Federal Cybersecurity Incidents Rocket 650% In 5 Years
As Obama administration declares October a time to focus on stopping cybersecurity threats, GAO releases a report indicating weaknesses.Reports of security incidents among 24 key agencies increased more than 650% in the last five years, according to a report released Monday by the Government Accountability Office. The report cited persistent weaknesses in information security controls, due to incomplete implementation of security programs, for the disturbing increase in security problems.
More Government Insights
Webcasts
- Single Source of Truth for Managing Critical Assets Application Consolidation across Public Sector Organizations
- Reliable Information for Actionable Insights
White Papers
More >>Reports
More >>At the same time, President Obama has deemed October a month in which the nation should pay special attention to the cybersecurity issues his administration has been working to combat.
"I call upon the people of the United States to recognize the importance of cybersecurity and to observe this month with activities, events, and trainings that will enhance our national security and resilience," Obama said in a proclamation about National Cybersecurity Awareness Month.
[The feds are taking a new approach to fighting national security threats. Learn more: Homeland Security Revamps Cyber Arm.]
In the proclamation, Obama highlighted efforts the administration has made to bolster cybersecurity within the federal government and among businesses and private consumers.
One is the release of the National Strategy for Trusted Identities in Cyberspace, which aims to improve security for consumers conducting e-commerce by helping prevent fraud and identity theft and by making it easier for businesses to operate online.
Others include numerous partnerships with the private sector to bolster security for U.S. critical infrastructure, and the Department of Homeland Security's Stop. Think. Connect. campaign to raise people's Internet security awareness.
Still, the GAO report suggests that the administration's internal cybersecurity efforts may not be enough. Despite the agency and other federal inspectors making a number of security recommendations to agencies in fiscal years 2010 and 2011, cybersecurity incidents persist, according to the report.
The GAO cited weaknesses in how agencies are implementing security controls as a reason things don't appear to have improved. Specifically, agencies are not always making sure that personnel with significant responsibilities receive the proper training or that there is active monitoring of security controls.
Agencies also have not fixed weaknesses effectively nor have they resolved incidents "in a timely manner," according to the report.
The GAO also put some blame on the Office of Management and Budget for persistent cybersecurity incidents, saying that while they provided new cybersecurity metrics for agencies, they did not always provide performance target to measure improvements.
Despite the bleak news, the administration continues to hammer away at cybersecurity and has even recently taken more steps to force agencies to be more proactive in preventing incidents.
One new mandate that should bring better monitoring of agencies' cybersecurity postures is that agencies must begin reporting security data monthly to an online compliance tool called CyberScope as part of new fiscal year 2011 requirements for Federal Information Security Management Act (FISMA), the standard for federal security implementation.
In "Becoming A Security Detective," this all-day virtual event from InformationWeek and Dark Reading, experts will offer detailed insight in how to collect security intelligence in the enterprise, and how to analyze and study it in order to efficiently identify new threats as well as low-and-slow attacks such as advanced persistent threats. It happens Oct. 20. Sign up now. (Free with registration.)
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Subscribe to RSSResource Links
Related Webcasts
- Single Source of Truth for Managing Critical Assets Application Consolidation across Public Sector Organizations
- Reliable Information for Actionable Insights
- The view is better up here: breaking through barriers to Cloud
- Supporting an Enterprise-wide Data Archive and Retention Strategy
- High-Frequency Trading: The Good, The Bad and The Ugly
This Week's Issue
Free Print Subscription
SubscribeCurrent Healthcare Issue
- InformationWeek Healthcare CIO 25: Our second annual honor roll of the health IT leaders driving healthcare's transformation.
- EHR Unreadiness: Only a small percentage of physicians planning to apply for Meaningful Use funds have e-health record systems capable of achieving most of the requirements. .
- And much more!
- Read the Current Issue
Related Whitepapers
- Advanced Case Management: Making its Mark on Key Government Sectors
- Unleashing Cloud Performance
- The Creating value in the Public Sector: intelligent project selection in the US federal government
- Improve Business Performance in a Project-Intensive World
- Defining and Planning Continuous Monitoring for NIST Requirements
Featured Whitepaper
In this white paper, Tripwire discusses strategies for defending cyber threats that include monitoring security status of systems throughout the enterprise, detecting threats to sensitive data, and responding to threats in real-time.
Learn More













