Skip the navigation
News

Feds moving ahead on effort to reduce Internet connections, but with adjusted target

IT chief says external links cut from 4,300 to 2,750; ultimate goal now about 100, up from 50

By Jaikumar Vijayan
July 10, 2008 12:00 PM ET

Computerworld - Federal agencies continue to report that they're making progress on a governmentwide initiative aimed at reducing their exposure to Internet-based threats, according to Karen Evans, the de facto federal CIO. But she also disclosed that the effort to consolidate the government's connections to the Net has been scaled back because of feedback from agency officials.

During a press conference today, Evans, whose official title is administrator of e-government and IT at the White House Office of Management and Budget, provided a status update on the Trusted Internet Connections (TIC) initiative launched by the OMB last November. As part of the effort (download PDF), civilian agencies are working to reduce the number of external Internet connections that they have in place.

The goal is to lower the risk that government systems will be hit by online attacks, and to make it easier to monitor the Internet connections agencies are using. Instead of having each individual agency manage its own connections, the plan is to have a small group of TIC access providers offering centralized connectivity and gateway-monitoring services to some agencies.

Evans said that as of May, the number of external connections had been reduced from a total of more than 4,300 when the TIC initiative was announced to just over 2,750, based on reports submitted to the OMB by agencies. But she added that instead of whittling down the overall number of connections to 50, which is what the plan originally called for, the OMB now is looking to lower that number to about 100 by the end of 2009.

"Initially, we thought we could bring it down to 50," Evans said. "Right now, based on feedback from agencies and the [General Services Administration], we have set the goal at less than 100."

Thus far, two agencies have indicated their willingness to act as Internet access providers for other agencies, Evans said without identifying them. One has already demonstrated the technical and business capabilities needed to deliver access services beyond its own systems, while the other is about 90% of the way there and is working to close the remaining gaps in its capabilities, she said. Between them, those two agencies are expected to manage a total of seven Internet connections.

Another 16 agencies have shown themselves to be willing and able to act as their own Internet access providers, Evans said, adding that they likely will oversee a combined total of 72 connections under TIC. The remaining 121 agencies covered by the initiative will have their Internet connections managed via a GSA-approved access provider, according to Evans.

The number of connections eliminated thus far "is quick, impressive progress," said Alan Paller, director of research at the SANS Institute, a Bethesda, Md.-based security training and certification organization. And for the most part, that progress has been "relatively painless" for federal agencies, he added.

"The agencies trying to make it hard are just whining out of habit, as they do whenever they're asked to do security," said Paller, who is an adviser to the government on the TIC initiative.

TIC is a key component of a broader "Cyber Initiative" that was mandated by President Bush in a classified directive issued in January. The directive called on agencies to work together to improve the security of federal systems, which has routinely been criticized in congressional report cards and in reports issued by the Government Accountability Office.

Among other things, Bush's mandate calls for expanded monitoring of federal networks in order to enable network administrators to detect intrusions and other malicious activities and then respond to them more quickly than they can now. In an interview earlier this year, Evans vowed that the efforts to improve security will be done "in a very transparent way," without compromising the privacy of federal workers.

Read more about Security in Computerworld's Security Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs