Feds get an overall 'C-' on security; a third of agencies are given 'F' grades
Governmentwide grade improves from D+ on earlier versions of annual report card
Computerworld - The federal government today got an overall grade of C-minus in an annual computer security report card that evaluates the performance of 24 individual agencies covered by the Federal Information Security Management Act (FISMA).
Eight agencies -- including the departments of Defense, Interior and State as well as the Nuclear Regulatory Commission -- received failing grades. An equal number of agencies, including the General Services Administration, the Social Security Administration and the Department of Housing and Urban Development (HUD), scored at least an A-minus.
The grades in the seventh annual report card on federal computer security were released this morning by Rep. Tom Davis, (R-Va.), ranking member of the House Committee on Oversight and Government Reform (download PDF). The committee each year releases the Federal Computer Security Report Card based on security evaluations defined in FISMA. The evaluations are compiled by the committee based on information provided to Congress each year by the inspector general from each agency.
Asked at a news conference whether the U.S. public should be confident that government agencies are protecting against cyberterrorism, Davis said, "It doesn't give me a lot of confidence."
Davis defended the Department of Homeland Security, which got a "D," saying it is still working to integrate the 22 agencies merged to create it in 2002. The creation of the department was a "horrendous, complicated deal," he said.
"It's a work in progress, and it's going to take some time."
But Davis had no kind words for the Department of Defense. He called it a "badly managed agency" with each military branch focusing on its own technology.
Agencies are rated on issues such as their adherence to security configuration standards, their ability to detect and respond to intrusions, whether they certify and accredit their systems, inventory accuracy and the kind of security training programs they offer employees.
Overall, the government's C-minus performance marks a "slow but steady improvement from past years," said Davis in a statement, pointing to the D-plus and D grades he had given the government over the past three years. "Obviously, challenges remain. But there are some excellent signs of progress in this year's report, and that's encouraging."
Those showing the most improvement in this year's report were the Department of Justice and HUD, both of which jumped from Ds to As. Meanwhile, NASA and the Department of Education showed the biggest declines in security. The space agency dropped from a B-minus to a D-minus; the education department went from a C-minus to an F.
According to Davis, this year's reports show that more agencies are paying attention to issues such as the annual testing of security controls and contingency plans -- and there is much better reporting of security breaches. However, more progress needs to be made in areas such as configuration management and progress measurement, he said.
- 18 Hot IT Certifications for 2014
- CIOs Opting for IT Contractors Over Hiring Full-Time Staff
- 12 Best Free iOS 7 Holiday Shopping Apps
- For CMOs Big Data Can Lead to Big Profits
- Slideshow: 5 ways to lock down your mobile device
- Slideshow: 10 mistakes companies make after a data breach
- How to rob a bank: A social engineering walk through
- Which smartphone is the most secure?
If you think getting it right from day one is always what matters, you probably haven't been following technology too closely.
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Bring Networks and Applications Closer--Cisco ONE
- A series of sweeping trends is placing new requirements on the tried-and-true network model--requiring network infrastructure and applications to communicate. Get the open...
- Lippis Research Reviews the Cisco Catalyst 2960-X
- In this Lippis Report Research Note, Lippis Research reviews the latest edition of the "most popular access switch on the planet" -- the...
- Design Guide--Scaling Up to a Campus-Wide LAN
- Is it time to scale your network environment to a campus wired LAN? Here's the framework you need to set up your LAN...
- Comprehensive Security: Cisco Catalyst 2960 Series
- With a rich and comprehensive set of security features, Cisco Catalyst 2960-X and 2960-XR Series Switches can help you address networking megatrends such...
- Be Energy Efficient--The Cisco Catalyst 2960 Series
- How much energy could be saved if all 230 million Layer 2 and 3 fixed managed switch ports sold in 2012 were as... All Government IT White Papers
- Modernizing SAP environments with minimum risk - a path to Big Data Hear from top IDC analyst, Richard Villars, about the path you can start taking now to enable your organization to get the benefits...
- Vblock™ Specialized System for SAP HANA® Overview video from DJ Long about the new Vblock Specialized System for SAP HANA®.
- The Power of the Citrix Mobility Solution, XenMobile Does everything become a smartphone? Or does the smartphone begin to do everything? How can we afford to support BYOD? Rather, how can...
- BYOD Happens: How to Secure Mobility How to navigate the journey of securing mobility, including the BYOD corruption of IT, the top ten mobility strategies, and the mobility management...
- Fighting Fraud Videos: IBM Intelligent Investigation Manager Short videos about IBM Intelligent Investigation Manager (IIM) for Fraud. IIM optimizes the investigation of fraud for customers across many industries in both...
- All Government IT Webcasts
Does your organization offer extensive benefits, cool perks, competitive salaries, opportunities for training and advancement? Then get it recognized!
Nominate your company or another deserving organization for Computerworld's 2014 Best Places to Work in IT list now through Dec. 20, 2013.