A quantitative risk assessment of the FBI-NSA information technology environment should be prepared over a one year period. This report will be released to the public with no redactions. The prime focus is to identify long-term criminal threats.
This is routine work for commercial IT departments. "What damage can a System Administrator do? Or a Vice-President of Security?" These are critical questions.
FBI UPSTREAM and NSA PRISM systems warrant independent downside analysis. We know that millions of these phone records were copied to an FBI employee's laptop. Similar crimes range from politically motivated cell phone taps to the Watergate "Plumbers" conspiracy.
Assuming the future replicates known "dirty trick" crime patterns, what new hazards for theft or blackmail are now at hand?



