Originally published: August 9, 2011
Last updated: August 9, 2011 - 5:43pm
Government watchdogs have found holes in a project designed to plug vulnerabilities in computer networks and systems at the State Department, according to the Government Accountability Office (GAO). The program, called iPost, was created to provide continuous monitoring of information security risks within the department's IT infrastructure, GAO said. "But it does not provide a complete view of" those risks. State officials use iPost risk scores to identify and prioritize vulnerability mitigation.
GAO noted progress in iPost implementation but flagged shortfalls. The system:
- Addresses Windows hosts but not other IT assets on its major unclassified network.
- Covers a set of 10 scoring components that includes many, but not all, information system controls that are intended to reduce risk.
- Assigns a score for each identified security weakness, although State could not demonstrate the extent to which scores are based on risk factors such as threat, impact, or likelihood of occurrence that are specific to its computing environment."
GAO recommended State "(1) implement procedures to consistently notify senior managers at sites with low security grades of the need for corrective actions, in accordance with department criteria, and (2) develop, document, and implement a continuous monitoring strategy."
- Login or register to post comments
- Email this page
Related
- Watchdog cites gaps in security of wireless devices
- DHS needs to plug some cybersecurity holes, audit finds
- Security Pros Are Focused on the Wrong Threats
- The Government Model
- GAO: Federal network security breaches spike 650 percent
- America's power grid too vulnerable to cyberattack
- GAO: Continued Attention Needed to Protect Our Nation's Critical Infrastructure and Federal Information Systems
- Government in cyber fight but can't keep up
- Hacker attacks show vulnerability of cloud computing
- DHS Cybersecurity Center Promotes Information Sharing
- Cyber czar: Power companies need to watch their backs
- Homeland Security authorized to hire up to 1,000 cybersecurity specialists
- Targeting Phone Security Flaws
- White House grading agency cyber progress
- Homeland Security seeks to thwart cyberattacks
National Broadband Plan
Learn more about:
Location
Ratings
Login to rate this headline.

