytheLouisianaTechnologyCouncil(LTC)onJuly6th,entitledEmailRecoveryProjectReport.Issue3.1:LTCdidnotidentifyalternativesourcesLTConlyidentifiedtwoserversandNaginsdesktopaspotentialsourcesofemail.BlackBerryhandhelds,computersforkeystaffandfileserverscontaininghundredsofthousandsofmessageswerenotexaminedpriortoreleasingtheirfindings.Inaddition,alternativesearchmethodologiesthatwouldhaveyieldedresultswerenotemployed.Issue3.2:StandardforensicprotocolswerenotutilizedAlthoughtheuseofdatarecoverysoftwarewasdocumented,properforensictechniquespreventingthecontaminationoftheforensicdatawerenotemployed.OurreviewoftheharddrivesprovidedbyLTCindicatethatitwasnotuntilJune212009,approximatelysevenweeksafterworkbegan,thatLTCoroneofitsaffiliatesutilizedarudimentarytooltocreateaforensiccopyoftheMNOMail01server.Industrystandardpracticeincludestakingprecautionstopreventmodificationofcomputerevidenceduringananalysis.Ifaforensiccopyofacomputerdriveistobemade,thecopyshould

  • SunBlockSystems EmailRecordsRetention Page4of27

    bemadefirstandthentheanalysisconducted,nottoconductananalysisfirstandthenmakeaforensiccopy.Failuretofollowtheproperprocedurescancausethelossordestructionofpotentiallyrelevantinformationandcontaminationofanyforensicexaminations.Issue3.3:ResultsfromRecoverDatautilitywerenotproperlyanalyzedLTCprovidedtheresultsfromtheRecoverDatautilityinsupportoftheirconclusionthat22GBofdatawasdeletedfromthemailserverpriortotheirarrival.SunBlockstestingoftheRecoverDatautilityhasfoundanerrorintheprogramwhichcanincorrectlystatefilesizes.TheEDBfileinquestionwasextractedusingalternativetoolssuchasBitFlareandWindows.Acomparisonofthedigitalfingerprintsfortheseextractedfilesprovidedanexactmatch.ThiscorroboratesthefindingsoftheITdepartmentthatthatRecoverDatadidnotaccuratelyseeanyadditionaldatabeyondthe66GBavailable.

    1.3 IT Operational Issues Alongwiththepreviouslydescribedtasks,SunBlockwasalsoaskedtodocumentanyoperationalissuesencounteredthatwouldbeofinterest.ThegoalwastoassistinupdatingpoliciesandproceduresforthemanagementandoperationsoftheemailserverplatformaswellasprovidetheCitywithbestpracticesrecommendations.Issue4.1:NouniformemailretentionpolicyexistsDuringinterviews,OfficeofTechnologypersonnelstatedthatnoemailpolicyorAcceptableUsePolicyexisted.FurtherresearchbySunBlocklocatedanemailpolicydatedMay13,2008ontheCitysiteat:http://www.cityofno.com/Portals/Portal98/Resources/EmailPolicies.pdfHowever,thispolicyisnotwidelyknown.Inorderforapolicytobeimplemented,itmustbeuniformlydisseminatedsothatemployeesunderstanditexists.Issue4.2:ConfusionregardingimplementationofpoliciesThereissignificantconfusionamongCitypersonnelregardingtheimplementationofpoliciesandproceduresprovidedforemailretention.Sinceemailserverspaceandbackupcapacityislimited,anITdirectiveexistswhichencouragesalluserstoroutinelycleartheirmailbox.Usersareoftensentreminderstoreducethestorageutilizationoftheirinbox.Thisdirectivefailstoprovideproperinstructionsonhowtosatisfyrequirementsoftheemailretentionpolicyreferencedabove,potentiallyleadingtoconfusionamongusers.Issue4.3:BackupproceduresdrivenbytapebudgetsWithoutaformalpolicy,theOfficeofTechnologyhasimplementedbackuprequirementsandproceduresonanadhocbasis.Budgetconsiderationsandprocurementissueshaveunderminedbackuppractices.Initially,backupdatawasretainedfora30dayperiod.Assystemsgrewanddatadoubledinsize,insteadofpurchasingadditionalbackupcapability,backupretentiontimeswerereducedbyhalftotwoweeks.

  • SunBlockSystems EmailRecordsRetention Page5of27

    Issue4.4:UtilizingsystembackupsforemailarchivingEmaildatacanbetransientinnature.Sincetraditionalsystembackupsonlyoperateonadailybasis,theyarenotabletokeepupwiththetransientnatureofemail.Withnightlysystembackups,amessagethatisreceived,readanddeletedonthesamedaywillnotbeproperlybackedup.Atrueemailarchivingsolutionswasnotutilized.Manysuchsolutionsexistinthecommercialmarketplaceandcanaddresstheneedsofpublicrecordsemailretentionbycapturingallincomingandoutgoingemailstoanoffsitearchive.Theyallowforsecurepreservationofemailsandauserisunabletodeletetheirmessagesfromthearchive.Thesesolutionsarerelativelyinexpensiveandshouldbeutilized.

  • SunBlockSystems EmailRecordsRetention Page6of27

    2 Email Search InconductingtheemailsearchforemailstoandfromMayorC.RayNagin,SunBlockbeganwithitsstandardeDiscoveryprotocolsuccessfullyusedinsimilarmatters.Thisprotocolbeginswithanoverallreviewofallsystemsandoperationalproceduresinplacewithoutinitiallyfocusingonanyspecificsourcesofemail.Thiscomprehensiveapproachprovidesabroadunderstandingofallpotentialsourcesofdata,allowingformorereliableidentificationofallpossiblesourcesofresponsiveemails.

    2.1 Email Sources Identified TheSunBlockeDiscoveryprotocolbeganbyprovidingCitytechnicianswithamultipagesurveyconsistingof24questionsregardingsystemsandoperationalproceduresinplaceattheMayorsOfficeofTechnology.ThesurveywasfollowedupwithphoneinterviewsandfacetofacemeetingsattheCitysOfficeofTechnology,theCityAttorneysOffice,andMayorNagin.Basedonthedataprovided,itbecameclearthattheOfficeofTechnologyadministerstwodifferentemailsystems:oneforallCityemployees,andonededicatedtotheMayorsofficeandpersonnel.ItwasdeterminedthatSunBlockwouldconfineitssearchtosystemsdedicatedtotheMayorsofficeandpersonnel.Withexclusivefocusonth

Recommended

View more >