DHS infosec weaknesses cited

By
Follow google news

The Department of Homeland Security has not fully implemented a comprehensive information security program, according to the Governmental Accountability Office.

In a report released Monday, the GAO said key infosec practices and controls - including risk assessments, testing and evaluation of security controls, and remedial action plans - were either incomplete or missing in a review of selected DHS departmental components.


DHS has an "enterprisewide tool" for overseeing implemention of security controls but that tool has not been reliable, according to the report.

"Until DHS addresses weaknesses with using the tool and implements a comprehensive, departmentwide information security program, its ability to protect its information and information systems will be limited," GAO analysts said.

In a written response, DHS officials generally agreed with the report and outlined what the agency is doing to implement its infosec program.

In May, the GAO reported that DHS was lagging in its cybersecurity responsibilities, including development of national cyber threat and vulnerability assessments and recovery plans.

www.gao.gov

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Bendigo Bank aims to have Australia's "first agentic SOC"

Bendigo Bank aims to have Australia's "first agentic SOC"

ASD to retire Essential Eight cyber security framework within next two years

ASD to retire Essential Eight cyber security framework within next two years

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

NAB's SecOps rethink focuses on data expert and dev hires

NAB's SecOps rethink focuses on data expert and dev hires

Log In

  |  Forgot your password?