Commentary

10 Rules For Avoiding Identity Theft 'Mistakes'

The federal government is trying to clean up its act when it comes to ID theft. That includes lecturing CIOs on the basics of information security.

The federal government is trying to clean up its act when it comes to ID theft. That includes lecturing CIOs on the basics of information security.The federal Chief Information Officers Council was established in 1996, and codified into law by Congress in the E-Government Act of 2002. The CIO Council is described on its Web site like this: "The CIO Council serves as the principal interagency forum for improving practices in the design, modernization, use, sharing, and performance of Federal Government agency information resources." Membership on the Council is comprised of CIOs and deputy CIOs from 28 federal agencies, including the departments of Commerce, Defense, Justice, and State.

One interesting piece of news featured on the Web site is a PDF document with this title: "Top Ten Risks Impeding the Adequate Protection of Government Information." Here's how the document begins:


More Global CIO Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

MEMORANDUM FOR CHIEF INFORMATION OFFICERS

FROM: Karen Evans Administrator, Office of E-Government and Information Technology

SUBJECT: Top 10 Risks Impeding the Adequate Protection of Government Information

In order to maintain the trust of the American public, we must operate effectively by securing government information and safeguarding personally identifiable information in our possession. To make the federal government's identity theft awareness, prevention, detection, and prosecution efforts more effective and efficient, the President's Identity Theft Task Force recently issued "Combating Identity Theft: A Strategic Plan."

The strategic plan instructed the Office of Management and Budget and the Department of Homeland Security to develop the attached paper identifying common risks (or "mistakes") and best practices to help improve your agency's security and privacy programs. Each risk is associated with selected best practices and important resources to help your agency mitigate and avoid these risks. All of the best practices and important resources are inter-related and complementary, and they can be broadly applied when administering your information security and privacy programs.

I love those quote marks around "mistakes" -- they're so ... lawyerly. Here's the list, minus the accompanying best practices and important resources. See how these "guidelines" match up with your own security initiatives.

    1. Security and privacy training is inadequate and poorly aligned with the different roles and responsibilities of various personnel. [[Beware the insider.]]

    2. Contracts and data sharing agreements between agencies and entities operating on behalf of the agency do not describe the procedures for appropriately processing and adequately safeguarding information. [[Beware the outsider.]]

    3. Information inventories inaccurately describe the types and uses of government information, and the location where it is stored, processed, or transmitted, including personally identifiable information. [[Like the front seat of an intern's car?]]

    4. Information is not appropriately scheduled, archived, or destroyed. [[The federal government destroys information? Since when?]]

    5. Suspicious activities and incidents are not identified and reported in a timely manner. [[Unless you count The New York Times.]]

    6. Audit trails documenting how information is processed are not appropriately created or reviewed. [[What's an audit trail?]]

    7. Inadequate physical security controls where information is collected, created, processed or maintained. [[I've got the number for Blackwater around here somewhere.]]

    8. Information security controls are not adequate. [[The plain, simple truth.]]

    9. Inadequate protection of information accessed or processed remotely. [[Remember: Lock up that laptop.]]

    10. Agencies acquire information technology and information security products without incorporating appropriate security and privacy standards and guidelines. [[So what's wrong with point solutions?]]

These seem like conventional wisdom to me -- if government agencies aren't implementing these simple security measures by now, we're all in trouble. What do you think? What should federal government agencies concentrate on to stop identity theft -- and cybersecurity problems in general?


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links