• Access to the system, including successful and failed login attempts, and logouts;
• Inbound and outbound file transfers;
• Terminal connections (telnet) to and from external systems;
• Sent and received e-mail messages;
• Web sites visited, including uniform resource locator (URL) of pages retrieved;
• Date, Time, and user associated with each event.
J.A. 125-26. The policy also stated that “[u]sers shall ... [u]nderstand FBIS will periodically audit, inspect, and/or monitor the user’s Internet access as deemed appropriate.” J.A. 127.
FBIS contracted with Science Applications International Corporation (SAIC) for the management of FBIS’ computer network, including monitoring for any inappropriate use of computer resources. On July 17, 1998, Clifford Mauck, a manager at SAIC, began exploring the capabilities of a firewall recently acquired by SAIC, because Mauck believed that SAIC needed to become more familiar with the firewall to service the FBIS contract properly.1 Mauck entered the keyword “sex” into the firewall database for July 14 and 17, 1998, and found a large number of Internet “hits” originating from Simons’ computer. It was obvious to Mauck from the names of the sites that they were not visited for official FBIS purposes.
Mauck reported this discovery to his contact at FBIS, Katherine Camer. Cam-er then worked with another SAIC employee, Robert Harper, to further investigate the apparently unauthorized activity. Camer instructed Harper to view one of the websites that Simons had visited. Harper complied and found that the site contained pictures of nude women.
At Camer’s direction and from his own workstation, Harper examined Simons’ computer to determine whether Simons ■ had downloaded any picture files from the Internet; Harper found over 1,000 such files. Again from his own workstation, Harper viewed several of the pictures and observed that they were pornographic in nature. Also at Camer’s request and from his own workstation, Harper printed a list of the titles of the downloaded picture files. Harper was then asked to copy all of the files on the hard drive of Simons’ computer; Harper accomplished this task, 'again, from his own workstation.
On or about July 31,1998, two representatives from the CIA Office of the Inspector General (OIG), one of whom was a criminal investigator, viewed selected files from the copy of Simons’ hard drive; the pictures were of minors. Later that day, Harper physically entered Simons’ office, removed the original hard drive, replaced it with a copy, and gave the original to the FBIS Area Security Officer. The Security Officer turned it over to the OIG criminal investigator the same day.2 This last assignment was the only one that required Harper to physically enter Simons’ office.
On August 5, 1998, FBI Special Agent John Mesisca viewed over 50 of the images on the hard drive that had been removed from Simons’ office; many of the images contained child pornography. Mesisca, Harper, the two OIG representatives, and Assistant United States Attorney Tom Connolly worked together to prepare an application for a warrant to search Simons’ office and computer. An affidavit from Mesisca supported the warrant application. The affidavit stated, inter alia, that Si-mons had connected a zip drive to his computer.3 The affidavit also expressed a
1
A firewall is like a funnel through which all Internet access flows and is registered; the firewall collects data and may be searched as a database.
2
The OIG investigator “placed it into evidence.” J.A. 70.
3
.A zip drive is a device for storing computer files; it has greater storage capacity than other computer storage devices. Zip drive diskettes work only in zip drives and not with other computer storage devices.