SHARE
Facebook X Pinterest WhatsApp

Feds Flunk Security 101

Written By
thumbnail
Allan Alter
Allan Alter
Sep 5, 2005

The language is dry but the findings are damning. Despite some improvements, the U.S. Government Accountability Office, in its first comprehensive study of computer security in the federal government conducted under the 2002 Federal Information Security Management Act, found “pervasive weaknesses” in security practices at 24 major agencies.

The departments of Defense and Homeland Security were among the 14 agencies with problems in all five categories that were examined: controlling access to government data; controlling what software is installed; detecting inappropriate activity; business continuity planning; and fully implementing information security programs.

Many of the flaws the GAO documented in its gloomy July 2005 report are security basics. For example, users employed common words as passwords.

Also, agencies failed to deactivate user accounts, keep software updated, and include emergency contact information in their contingency plans. Gregory Wilshusen, the GAO’s director of information security issues, writes that these and other weaknesses “put federal operations and assets at risk of fraud, misuse and destruction. In addition, they place . . . sensitive information at risk of inappropriate disclosure, and critical operations at risk of disruption.”

Wilshusen says that the government is “making progress,” however. For example, 23 agencies reviewed at least 90 percent of their systems in 2004, up from 11 agencies in 2003. Wilshusen also urges better follow-through on implementing programs and more detailed reporting.

Recommended for you...

What do Amazon, Microsoft, Meta, and IBM Have in Common? Tape Storage
Drew Robb
Aug 15, 2022
What Does Quantum Computing Mean for IT?
Devin Partida
Aug 11, 2022
Solving the Video Surveillance Retention Challenge 
Drew Robb
Jul 28, 2022
Top 6 IT Challenges in Healthcare
Lauren Hansen
Jun 21, 2022
CIO Insight Logo

CIO Insight offers thought leadership and best practices in the IT security and management industry while providing expert recommendations on software solutions for IT leaders. It is the trusted resource for security professionals who need to maintain regulatory compliance for their teams and organizations. CIO Insight is an ideal website for IT decision makers, systems integrators and administrators, and IT managers to stay informed about emerging technologies, software developments and trends in the IT security and management industry.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.