Commentary

George Hulme
 

Good News: Federal Agency IT Security Improving

Usually the government releases news it wants to bury over the weekend. This Saturday, however, the Office of Management and Budget released a report stating that, overall, federal IT security is improving.

Usually the government releases news it wants to bury over the weekend. This Saturday, however, the Office of Management and Budget released a report stating that, overall, federal IT security is improving.According to the OMB report, available here, the federal government generally did a better job at its efforts to secure IT systems than in years past. Such as the conclusion that the Inspectors General at 22 of the 25 major agencies report that 80%, or more, of their systems, have been inventoried. (That's a good step, since you really can't secure what you don't know that you own or operate ... ).

When compared with the initial 2002 statistics, the federal government has come a long way. For instance, 92% of systems have been properly certified and accredited, compared with only 42% in 2002. And 86% of agencies have tested their contingency plan, while 95% have tested their security controls. Those figures where a dismal 35% and 60%, respectively, in 2002.


More Security Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

According to the report, a number of larger agencies made significant gains, including NASA and the departments of State, Treasury, and Defense.

The report also states that these federal agencies spent $5.9 billion, or 9.2% of their total IT budget, on IT security.

Yet, the number of security incidents reported to the US-CERT has skyrocketed. In 2007, the federal agencies reported 12,986 security incidents, compared with 5,146 incidents in 2006, and 3,569 in 2005.

While it may be counterintuitive, I regard the dramatic rise in reported incidents as a good indicator. At least the agencies have a greater awareness of the systems under their control, which provides for better visibility into potentially malicious activity.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links