Feeds

GAO gives US.gov D- for security

Holes inside the Beltway

  • alert
  • submit to reddit

Internet Security Threat Report 2014

US federal agencies are poorly prepared in withstanding spyware, spam or phishing attack, a government audit has concluded. A survey by the Government Accountability Office published this week reveals a lack of coherent security planning among as many as 20 federal agencies.

"Many agencies have not fully addressed the risks of emerging cybersecurity threats as part of their required agency-wide information security programs," the GAO's Emerging Cybersecurity Issues Threaten Federal Information Systems study (PDF summary) states. It called on agencies to implement recommendations in the Federal Information Security Management Act of 2002.

The report also criticised the Department of Homeland Security for a lack of leadership on information security reporting issues. US government agencies are supposed to report information security threats to US CERT but this is a custom more honoured in the breach than by its observance, the study concludes.

The issues addressed in the report are far from theoretical. Staff at several agencies - including the FBI and the Internal Revenue Service - have been taken in by phishing attacks, the GAO's study notes. Gartner security guru John Pescatore told Computerworld that private sector firms were little or no better than government organisations in defending against emerging security threats. "If there was a GAO that looked at private companies, you would find the same thing," he said. ®

Related stories

UK under cyber blitz
US gov wants to refang Patriot Act
Homeland Security blows $16m prepping for apocalypse
DHS comes clean on CAPPS, lets self off hook

Internet Security Threat Report 2014

Whitepapers

Driving business with continuous operational intelligence
Introducing an innovative approach offered by ExtraHop for producing continuous operational intelligence.
The total economic impact of Druva inSync
Examining the ROI enterprises may realize by implementing inSync, as they look to improve backup and recovery of endpoint data in a cost-effective manner.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Simplify SSL certificate management across the enterprise
Simple steps to take control of SSL across the enterprise, and recommendations for a management platform for full visibility and single-point of control for these Certificates.