Curt B. Weldon and the 1998 GAO Shell Game on DoD Security

By Miriam Adler ·

While the FBI scrambled to stop "Operation Solar Sunrise," a June 1998 letter reassured Congress that a new management process had solved the problem.

In February 1998, the Defense Department's digital gates were left wide open. Our most sensitive military secrets became a playground for foreign intruders, and the men paid to watch the door were arguing over the font of their reporting forms while the house burned down.

I am working from the archive's curated description of a letter dated June 11, 1998, not the original pages. The record is a piece of correspondence from Allen Li, an official with the General Accounting Office, addressed to Curt B. Weldon. The subject is the "DOD's Information Assurance Efforts."

On its face, the letter is a victory lap. According to the record, the GAO provides "the GAO's assessment of the actions taken by the Defense Department to implement the recommendations in the Defense Science Board's November 1996 report," as well as an update on the department's "development of an information assurance management process" and its "adoption of a new information assurance certification and accreditation process."

Operation Solar Sunrise

To understand the lie in this letter, one must look at what was happening in the hallways of the FBI three months earlier. While the GAO was preparing its assessment, the operational world was in a panic. On February 16, 1998, the FBI issued a secret memo regarding "Computer Intrusions." By March 4, the bureau was documenting "Operation Solar Sunrise," a massive, coordinated cyber-attack that had penetrated the networks of the Defense Department and several other federal agencies.

Solar Sunrise was not a theoretical vulnerability; it was a systemic collapse. The intruders had breached the perimeter and were moving laterally through the systems. The FBI's messages to its offices in Philadelphia and Newark on February 18 make the urgency clear: this was an active intrusion, a live breach of the nation's most guarded secrets. The Defense Department was not "implementing recommendations"; it was under siege.

Document imagery from nsarchive.gwu.edu From the files: nsarchive.gwu.edu

June 11, 1998

Then comes the GAO letter to Curt B. Weldon. Weldon, a Republican representing Pennsylvania's 7th district, sat as the vice-chair of the Armed Services Committee and the House Homeland Security Committee. He was the primary legislative conduit for DoD oversight, the man whose job it was to ensure the Pentagon was not playing fast and loose with national security.

The GAO—the legislative branch agency providing auditing and investigative services for Congress—acted as the referee in this exchange. The GAO used the findings of the Defense Science Board, a committee of civilian experts appointed to advise the DoD on technical matters, as the benchmark for its audit. In November 1996, the Board had warned the Pentagon that its information assurance was deficient. By June 1998, the GAO was telling Weldon that the DoD had finally developed a "management process" and a "certification and accreditation process" to fix it.

There is a profound, almost professional irony here. The GAO was reporting on the process of security while the reality of security was a crater. The record shows the GAO was satisfied that the Defense Department had adopted a "new information assurance certification and accreditation process." In the world of tradecraft, a certification is a piece of paper that says a system meets a standard. It is not the same thing as a system that actually stops a hacker in a basement in East Asia.

Certification as Camouflage

This is where the record reveals the shell game. The GAO was not auditing operational efficacy; it was auditing administrative compliance. The desk's reading is that the GAO treated "Information Assurance" as a paperwork exercise, checking off boxes to ensure that a management structure existed, while the systems themselves were actively failing.

If this file is shaped the way it looks, the Defense Department utilized a "compliance narrative" to satisfy legislative oversight. By presenting the implementation of the 1996 recommendations as a success, the Pentagon could tell Weldon that the problem was "managed." This allowed the department to maintain a facade of control before the House Homeland Security Committee even while the FBI was still scrubbing the residue of Solar Sunrise from the servers.

This functional decoupling is a recurring theme in the history of the American security state. There is the operational response—the frantic, secret work of the FBI and the intelligence community to plug leaks—and there is the management process—the slow, public-facing work of the GAO and the DoD to ensure the paperwork is in order. The GAO letter to Weldon belongs to the latter. It is a document designed to close a file, not to secure a network.

Where the NSA Vanished

The most telling part of the record is who is not in it. The National Security Agency, the technical authority responsible for the actual security standards and cryptologic integrity of the United States, is entirely absent from the reporting chain in this letter. The GAO audits the DoD, the DoD refers to the Defense Science Board, and the result is delivered to a Congressman. The NSA, the only entity with the technical capacity to tell Weldon that the "certification process" was a joke, is nowhere to be found.

The pattern suggests that the NSA was excluded from the reporting chain to maintain a layer of plausible deniability. If the NSA had signed off on the GAO's assessment, they would have been on the hook for the breaches. By leaving the NSA out of the loop, the DoD could claim technical success to the GAO while keeping the actual failures buried in the vault.

The desk's reading is that this letter was a political tool, not a security audit. It provided Weldon with the necessary cover to tell his colleagues that the DoD had its house in order, effectively silencing legislative inquiry into cyber-vulnerabilities at a moment when those vulnerabilities were being exploited in real-time.

A full release of the withheld pages from this era would likely show a stark contrast between the "certified" systems the GAO praised and the red-inked disaster reports the NSA was filing in private. The cost of this deception was a false sense of security that persisted for years, treating the symptoms of bureaucratic disorder rather than the disease of technical obsolescence. The Pentagon didn't fix the leak; they just certified the bucket.

Sources

  1. Allen Li, General Accounting Office, Letter to Curt B. Weldon, Subject: DOD's Information Assurance Efforts, June 11, 1998. Unclassified. — National Security Archive (GWU)
  2. Document PDF (Allen Li, General Accounting Office, Letter to Curt B. Weldon, Subject: DOD's Information Assurance Efforts, June 11, 1998. Unclassified.)
  3. Background: Department of Defense Information Assurance Certification and Accreditation Process — Wikipedia