The Postal Service inspector general has been dinging the agency on its cybersecurity posture recently, with the most recent report examining deficiencies in the firewalls protecting mail processing systems.
The report — which was finalized on Jan. 26 but just released in redacted form — notes USPS maintains 285 firewalls nationwide. The IG sampled 30 of those systems for review and discovered that all of them were deficient on two-thirds of the required security controls.
Download: Firewall Security Review
The report is heavily redacted in some parts and sparsely redacted in others.
For instance, the big takeaway highlighted on the first page states, “Postal Service firewalls are [redacted] at all facilities and are not properly managed and functioning to safeguard mail processing operations.”
In another part of the same page, auditors wrote they reviewed 504,528 rules governing firewall settings and operations, though the results of those reviews have been blacked out.
Postal Service IT managers told auditors their focus has been on getting systems up and running rather than managing security, citing budget constraints.
“IT firewall administrators and engineering systems analysts focused on supporting system deployment as opposed to implementing security controls and managing firewall rules,” the IG said.
Without going into the specifics of the deficiencies, the IG noted IT managers did not do a risk assessment on these decisions, leaving them with little to no context of the ramifications.
As a result, “The Postal Service does not have a reliable and secure network and is at risk of unauthorized access to data and disruption of critical mail processing operations.”
These deficiencies expose the agency to upwards of $237 million in potential revenue losses. Postal Service managers disagreed with this number, pegging the actual exposure at $175,393 and citing continuous monitoring and automated contingencies that would prevent significant revenue loss.
The IG stood by its figures and recommended several actions for USPS management to take immediately.
The salient details of the IG’s primary recommendation is redacted, though secondary recommendations are legible.
Auditors recommended USPS firewall administrators “regularly review and update current firewall configuration settings and implement all security controls in the hardening standards. Finally, we recommend administrators and analysts review firewall rules every six months and review and update firewall security standards annually in accordance with policy.”
A Postal Service spokesman told Federal Times the agency is already taking steps to address the deficiencies.
“As part of the Postal Service’s cybersecurity improvement strategy, postal management has already approved funding and initiated a significant undertaking to enhance firewall and network security at all 352 mail processing facilities,” said Roy Betts, senior USPS public relations representative. “This effort includes replacing all existing firewalls with the latest technology at all mail processing facilities by 2017, which surpasses the OIG’s recommendation.”




