The Inevitable IT Security Breach
2 Studies Show Why War Logs Leak Wasn't a Surprise…
Eligible |
![]() |
The nation's federal and private-sector infrastructure systems remain at risk of not being adequately protected unless action is taken, the Government Accountability Office said in a letter issued Tuesday to a House panel.
"The need for improved cybersecurity in the federal government is clear," wrote Wilshusen GAO's information security issues director.
In the letter, GAO offers five ways Congress can strengthen the Federal Information Security Management Act, the law that governs IT security in the federal government. The five proposals:
Wilshusen was responding to two follow-up questions by members of the House Committee on Oversight and Government Reform's Subcommittee on Government Management, Organization and Procurement, stemming from a May 19 hearing on federal information security. One question solicited the views of GAO, the investigative arm of Congress, on how FISMA could be improved; the other solicited GAO's view on the Cybersecurity Act of 2009, a bill sponsored by Senators Jay Rockefeller, D.-W.Va., and Olympia Snowe, R.-Maine.
Wilshusen says the bill, known as S. 773, is intended to improve cybersecurity in the United States. According to the bill, America's failure to protect cyberspace is one of the most urgent national security problems facing the country, a point Wilshusen didn't dispute. In the last fiscal year, he says, GAO determined that 23 of the government's top 24 agencies did not have adequate controls in place to ensure that only authorized individuals could access or manipulate data on their systems and networks. "The present cybersecurity strategy and its implementation had not been fully effective in mitigating the threat," he wrote. He reported that the number of IT security incidents reported by federal agencies has increased dramatically over the past three years, tripling from 5,503 incidents reported in fiscal year 2006 to 16,843 incidents in fiscal year 2008.
To remediate these problems, GAO recommended:
| 1 | 2 |
NIST SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems..Next Topic
DoJ: Report to Congress on Implementation of Section 1001 of the USA PATRIOT Act..Next Topic
NIST SP 800-41 Revision 1: Guidelines on Firewalls and Firewall Policy..Next Topic
NIST Guide to Security for WiMAX Technologies (Draft)..Next Topic
OMB Memorandum: New Reporting Instructions for FISMA..Next Topic
NIST IR 709: Cryptographic Key Management Workshop Summary (Draft)..Next Topic