The FSO of the SCIF where he (presumably) worked should be investigated. His CO and the rest of his chain of command should be investigated as well. The (contract investigator, most likely) who was involved in granting him his clearance, too. I'm pretty sure that all happens automatically when something like this happens -- at the very least, they need to work on making sure this doesn't happen again, but it's hard to believe they were 100% blameless in this.
The actual IT systems used by the military for secret-or-higher classified data are kind of pathetic, actually. Certain things are done well (the "air gap" model for networks, and generally the military is decent at key management, and most members granted security clearance are good about changing passwords and reporting security probes, vs. commercial environments. However, the technology itself is often windows (2k, xp, vista), and isn't exactly the best managed network in the world. To some extent being "air gapped" causes them to be lazy about other forms of security. A lot of this has to do with the exceptionally slow procurement and integration cycle of the military, but at the core, windows is just not a great solution for building an office automation system with 100% accountability for every file.
(I'm actually working on a startup that will address this market; it's a good market, but I've also been someone at personal safety risk from security violations, so it is more compelling to me than writing another fb game or ipad app.)