A review of procedures at the Securities and Exchange Commission showed, among other deficiencies, a lack of information security, particularly around maintaining baseline cybersecurity standards, password settings and network services, according to a new report from the Government Accountability Office.
At the base of the issue is a failure to update the agency’s configuration baselines — the set of standards for managing access and control within networks.
Report: Improvements Needed in SEC’s Internal Controls and Accounting Procedures
“We found that SEC did not maintain and monitor configuration baselines for the significant financial systems and general support systems,” GAO wrote in the new report, also citing a failure to maintain “baseline settings for the database supporting a key financial system.”
The report also notes the commission’s lack of an inventory of hardware, software and firmware for “significant financial systems” and the associated data elements.
“Not monitoring configuration baseline settings may result in exploitation without detection or user accountability,” the report warns. “Without a complete and accurate systems baseline designating critical components, SEC does not have an accurate inventory that can be used for determining approved configuration baselines, configuration change control/security impact analysis and monitoring/reporting.”
Related: Buying IaaS — Colocation or wholesale hosting?
More specifically, GAO found that SEC policies on passwords were often circumvented or ignored, creating a serious security gap.
The official policy requires passwords to expire after 120 days and limits the number of incorrect attempts before locking the system.
The expiration date for passwords was lifted on 22 of the 92 assets reviewed by GAO, as were limitations on the number of log-in attempts for six assets.
The commission’s systems are also lax on password strength, allowing users to create passwords with fewer than eight characters and failing to require the use of both letters and numerals.
These critical vulnerabilities are a direct result of not having strong configuration baselines, according to GAO.
“If unresolved, these weaknesses can jeopardize the reliability of the data processed by key financial systems and increase the risk that unauthorized individuals could gain access to financial systems and intentionally or inadvertently access, alter or delete sensitive data or computer programs,” GAO notes.
SEC Chair Mary Jo White called the GAO recommendations “helpful,” and said the agency “remains committed to investing the time and resources necessary to maintain strong internal controls over financial reporting.”




