NextGov.com

Brought to you by GovernmentExecutive.com Events

Government Executive events provide federal managers with practical insights on current topics. They feature prominent thought leaders addressing key issues facing the federal government. Attendees gain the latest insights and best practices from their colleagues throughout government.

UPCOMING EVENTS

OCTOBER 21
Communication Today: New Generations, New Rules

OCTOBER 23
Developing Effective Records Management Strategies

What's happening in the federal IT community

A Serious Gamer for the Obama Team
by Allan Holmes - 11/19/08 5:09 pm EST

Feds May Want Vendors to Vouch
by Gautham Nagesh - 11/19/08 4:47 pm EST

CACI Hires Former FBI CIO
by Allan Holmes - 11/18/08 9:38 am EST

What If We're All the CTO?
by Anne Laurent - 11/17/08 3:32 pm EST

What should the CTO do?
by Gautham Nagesh - 11/14/08 9:48 am EST





















Audit shows continued weaknesses in FEMA's IT security
By Gautham Nagesh, gnagesh@govexec.com   08/05/08

A recent audit found that the Federal Emergency Management Agency has failed to correct a number of information technology security weaknesses flagged last year.

Comment on this article in The Forum.The audit, conducted by the accounting firm KPMG on behalf of Homeland Security Inspector General Richard Skinner and released Monday, found that FEMA failed to correct 31 security issues discovered in fiscal 2007. The agency successfully addressed only 10 of the issues identified. Moreover, auditors found 13 new weaknesses for fiscal 2008.

"These issues collectively limit FEMA's ability to ensure that critical financial and operational data is maintained in a manner to ensure confidentiality, integrity and availability," the report stated.

The audit, which was heavily redacted before release, identified problems in areas such as agencywide security and disaster planning, access and password controls, and documentation of security tests.

For example, auditors found that almost 800 former FEMA employees and contractors still had active accounts for the agency's computer systems. Auditors classified FEMA's password management controls as weak, adding the agency gave excessive access to certain sensitive or critical files and applications.

FEMA's strategy for continuing operations in the event of a disaster or service interruption has not been adequately tested, the report noted. In addition, the agency has not updated its list of mission-critical IT systems that would have to be restored at an alternate site in the event of an emergency.

Auditors recommended that FEMA officials address the remaining issues by focusing on monitoring and enforcing IT security policies and procedures. Many older vulnerabilities could be addressed by reconfiguring the agency's software to comply with DHS and National Institute of Standards and Technology requirements, the report stated.

FEMA officials concurred with the auditors' recommendations and detailed some steps they have taken to deal with the security issues. For example, the agency is developing a semiautomated, semiannual process to validate employees' access to systems and remove unnecessary accounts. In addition, the agency changed its wait for dropping locked accounts of terminated employees to 45 days from 90 days in accordance with DHS policy. The inspector general's office confirmed that FEMA is working to address the known weaknesses.


E-MAIL THIS ARTICLE    SHARE THIS ARTICLE    PRINT THIS ARTICLE

VENDOR SOLUTIONS

Facing challenges for delivering applications quickly and securely?
Application Delivery Network Whitepaper brought to you by Blue Coat

The New Congress Briefing - Implications of the election outcomes
Offered by the Government Affairs Institute at Georgetown University

Kronos Solutions for the Federal Government brochure
Federal Contractor Accounting Whitepaper, brought to you by Kronos

BIM and Facilities Management Whitepaper
Free whitepaper, brought to you by Autodesk.

3 New White Papers from IBM
Transformational Government; Going Green; and ECM for Government Case Management

View more products and services... Purchase a link now...