GAO knocks SEC on info security, password management

WASHINGTON, DC – JANUARY 21: Federal Deposit Insurance Corporation Chairman Martin Gruenberg (L) listens as Securities and Exchange Commission Chair Mary Jo White (R) speaks during an open session meeting of the Financial Stability Oversight Council January 21, 2015 at the Treasury Department in Washington, DC. The council met to receive an update on benchmark reform efforts and a discussion of the Council’s process for considering nonbank financial companies for potential designation. (Photo by Alex Wong/Getty Images)

A review of procedures at the Securities and Exchange Commission showed, among other deficiencies, a lack of information security, particularly around maintaining baseline cybersecurity standards, password settings and network services, according to a new report from the Government Accountability Office.

At the base of the issue is a failure to update the agency’s configuration baselines — the set of standards for managing access and control within networks.

Report: Improvements Needed in SEC’s Internal Controls and Accounting Procedures

“We found that SEC did not maintain and monitor configuration baselines for the significant financial systems and general support systems,” GAO wrote in the new report, also citing a failure to maintain “baseline settings for the database supporting a key financial system.”

The report also notes the commission’s lack of an inventory of hardware, software and firmware for “significant financial systems” and the associated data elements.

“Not monitoring configuration baseline settings may result in exploitation without detection or user accountability,” the report warns. “Without a complete and accurate systems baseline designating critical components, SEC does not have an accurate inventory that can be used for determining approved configuration baselines, configuration change control/security impact analysis and monitoring/reporting.”

Related: Buying IaaS — Colocation or wholesale hosting?

More specifically, GAO found that SEC policies on passwords were often circumvented or ignored, creating a serious security gap.

The official policy requires passwords to expire after 120 days and limits the number of incorrect attempts before locking the system.

The expiration date for passwords was lifted on 22 of the 92 assets reviewed by GAO, as were limitations on the number of log-in attempts for six assets.

The commission’s systems are also lax on password strength, allowing users to create passwords with fewer than eight characters and failing to require the use of both letters and numerals.

These critical vulnerabilities are a direct result of not having strong configuration baselines, according to GAO.

“If unresolved, these weaknesses can jeopardize the reliability of the data processed by key financial systems and increase the risk that unauthorized individuals could gain access to financial systems and intentionally or inadvertently access, alter or delete sensitive data or computer programs,” GAO notes.

SEC Chair Mary Jo White called the GAO recommendations “helpful,” and said the agency “remains committed to investing the time and resources necessary to maintain strong internal controls over financial reporting.”

About 

Aaron Boyd is an awarding-winning journalist currently serving as editor of Federal Times — a Washington, D.C. institution covering federal workforce and contracting for more than 50 years — and Fifth Domain — a news and information hub focused on cybersecurity and cyberwar from a civilian, military and international perspective.