Ads by TechWords

See your link here
Receive the latest technology news and information.
Storage
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Feds See Slight Gain On Security Marks

Overall grade up to C-, but eight agencies still flunk FISMA test

April 16, 2007 12:00 PM ET

Computerworld - The federal government last week received an overall grade of C- on an annual IT security report card issued by Rep. Tom Davis (R-Va.). That was a slight improvement from the D+ grades handed out for the two previous years, but eight agencies got failing marks — the same number as last year.

The agencies at the bottom of the report card included the departments of Defense, State, the Interior and the Treasury, as well as the Nuclear Regulatory Commission. It was the second straight F grade for the Defense, State and Interior departments. Meanwhile, the Department of Homeland Security received a D, up one grade from an F a year ago.

Karen Evans, administrator of e-government and IT at the White House Office of Management and Budget, said at a press conference in Herndon, Va., that she was encouraged by the improvement in the overall security grade but not satisfied with the results. “I would not accept a C- on my kids’ report cards,” Evans said. “Average is not good enough.”

The grades are based on reports compiled annually bythe agencies’ inspectors general to comply with the requirements of the Federal Information Security Management Act, which Davis authored. The FISMA reports submitted for 2006 show that more agencies are testing their security controls and contingency plans and that the reporting of security breaches has “increased dramatically,” said Davis, who is the ranking minority member on the House Committee on Oversight and Government Reform.

However, Davis said more improvements need to be made in areas such as secure systems configuration and the development of effective security plans, as well as establishing milestones for measuring the progress of the plans.

Not everyone is convinced, though, that the FISMA-based report card provides a clear picture of the security posture within federal agencies.

Avoiding a Black Eye

Alan Paller, director of research at the SANS Institute in Bethesda, Md., said that although the grades for 2006 appear to show an overall improvement, at least some of the gains likely are the result of “a few more agency [inspectors general] deciding it wasn’t worth it to give a black eye to their departments” by issuing a poor assessment of their security practices.

Paller also pointed to continuing limitations in how agencies are assessed for security readiness. For example, one of the most important contributors to a good FISMA grade is the level of compliance within an agency to hardware and software configuration standards established by its information security team.



Jump to comments

Karen Evans

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

PCI DSS Compliance in the UNIX/Linux Datacenter Environment
Download this complimentary white paper today! Provided by BeyondTrust.  

Preventing Data Breaches in Privileged Accounts Using Access Control
To learn how using access control can protect your organization, download this white paper today!  

Achiving Compliance Through Good Governance
Watch this complimentary video today!

FISMA Prescriptive Guide
A Tactical Guide Enabling you to take Action and Achieve Operational Excellence