Members of a US House subcommittee blasted Department of Homeland Security CIO Scott Charbo for what they called a lack of leadership on information security issues and questioned his willingness to make needed fixes — and even his ability to head the agency's IT organization.
The stinging criticisms levelled at Charbo illustrate the complexity of the challenge he has faced since taking over as CIO of the DHS in July 2005: developing a unified IT infrastructure for the 22 separate agencies that were cobbled together to create the DHS.
Charbo rebutted the charges at a hearing held by the subcommittee, which is investigating cybersecurity vulnerabilities at the DHS. He said that much of the criticism of the agency's security capabilities was based on outdated information that ignored some of the improvements the DHS has made to its IT defences.
"I'm confident that the DHS information security program is moving in the right direction," Charbo said in his prepared testimony. "Although we still have a ways to go, we've made measurable improvements in the management of information security."
But that didn't dissuade legislators such as Bennie Thompson from launching verbal salvos at Charbo. Thompson, who chairs the House Committee on Homeland Security, said he had reviewed Charbo's responses to a series of security-related questions posed by the panel's subcommittee on emerging threats, cybersecurity, and science and technology in advance of the hearing.
Based on the responses, "I think the first thing that Mr Charbo needs to do is explain to us why he should keep his job," Thompson said. "I am not convinced that he's serious about fixing the vulnerabilities in [the DHS's] systems."
Thompson's criticism of Charbo was echoed by James Langevin, the subcommittee's chairman. In his opening remarks at the hearing, Langevin expressed his "shock and disappointment" at learning that the DHS had reported a total of 844 security incidents during the federal government's 2005 and 2006 fiscal years.
Langevin also said he was dismayed by what he claimed was Charbo's unwillingness to invest the needed resources to correct such problems. "The finances show that Mr Charbo and the department's leadership continue to underinvest in IT security," Langevin said.
'Material Weakness'
Adding more fuel to the fire was a report released by the Government Accountability Office, which said it had found pervasive and systemic security problems at the DHS during a year long review.
Among the issues highlighted by the GAO were a "material weakness" in the security controls on financial systems, the lack of an effective agencywide information security program and a continued failure to conduct comprehensive assessments of security risks.
Keith Rhodes, the GAO's chief technologist, said at the hearing that eventually his staff simply stopped looking for more vulnerabilities in the systems at the DHS and its component units because the problems were so widespread.
But Christopher Pierson, a partner at US law firm Lewis and Roca and board member in the local chapter of the FBI's InfraGard security information-sharing program, said that blaming Charbo for all of the problems at the DHS is unwarranted.
"DHS is faced with a unique problem," Pierson said. "It has a patchwork of 22 agencies that have been stitched together, do not share similar systems or security processes, and function very differently."
And until DHS Secretary Michael Chertoff issued a directive in March giving the CIO greater authority over IT on an agency-wide basis, Charbo really didn't have the clout needed to make meaningful changes, Pierson said.
Charbo said during this hearing that the DHS has completed an inventory of its systems and has made significant progress in certifying that they meet Federal Information Security Management Act (FISMA) standards.
The DHS is also in the midst of three IT consolidation projects that will have a significant impact on security, Charbo said. They include the creation of a single WAN called OneNet, featuring IPsec-based encryption and authentication; the development of an enterprise architecture that consolidates 13 different e-mail and directory systems into one; and the melding of multiple data centres into a shared facility.
In addition, Charbo defended his agency's IT security spending, saying it was on a par with industry standards.
Alan Paller, director of research at the US SANS Institute, said Charbo's record on information security is similar to those of a majority of CIOs at large federal agencies. But, he added, at least some of the FISMA compliance efforts at the DHS appear to have been paperwork exercises that have done little to actually improve security.
- White PaperView this webcast and discover the drivers for changing network design practices, why many organisations are changing their approach to network architecture and how enterprises should be moving forward with open architecture multi-vendor network solutions. Register now and learn how your business can maximize the business value of the enterprise network.
- White PaperJoin Lee Benjamin, a Microsoft Exchange MVP and Ryan Shipkowski, network administrator for Matthews, to discuss the process and ROI of implementing an email archiving solution, with emphasis on a case study from Matthews International.
- White PaperDiscover how the integration of disparate technologies in your company can lead to greater user productivity, improved management, lower costs, higher efficiency, and easier risk mitigation.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
SOA What? Why You Need SOA Governance Framework 04 December, 2008 08:32:00
Adopting services oriented architecture (SOA) in your enterprise without thinking through IT governance can cause something like the Gold Rush in the 1800s; extreme rates of growth and minimal law and order which produce unexpected outcomes. - +
The Myth of Cloud Computing 04 December, 2008 08:25:00
Why the rapid spread of virtual technology is becoming a security riskWhy the rapid spread of virtual technology is becoming a security risk. - +
Who Pushed Vendors Toward Better Security? 04 December, 2008 09:38:00
Hint: It had something to do with pressure from customers and government agencies, writes Oracle CSO Mary Ann DavidsonHint: It had something to do with pressure from customers and government agencies, writes Oracle CSO Mary Ann Davidson. - +
CPO & CISO: A Comprehensive Approach to Information 04 December, 2008 08:42:00
GE CPO Nuala O'Connor Kelly advocates greater CPO/CISO cooperation to place the right value on information assets.GE CPO Nuala O'Connor Kelly advocates greater CPO/CISO cooperation to place the right value on information assets. - +
Virtually every Windows PC at risk, says Secunia 04 December, 2008 08:00:00
Almost all PCs scanned by patch tool have an unpatched app; 46% have 11-plus.More than 98% of Windows computers harbor at least one unpatched application, and nearly half contain 11 or more programs at risk from attack, a Danish security company said Wednesday.
F-Secure: Growth In Internet Crime Calls For Growth In Punishment 05 December, 2008 13:00:00
International researchers gather in Sydney to preview the clever web 05 December, 2008 09:48:00
Borderless corporate networks to shift focus to secure content management in Australia in 2009 04 December, 2008 16:06:00
IDC Says Asia/Pacific Excluding Japan IT Market Will Remain The Bright Spot... 04 December, 2008 15:04:00
MySpot SOS "Panic Button" Smartphone Application could save lone worker lives 04 December, 2008 13:34:00
|
||
|
||
|
|
||
|
Best Practice in Building an Integrated Information Management Strategy
Discover the business value that creating an integrated information platform can bring. Learn how to provide consistent, accurate information to all stakeholders within your business network. Integrate vital data from disparate sources and deliver a trusted information foundation. Read on to uncover the stepping-stones to your new information management strategy.
















