The Government Accountability Office has released a statement on the laws, policies and longstanding challenges impacting the nation’s cybersecurity, as well as the controls needed to reinforce information security protections.
The study, “Federal Information Security: Actions Needed to Address Challenges,” collects previously published work alongside testimony given by Gregory Wilshusen, director of information security issues, before the President’s Commission on Enhancing National Cybersecurity.
Cyber incidents have increased by 1,300 percent from fiscal 2006 to fiscal 2015. The nation’s critical cyber infrastructure, and the protection of personally identifiable information collected, maintained and shared by federal and nonfederal entities, has been designated a governmentwide high-risk area. Laws and policies have been established but not deployed consistently throughout organizations, and the growing cyberthreat has shown government systems to be vulnerable.
This has prompted the GAO to make more than 2,500 recommendations in recent years for federal agencies to implement risk-based information security programs; improve capabilities for detecting, responding to and mitigating cyber incidents; and expand cyber workforce and training efforts. However, 1,000 security-related recommendations that the GAO has made but that have not been implemented remain a major flashpoint.
GAO’s study shows that agencies have not fully, effectively or consistently developed, documented and implemented the framework provided under the Federal Information Security Modernization Act of 2014 and its predecessor, the Federal Information Security Management Act of 2002, as well as several other acts that codify roles and responsibilities.
Agencies continue to be directed to enhance capabilities to effectively identify cyberthreats to agency systems and information; implement sustainable processes for securely configuring operating systems, applications, workstations, servers and network devices; patch vulnerable systems and replace unsupported software; develop comprehensive security test and evaluation procedures and conduct examinations on a regular and recurring basis; and strengthen oversight of contractors providing IT services.
GAO also recommended DHS promote wider adoption of its intrusion detection and
prevention system, as agencies need effective mechanisms for detecting, responding to, reporting and recovering from incidents. Plans for recruiting and retaining a qualified cybersecurity workforce should also be a priority to support control deficiencies and mitigation efforts as government systems labor to keep up with increasing cyberthreats.
Download the entire 17-page PDF from the GAO website.




