← Back to Search
Matthew Rocheleau v. Executive Office of Technology Services and Security (SPR 20200198)
Massachusetts Public Records Appeal · Petitioner won — agency ordered to provide records · Filed 02-04-2020
ClosedAppealPetitioner Won
SPR 20200198 is a Massachusetts Public Records Law appeal filed by Matthew Rocheleau concerning records held by Executive Office of Technology Services and Security, opened 02-04-2020. Type: Appeal. Status: Closed. Supervisor of Public Records determination: Petitioner won — agency ordered to provide records.
Case Details
- Case Number
- 20200198
- Case Type
- Appeal
- Case Subtype
- Initial
- Status
- Closed
- Requester
- Matthew Rocheleau
- Date Opened
- 02-04-2020
- Date Closed
- 02-19-2020
- Date Request Submitted
- 01-17-2020
- Response Provided Date
- 02-03-2020
- Processing Fees Charged
- 0.00
- Petitions Regarding Fees
- No
- Time to Comply
- 11 Business Days
PDF Document
Extracted Text (searchable & copyable)
The Commonwealth of Massachusetts William Francis Galvin, Secretary of the Commonwealth Public Records Division Rebecca S, Murray S11pe111/sor of Records February 19, 2020 SPR20/0198 Shannon C. Sullivan, Esq. General Counsel Chief Privacy Officer Executive Office of Technology Services and Security One Ashburton Place, 8th Floor Boston, MA 02108 Dear Attorney Sullivan: I have received the petition of Matthew Rocheleau of the Boston Globe appealing the response of the Executive Office of Technology Services and Security (EOTSS). Specifically, Mr. Rocheleau requested "[t]he e-mail address(es) assigned to each employee of the Commonwealth of Massachusetts, showing their name and the department they work for." EOTSS responded on February 3, 2020 by denying access to records under Exemption (n) of the Public Records Law. G. L. c. 4, § 7(26)(n). Tlie Public Records Law The Public Records Law strongly favors disclosure by creating a presumption that all governmental records are public records. G. L. c. 66, § lOA(d); 950 C.M.R. 32.03(4). "Public records" is broadly defined to include all documentary materials or data, regardless of physical form or characteristics, made or received by any officer or employee of any town of the Commonwealth, unless falling within a statutory exemption. G. L. c. 4, § 7(26). It is the burden of the records custodian to demonstrate the application of an exemption in order to withhold a requested record. G. L. c. 66, § lO(b)(iv); 950 C.M.R. 32.06(3); see Dist. Attorney for the Norfolk Dist. v. Flatley, 419 Mass. 507, 511 (1995) (custodian has the burden of establishing the applicability of an exemption). To meet the specificity requirement a custodian must not only cite an exemption, but must also state why the exemption applies to the withheld or redacted portion of the responsive record. Appeal In its February 3rd response EOTSS indicates "[t)he records you have requested below are One Ashburton Place, Room 1719, Boston, Massachusetts 02108 • (617) 727-2832• Fax: (617) 727-5914 sec.state.ma.us/pre• pre@sec.state.ma.us Shannon Sullivan, Esq. SPR20/0198 Page 2 February 19, 2020 not subject to public disclosure pursuant to M.G.L. c. 4, § 7, Twenty-sixth (n), as their disclosure would jeopardize the Commonwealth's cybersecurity." Exemption (n) Exemption (n) applies to: records, including, but not limited to, blueprints, plans, policies, procedures and schematic drawings, which relate to internal layout and structural elements, security measures, emergency preparedness, threat or vulnerability assessments, or any other records relating to the security or safety of persons or buildings, structures, facilities, utilities, transportation, cyber security or other infrastructure located within the commonwealth, the disclosure of which, in the reasonable judgment of the record custodian, subject to review by the supervisor of publfo records under subsection ( c) of section 10 of chapter 66, is likely to jeopardize public safety or cyber security. G. L. c. 4, § 7(26)(n). Exemption (n) allows for the withholding of certain records which if released would jeopardize public safety. The first prong of Exemption (n) examines "whether, and to what degree, the record sought resembles the records listed as examples in the statute;" specifically, the "inquiry is whether, and to what degree, the record is one a terrorist 'would find useful to maximize damage.'" People for the Ethical Treatment of Animals (PETA) v. Dep't of Agric. Res., 477 Mass. 280, 289-90 (2017). The second prong of Exemption (n) examines "the factual and contextual support for the proposition that disclosure of the record is 'likely to jeopardize public safety."' Id. at 289-90. The PETA decision further provides that "[b]ecause the records custodian must exercise 'reasonable judgment' in making that determination, the primary focus on review is whether the custodian has provided sufficient factual heft for the supervisor of public records or the reviewing court to conclude that a reasonable person would agree with the custodian's determination given the context of the particular case." Id. EOTSS indicates "[i]n reviewing your request, I consulted with our Chief Information Security Officer, our office's primary subject matter expert concerning the cybersecurity of our office and of the IT infrastructure our office maintains on behalf of the Commonwealth. It is his assessment that disclosing a complete list of email addresses for Commonwealth employees along with their names and corresponding departments would be a risk to the Commonwealth's cybersecurity and IT infrastructure." You further asse1i that"[ t]he primary risks - phishing, spear phishing, business email compromise, and social engineering attacks - though present when even a single email address is disclosed, are significantly amplified by wholesale disclosure. A disclosure of the requested nature would enhance the ability of adversaries to conduct highly targeted attacks against Commonwealth users." Shannon Sullivan, Esq. SPR20/0198 Page 3 February 19, 2020 EOTSS provides additional information regarding the risk of "spear fishing" and indicates "[s] pear phishing, in particular, is a major concern of the EOTSS Security Office." You assert the following: Email addresses are relatively easy to spoof, and it is possible that an adversary could fabricate an email so it appears to have originated from one of these users. Should we disclose a list of email addresses for every Commonwealth employee whose information we maintain, along with their name and the department where they are employed, cyber attackers would be able to tailor attacks specifically to each employee, making their attacks more convincing .. Combined with other publicly available information (e .g., job titles, agency functions, social media accounts, etc.), the risk of a successful attack is further increased. The more email addresses an attacker can utilize, the greater the likelihood there will be a successful attack. EOTSS indicates that "[t]here are numerous examples of successful spear phishing attacks against government employees" and that "[w]hile the Commonwealth employs a variety of measures to guard against such attacks (e.g., requiring cybersecurity awareness training for all employees, implementing risk mitigation software solutions), human error and sophisticated phishing techniques continue to pose a real threat to Commonwealth cybersecurity." With respect to the availability of responsive email addresses, you assert "[w]hile we are aware that some employee email addresses are necessarily available to the public in order for such employees to effectively perform their job responsibilities, many of the employees whose email addresses are sought by this request generally have limited or no contact with the general public via their work email account, simply because there is no need based on their job · function(s). This may make them less suspicious and more susceptible to an attack. There is limited or no public interest in the disclosure of such email addresses." EOTSS provides information regarding the impact of a successful attack by indicating, in part, "[w]e are at risk of everything from financial damages through a successful business email compromise attack to interference with our ability to respond to real world emergencies should attackers gain access to our network via spear phishing and target our dispatch channels." You further contend that "[s]uccessful infiltration of our network could have catastrophic consequences for the Commonwealth's operations. Wholesale disclosure of so many Commonwealth employee email addresses would substantially increase our vulnerability, while undermining the Commonwealth's cybersecurity posture and the other protective and preventive measures we have taken, diminishing our ability to protect our IT infrastructure and the confidential personal and business data we are required to maintain." In his appeal petition Mr. Rocheleau asserts, in part, "[t]he Department ignores the first portion of the Exemption, which requires that the documents subject to the exemption 'relate to' one of a select number of topics, none of which applies in this case. As such, any claim that the Exemption applies must fail." In furtherance of his argument, he further notes "[j]ust because Shannon Sullivan, Esq. SPR20/0198 Page 4 February 19, 2020 disclosing a record may make easier the task of someone with malicious intent does not mean that disclosing that record is likely to jeopardize cybersecurity, as required for the Exemption to apply. Thus, even if the Department had shown with specificity that the record related to one of the topics listed in the Exemption - which it did not - the argument would fail because reasonable judgment shows that provision of this record is not likely to jeopardize cyber security." (emphasis in original). Based on its response, I find EOTSS has not met its burden to withhold the responsive email addresses under Exemption (n). In particular, EOTSS has not met its burden to show how the list of email addresses sufficiently "resemble[ s] the records listed as examples in the statute" as contemplated in PETA . Id. The examples provided in the statute are "blueprints, plans, policies, procedures and schematic drawings, which relate to internal layout and structural elements, security measures, emergency preparedness, threat or vulnerability assessments, or any other records relating to the security or safety of persons or buildings, structures, facilities, utilities, transportation, cyber security or other infrastructure." G. L. c. 4, § 7(26)(n). As such, it is unclear how the responsive email addresses are similar to these examples. Although EOTSS provides information regarding the risk of jeopardizing public safety or cyber security, please note that in PETA, the Supreme Judicial Court found that "[a]s the resemblance between the record sought and the listed examples in [E]xemption (n) decreases, the custodian's burden for demonstrating 'reasonable judgment' increases. Thus, when the requested record bears little or no resemblance to the listed examples, the custodian's burden for demonstrating that it exercised 'reasonable judgment' in determining that disclosure of the record is 'likely to jeopardize public safety' will be atits highest." PETA, 477 Mass. at 290-91. In light of this heightened burden outlined in PETA, I find EOTSS has not provided "sufficient factual heft" to conclude that a reasonable person would agree that disclosure of the email addresses is "likely to jeopardize ...c yber security" as required by Exemption (n). Id. Conclusion Accordingly, EOTSS is ordered to provide Mr. Rocheleau with a response to the request, provided in a manner consistent with this order, the Public Records Law, and its Regulations within 10 business days. A copy of any such response must be provided to this office. It is preferable to send an electronic copy of this response to this office at pre@sec.state.ma.us. Sincerely, Rebecca S. Munay Supervisor of Records cc: Matthew Rocheleau