Lifelong protection should be extended to all those whose data was lost by the lack of modern IT security infrastructure at OPM. Particularly as this lack of security was known through OIG audits. Lifelong protection should cover all whose data was affected, not only employees, but anyone whose data may have been compromised eg. Listed on SF-86. If evidence of data exfiltration can not be proved either way, error on the side of caution and extend the protection to anyone who may have been compromised.



