The FBI should avoid prioritizing cyberthreats on the basis of a “gut check” or assess them based on the “loudest person in the room,” according to a report released by the Justice Department’s Office of Inspector General.
The FBI should change its procedures to detect cyberthreats in a more timely way and track whether agents’ efforts are aligned to the most serious priorities, the July 21 report by Justice Department IG Michael Horowitz said.
The FBI does not prioritize cyberthreats in an agile, objective, data-driven, auditable manner, the report said. Threat review and prioritization is done annually which is not often enough for an agile response to identify emerging threats, according to the report.
Read the report here.
In addition, the FBI doesn’t adequately track the time agents spend by threat so it cannot be sure it is aligning cyber resources to its highest priority which the OIG called a “vital capability for a threat-driven organization.”
The FBI agreed with the report’s recommendations to use a data-driven methodology in scoping and prioritizing cyberthreats and to manually update results of the threat-ranking tool at least every 30 days so that emerging threats can be identified and mitigated. It also agreed to develop a record-keeping system to track agent time by threat, the OIG report said.
The audit, which included interviewing 40 FBI officials starting in August 2015, assessed the FBI’s cyberthreat mitigation strategy and focused on how the FBI prioritizes threats. The audit did show the FBI’s Cyber Division has made progress in developing a way to augment the threat review and prioritization process but it’s hampered by written policies about who should enter the data and how it should be used.




