MAR 11, 2013 3:26pm ET

Related Links

University Settles with Feds After HIPAA Violations
May 22, 2013
Data Entry Error Leads to Data Breach at LSU
May 21, 2013
Quick Turnaround on Breach Notification
May 17, 2013
California Developing Guidance for Patient Consent of HIE
May 17, 2013
Hacker Gets Patient Credit Cards from North Carolina Providers
May 16, 2013
OCR Seminars to Walk through Omnibus HIPAA Rule
May 16, 2013
PHI Breach #3 for Indiana University
May 15, 2013

GAO Pokes Holes in Government’s Cybersecurity Strategy

Print
Reprints
Email

The decade-old federal government cybersecurity strategy continues to face persistent challenges to effectively secure the nation’s online infrastructure, according to recent congressional testimony from the Government Accountability Office.

“Shortcomings persist in assessing risks, developing and implementing security programs, and monitoring results at federal agencies,” the GAO contends. “This is due in part to the fact that agencies have not fully implemented information security programs, resulting in reduced assurance that controls are in place and operating as intended to protect their information resources.”

Other major problems include lack of cybersecurity guidance for federal agencies, variances in the degree to which agencies must comply with specific cybersecurity regulations, the lack of a centralized information sharing system, and failure of the Department of Homeland Security to fully develop predictive analysis of cyber threats.

Consequently, there remains no coherent and comprehensive national strategy, and little coordination among federal agencies. “The federal cybersecurity strategy has evolved over the past decade with the issuance of several strategy documents and other initiatives that address aspects of these challenge areas,” according to the GAO testimony. “However, there is no overarching national cybersecurity strategy that synthesizes these documents or comprehensively describes the current strategy. In addition, the government’s existing strategy documents do not always incorporate key desirable characteristics GAO has identified that can enhance the usefulness of national strategies.”

The testimony is available here.

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn

As the feds ramp up enforcement of privacy and security rules, providers look to fill protection gaps.

Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Already a subscriber? Log in here
Please note you must now log in with your email address and password.