Report: DHS infosec program needs improvement

By
Follow google news

Although the Department of Homeland Security has made some progress with its information security program it still has a long way to go, according to a report released Wednesday by the department’s inspector general.

Specifically, the DHS CIO is not a member of the department's senior management team so he does not have authority to strategically manage agency-wide IT programs, the IG said. Also, there is no formal reporting structure between the CIO and the infosec managers of the agency's nine components, hindering support in implementing the DHS infosec program.


Among the other problems, DHS lacks an accurate and complete system inventory, which prevents it from effectively managing its infosec program, the IG said. Component infosec managers do not understand required program and system information, limiting DHS' ability to put together a comprehensive inventory.

The IG recommended that DHS improve its procedures for wireless technologies, remote access, vulnerability scanning, incident detection, among other areas.

In a written response, DHS's CIO generally agreed with the report's recommendations and said the department already is working to address issues raised by the IG, including compiling a comprehensive system and application inventory.

www.dhs.gov

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?