Feeds

Hate keeping your systems updated and secure? So does Uncle Sam

Report shows security lapses rampant in government agencies

The Power of One Infographic

A Senate report has cast doubt on the ability of many of the US's largest government agencies to properly secure and maintain their systems.

The report, authored by Senator Tom Coburn (R-OK) and his fellow Republican members of the Senate Homeland Security and Governmental Affairs Committee, detailed incidents in government agencies that ranged from the Department of Homeland Security and the Department of Energy to the Internal Revenue Service and the Department of Education.

The committee noted that in many cases agencies have failed to maintain everyday security measures and best practices for protecting data. Reported incidents included SEC officials carrying sensitive data on personal devices and accounts, the use of outdated and unpatched software by federal agencies, and the use of unsecured and unencrypted hard drives to handle sensitive data.

"Federal guidelines are clear: when an agency identifies a weakness in its IT security, officials must record the problem, find a way to fix it, and assign themselves a deadline for completion," the report reads.

"As officials make progress and the weakness is eventually remedied, officials are supposed to update their records. Without that basic system in place, neither the agency nor the administration can tell if vulnerabilities are being addressed."

Among the incidents cataloged in the report is the 2013 release of a false Emergency Broadcast warning claiming a zombie attack, which aired in Michigan, Montana, and North Dakota.

Other incidents noted in the report included an Army Corps of Engineers breach of dam security information, and the revelation that Nuclear Regulatory Commission officials kept plant data on unsecured drives.

The committee members said that the incidents underscore lapses in security among government agencies which should be addressed as agencies move to increase their work with the private sector.

"Over more than a decade, the federal government has struggled to implement a mandate to protect its own IT systems from malicious attacks," the report reads.

"As we move forward on this national strategy to boost the cybersecurity of our nation's critical infrastructure, we cannot overlook the critical roles played by many government operations, and the dangerous vulnerabilities which persist in their information systems." ®

HP ProLiant Gen8: Integrated lifecycle automation

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
Major problems beset UK ISP filth filters: But it's OK, nobody uses them
It's almost as though pr0n was actually rather popular
HP, Microsoft prove it again: Big Business doesn't create jobs
SMEs get lip service - what they need is dinner at the Club
ITC: Seagate and LSI can infringe Realtek patents because Realtek isn't in the US
Land of the (get off scot) free, when it's a foreign owner
MPs wave through Blighty's 'EMERGENCY' surveillance laws
Only 49 politcos voted against DRIP bill
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.