Feds get an overall 'C-' on security; a third of agencies are given 'F' grades
Governmentwide grade improves from D+ on earlier versions of annual report card
Computerworld - The federal government today got an overall grade of C-minus in an annual computer security report card that evaluates the performance of 24 individual agencies covered by the Federal Information Security Management Act (FISMA).
Eight agencies -- including the departments of Defense, Interior and State as well as the Nuclear Regulatory Commission -- received failing grades. An equal number of agencies, including the General Services Administration, the Social Security Administration and the Department of Housing and Urban Development (HUD), scored at least an A-minus.
The grades in the seventh annual report card on federal computer security were released this morning by Rep. Tom Davis, (R-Va.), ranking member of the House Committee on Oversight and Government Reform (download PDF). The committee each year releases the Federal Computer Security Report Card based on security evaluations defined in FISMA. The evaluations are compiled by the committee based on information provided to Congress each year by the inspector general from each agency.
Asked at a news conference whether the U.S. public should be confident that government agencies are protecting against cyberterrorism, Davis said, "It doesn't give me a lot of confidence."
Davis defended the Department of Homeland Security, which got a "D," saying it is still working to integrate the 22 agencies merged to create it in 2002. The creation of the department was a "horrendous, complicated deal," he said.
"It's a work in progress, and it's going to take some time."
But Davis had no kind words for the Department of Defense. He called it a "badly managed agency" with each military branch focusing on its own technology.
Agencies are rated on issues such as their adherence to security configuration standards, their ability to detect and respond to intrusions, whether they certify and accredit their systems, inventory accuracy and the kind of security training programs they offer employees.
Overall, the government's C-minus performance marks a "slow but steady improvement from past years," said Davis in a statement, pointing to the D-plus and D grades he had given the government over the past three years. "Obviously, challenges remain. But there are some excellent signs of progress in this year's report, and that's encouraging."
Those showing the most improvement in this year's report were the Department of Justice and HUD, both of which jumped from Ds to As. Meanwhile, NASA and the Department of Education showed the biggest declines in security. The space agency dropped from a B-minus to a D-minus; the education department went from a C-minus to an F.
According to Davis, this year's reports show that more agencies are paying attention to issues such as the annual testing of security controls and contingency plans -- and there is much better reporting of security breaches. However, more progress needs to be made in areas such as configuration management and progress measurement, he said.
This pilot fish is a contractor at a military base, working on some very cool fire-control systems for tanks. But when he spots something obviously wrong during a live-fire test, he can't get the firing-range commander's attention.
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Reduce federal infrastructure risk with compliance management and situational awareness
- IBM continuous monitoring and management solutions deliver real-time situational awareness to help federal agencies understand vulnerabilities, and protect the infrastructure.
- Virtualization and Cloud Computing: Optimized Power, Cooling, and Management Maximizes Benefits
- The effects that the cloud and virtualization have on the data center are discussed and possible solutions or methods for dealing with them...
- Comparing Data Center Power Distribution Architectures
- Significant improvements in have been achieved in data center power distribution, increasing the options available for data centers. This paper compares five power...
- Implementing Hot and Cold Air Containment in Existing Data Centers
- This paper investigates the constraints, reviews all available containment methods, and provides recommendations for determining the best containment approach.
- Data Center Projects: Project Management
- The project management model described in this paper is a framework to show essential characteristics that must be considered in any implementation of... All Government IT White Papers
- What should I look for in a Next Generation Firewall? SANS Provides Guidance With so many vendors claiming to have a Next Generation Firewall (NGFW), it can be difficult to tell what makes each one different....
- Why Are Customers Really Deploying an NGFW? It seems every IT Security expert is talking about the NGFW, but what are people really doing? This webcast covers 5 real-world customer...
- Charting Your Analytical Future - "Making predictive analytics part of your business processes" Webinar This session will show how predictive analytics can be used throughout the organization by anyone looking for answers and how organizations can make...
- On-demand webinar - 7 Keys to Service Catalog Implementation Success Watch this webinar to learn 7 crucial keys to make your service catalog a success!
- Transform Your IT Service Management Watch this webinar, to learn how EasyVista can increase IT productivity & efficiency and deliver streamlined & integrated IT Service & Asset Mgmt.
- All Government IT Webcasts