The US government got an overall grade of C-minus in a computer security report card that evaluates the performance of 24 individual agencies covered by the Federal Information Security Management Act (FISMA).
Eight agencies -- including the departments of Defense, Interior and State as well as the Nuclear Regulatory Commission -- received failing grades. An equal number of agencies, including the General Services Administration, the Social Security Administration and the Department of Housing and Urban Development (HUD), scored at least an A-minus.
The grades in the seventh annual report card on federal computer security were released by Tom Davis, ranking member of the House Committee on Oversight and Government reform. The committee each year releases the Federal Computer Security Report Card based on security evaluations defined in FISMA. The evaluations are compiled by the committee based on information provided to Congress each year by the inspector general from each agency.
Asked at a news conference whether the US public should be confident that government agencies are protecting against cyberterrorism, Davis said: "It doesn't give me a lot of confidence."
Davis defended the Department of Homeland Security, which got a "D," saying it is still working to integrate the 22 agencies merged to create it in 2002. The creation of the department was a "horrendous, complicated deal," he said.
"It's a work in progress, and it's going to take some time."
But Davis had no kind words for the Department of Defense. He called it a "badly managed agency" with each military branch focusing on its own technology.
Agencies are rated on issues such as their adherence to security configuration standards, their ability to detect and respond to intrusions, whether they certify and accredit their systems, inventory accuracy and the kind of security training programs they offer employees.
Overall, the government's C-minus performance marks a "slow but steady improvement from past years," said Davis in a statement, pointing to the D-plus and D grades he had given the government over the past three years. "Obviously, challenges remain. But there are some excellent signs of progress in this year's report, and that's encouraging."
Those showing the most improvement in this year's report were the Department of Justice and HUD, both of which jumped from Ds to As. Meanwhile, NASA and the Department of Education showed the biggest declines in security. The space agency dropped from a B-minus to a D-minus; the education department went from a C-minus to an F.
According to Davis, this year's reports show that more agencies are paying attention to issues such as the annual testing of security controls and contingency plans -- and there is much better reporting of security breaches. However, more progress needs to be made in areas such as configuration management and progress measurement, he said.
Though the annual computer security grades are generally perceived as an indication of the security readiness of federal agencies, some have questioned their value and the manner in which the grades are scored.
Alan Paller, director of research at the US SANS Institute, said that while the grades appear to show an overall improvement, at least some of that is likely the result of "a few more agency IGs [inspectors general] deciding it wasn't worth it to give a black eye to their departments" by giving them a poor assessment, he said. "Sometimes it's a crap shoot. If the IG isn't feeling good, [their agency] gets an F."
He also pointed to continuing limitations in how agencies are assessed for security readiness. For example, one of the most important contributors to a good FISMA grade is the level of compliance within an agency to established hardware and software configuration standards, Paller said.
"The way it gets implemented is that the security team puts out a policy that says all computers have to use such-and-such a configuration," he said. But few mechanisms exist within these agencies to enforce or to verify compliance with those requirements, he said. As a result, the data collected by the IGs about compliance with configuration requirements is often incomplete or unreliable.
The results of a survey of 30 federal chief information security officers released today appear to offer divergent views on the value of the FISMA report card. The survey was conducted by a group called the Merlin International Federal Research Consortium (MFRC), which bills itself as a group of IT vendors, including companies such as BMC Software, F5 Networks and Layer 7 Technologies.
According to Merlin, the survey shows that the current report card process appears to disproportionately benefit larger agencies. About 60 percent of CISOs at large agencies say that FISMA reporting provides real insight into the security of their department's IT environment while just 36 percent of CISOs from small agencies concur.
"The findings suggest that the report card is not one-size-fits-all, and that small agencies face different IT security challenges than their larger counterparts," the Merlin report noted. "Based on the CISO feedback, the current report card process does not take these differences into account."
As a result, it might be worth considering a separate evaluation process for smaller federal agencies, the Merlin report said. The study also noted a continuing disconnect between performance on the FISMA report card and its effect on funding. About 79 percent of federal CISOs do not see a link between FISMA grades and overall IT budgets, while 75 percent of CISOs do not see a relationship between FISMA grades and IT security funding.
Grant Gross, of the IDG News Service, contributed to this report.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Controlling storage costs with Oracle database 11g
How to improve employee productivity in small and medium businesses
Everything you need to know about email and web security (but were afraid to ask)
Still Sneaking In: The Threats Your Security Tools Aren't Telling You About
Dude! You Say I Need an Application-Layer Firewall?!
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Radicati Market Quadrant 2008 on Corporate Web Security
The state of Middleware
- White PaperJoin Ed Thompson, Research VP, featured analyst firm, Gartner, Inc., and Brad Wilson, General Manager CRM Microsoft Dynamics, for a new webcast, Delivering the Power of Choice with Microsoft Dynamics CRM, available now. Our panel will break down the best practices for getting the most out of CRM and you'll learn key recommendations you can implement in your organization. Additionally, you'll also hear Microsoft's vision for CRM.
- White PaperLearn to tie virtualized computing to virtualized storage, to offer a dynamic set of capabilities within the data centre and create improved performance and system reliability. Discover how best to utilize EMC Celerra in a VMware ESX environment.
- White PaperYour organisation may well have devised and implemented an Acceptable Use Policy (AUP) some time ago in order to guard against the risks of inappropriate use of computer systems by your workers, but are you confident that your AUP remains 'fit for purpose'? Read on to discover how you can enhance the effectiveness of your AUP.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
Virtually every Windows PC at risk, says Secunia 04 December, 2008 08:00:00
Almost all PCs scanned by patch tool have an unpatched app; 46% have 11-plus.More than 98% of Windows computers harbor at least one unpatched application, and nearly half contain 11 or more programs at risk from attack, a Danish security company said Wednesday. - +
US Open used Web filtering to prevent online gambling 03 December, 2008 07:44:00
USTA took security measure to retain "squeaky clean" imageThe US Open tennis tournament provides network access for the players, guests and media, but this past summer the association running the event took an extra security step to make sure access wasn't too open. - +
CBS website bitten by iFrame hack 02 December, 2008 07:30:00
Russian malware distributors have launched another iFrame attack on a sub-domain of the cbs.com site.TV network CBS has become the latest big name to have it website used to host malware, a security company has reported. - +
Excerpt: Counterterrorism Strategies for Corporations 27 November, 2008 12:36:00
Mike Ackerman calls terrorism "the skunk at the globalization lawn party." His new book lays out 10 principles for how businesses can prepare and respond.Mike Ackerman calls terrorism "the skunk at the globalization lawn party." His new book lays out 10 principles for how businesses can prepare and respond. - +
The 10 Ackerman Principles of Counterterrorism 27 November, 2008 12:43:00
Consultant and author Mike Ackerman's 10 counterterrorism principles for business.Consultant and author Mike Ackerman's 10 counterterrorism principles for business.
AOC Launches 18.5” Widescreen Green 16:9 LCD Monitor in Australia and New Zealand 03 December, 2008 15:30:00
FrontRange Solutions eases software license management with new License Manager 3.0 03 December, 2008 14:56:00
Progress Software's Cure for Managing Services-based Applications 03 December, 2008 14:42:00
Informatica Powercenter added to Nec Infoframe Solution Suite 03 December, 2008 11:36:00
Gerald Held joins Informatica’s Board of Directors 03 December, 2008 09:50:00
|
||
|
||
|
|
||
|
Data grids and service-oriented architecture
When choosing an SOA strategy, corporations must ensure data availability, reliability, performance and scalability. A data grid infrastructure, built with clustered caching provides a framework for improved data access that can create a competitive edge and sustain customer loyalty. Read on to discover how this can be created within your organisation.
















