recommended reading

IG: DHS Does Not Track Security Training of System Administrator Contractors

A cyber security analyst works in the "watch and warning center" in Idaho Falls, Idaho in 2011.

A cyber security analyst works in the "watch and warning center" in Idaho Falls, Idaho in 2011. // Mark J. Terrill/AP file photo

The Homeland Security Department does not keep tabs on whether contractors that monitor vulnerabilities on federal networks have undergone training, according to a new inspector general audit.

These private sector system administrators support CyberScope, a central reservoir for incoming streams of data summarizing every federal agency's computer security posture. The composite view of threat-levels is intended to help Homeland Security leaders manage cyber risks governmentwide. The account of an inadequate security training program for system administrator contractors at DHS follows the alleged breach of top secret files by a system administrator contractor at the National Security Agency.

Homeland Security does not maintain records on who has taken security awareness and specialized information technology training; nor does the department ensure that all training requirements have been completed, according to auditors. 

"CyberScope contractors may not have received the appropriate skills or knowledge to properly administer and secure the systems against potential cyber threats," Frank Deffer, assistant inspector general for the office of IT audits, wrote in the report. 

He said DHS "cannot guarantee the security of the data collected through CyberScope without ensuring that all people involved understand their roles and responsibilities and are adequately trained to perform them." Inspectors reported similar findings in 2011. 

It is now commonplace at Homeland Security to rely on contractors to do work historically performed by government employees, according to a 2010 Government Accountability Office audit. DHS took over responsibility for governmentwide cybersecurity that same year.

In a writtten response to a draft report, Suzanne Spaulding, acting undersecretary for the department's National Protection and Programs Directorate, wrote that the department is developing "procedural controls for tracking CyberScope administrators to ensure training meets or exceeds applicable" federal requirements.

House Democrats voiced concerns about dispatching so many potentially undertrained contractors to handle sensitive cyber data. 

“With the recent national security leak revelations involving a contractor at NSA, we no longer have to speculate about whether contractors are capable of leaking sensitive information," Rep. Bennie G. Thompson, D-Miss., the minority leader of the Homeland Security Committee, said in a statement. 

On several occasions, DHS officials have indicated they intend to hire more federal workers to carry out cybersecurity responsibilities, and "this timely report makes clear that DHS must address this weakness immediately," he added. “Since we know that DHS has a longstanding overreliance on contractors, it is puzzling that DHS has not taken the solid steps to ensure its contractor workforce gets proper security training.”

Threatwatch Alert

Network intrusion / Spear-phishing

Researchers: Bank-Targeting Malware Sales Rise in Dark Web Markets

See threatwatch report

JOIN THE DISCUSSION

Close [ x ] More from Nextgov
 
 

Thank you for subscribing to newsletters from Nextgov.com.
We think these reports might interest you:

  • Data-Centric Security vs. Database-Level Security

    Database-level encryption had its origins in the 1990s and early 2000s in response to very basic risks which largely revolved around the theft of servers, backup tapes and other physical-layer assets. As noted in Verizon’s 2014, Data Breach Investigations Report (DBIR)1, threats today are far more advanced and dangerous.

    Download
  • Featured Content from RSA Conference: Dissed by NIST

    Learn more about the latest draft of the U.S. National Institute of Standards and Technology guidance document on authentication and lifecycle management.

    Download
  • PIV- I And Multifactor Authentication: The Best Defense for Federal Government Contractors

    This white paper explores NIST SP 800-171 and why compliance is critical to federal government contractors, especially those that work with the Department of Defense, as well as how leveraging PIV-I credentialing with multifactor authentication can be used as a defense against cyberattacks

    Download
  • Toward A More Innovative Government

    This research study aims to understand how state and local leaders regard their agency’s innovation efforts and what they are doing to overcome the challenges they face in successfully implementing these efforts.

    Download
  • From Volume to Value: UK’s NHS Digital Provides U.S. Healthcare Agencies A Roadmap For Value-Based Payment Models

    The U.S. healthcare industry is rapidly moving away from traditional fee-for-service models and towards value-based purchasing that reimburses physicians for quality of care in place of frequency of care.

    Download
  • GBC Flash Poll: Is Your Agency Safe?

    Federal leaders weigh in on the state of information security

    Download

When you download a report, your information may be shared with the underwriters of that document.