The State of Federal IT Security

David Wagner, Managing Editor | 3/13/2012 | 4 comments

David Wagner
Yesterday, the United States Office of E-Government and Information Technology released the FY 11 Report to Congress on the Implementation of the Federal Information Security Management Act of 2002 (FISMA). The report, which essentially outlines all the major efforts, progress, and ongoing threats regarding IT security in the entire US government, not only serves to inform Congress of the current state of federal cybersecurity, but it helps enterprises get a handle on what they should be thinking about in terms of security as well.

For those who depend one way or another on the US government, you’ll be gratified to know that significant progress was made from FY 2010 to FY 2011. Improvements have been made in the use of mobile encryption, secure connections, tracking the status of assets, and credentialing. However, the report states that “because of the relentless dynamic threat environment, emerging technologies, and new vulnerabilities,” the defense posture must always be shifting. Currently, the government is concentrating on three major priorities -- continuous monitoring, Trusted Internet Connection (TIC), and HSPD-12 implementation for access control.

Of the three, continuous monitoring is the one most likely to already be implemented in the enterprise. The continuous automated monitoring of assets is relatively new to the federal government: Only 17 percent of departments could do so in 2010, but that number rose significantly, to 75 percent, in 2011. The National Institute of Standards and Technology (NIST) is in the midst of working out guidelines for continuous monitoring. Three documents it is circulating for public comment can be found here.

The situational awareness that comes from automated monitoring can quicken response times to threats, reveal unknown threats, and allow you to track larger patterns of events and threats. In the case of the government, data is not only reported at the department level but to an automated feed called Cyberscope, which compiles the data across departments, allowing the government to see whether persistent threats exist across multiples parts of the government.

Another issue that the federal government wanted to work on was consolidating the number of external telecommunications connections to the federal government. It did this by creating Trusted Internet Connection Access Portals (TICAP). Each TICAP includes firewalls, malware protection, and network security, and a total of 51 security requirements. Through this initiative, the government was able to consolidate external connections by 85 percent and make sure more of its traffic was going through secured connections.

The final issue is the safe credentialing required by Homeland Security Presidential Directive 12 (HSPD-12). This requires the use of PIV cards that have two-factor authentication (usually a smart card and a PIN). Eighty-nine percent of government employees have now been issued the cards, but strangely enough, only 66 percent (up from 55 percent in 2010) are actually required to use them. Two-factor authentication is significantly safer than single-factor authentication and could be used just as easily in the enterprise. The relatively small progress in the use of the cards is a major hurdle that both the federal government and an enterprise will encounter, and it mostly has to do with user resistance to the perceived inconvenience of two-factor authentication.

Another HSPD-12 requirement has been more of a success. Portable device encryption is now up to 89 percent from 54 percent in FY 2010. In 2011, the list of devices was extended to include every major enterprise mobile device including laptops, smartphones, and even USB devices. The obvious goal is 100 percent, and that's very doable. Total encryption is also a reachable goal in the enterprise. Portable devices are the number-one source of lost data in the government and the enterprise. Encryption would significantly lower that percentage. Fortunately, some departments in the government including the Treasury and the State Department have 100 percent encryption. Sadly, the Department of Defense is still lagging at 84 percent.

Of course, not everything in your enterprise is going to require protecting it with two-factor authentication, encryption, and special connection portals. However, nearly every enterprise, just like the government, needs to protect sensitive data. The savvy CIO will read this article (and the report) for pointers on what he should be doing to protect his company's most sensitive data. The best-practices in security are being created right now by Homeland Security.

View Comments: Newest First | Oldest First | Threaded View
David Wagner   The State of Federal IT Security   3/14/2012 3:40:30 PM
Re: Answer to cyber wars
@waqasaltaf- Definitely. I'm sure other governments do use this as a benchmark. The interesting thing about that is that many governments really don't have the kind of data to protect that even a large enterprise has. I'm thinking of small island nations that live mostly off tourism and such.

I wouldn't think most enterprises or small countries would need to think about adopting everything here, but it makes a nice place to start thinking about what you really do need.
David Wagner   The State of Federal IT Security   3/14/2012 3:37:13 PM
Re: Task force
@Damian Romano- I can't find anyone willing to go on record, but I've heard from It folks in the government that a great percentage of the problem was the Bush administration. Despite the fact that his adminstration passed FISMA in 2002, there wasn;t much progress until the Obama administration took over.

i'm sure every administration thinks the previous one was backward, but accoridng to people I know, the state of IT in the federal government in 2008 was barbaric. They've spent these years catching up.
WaqasAltaf   The State of Federal IT Security   3/14/2012 11:18:00 AM
Answer to cyber wars
In today's scenario where cyber-gorilla wars have started between governments with conflicting motives and where hackers are being supported by intelligence agencies, security of government access points through internet has become of utmost importance. While the US government makes its security developments as a benchmark for CIOs, I think it also serves as a good example if not a benchmark for other governments esp those that have not yet realized the importance of security of their information assets.  
Damian Romano   The State of Federal IT Security   3/14/2012 8:03:49 AM
Task force
I'm kind of surprised to read some of the percentages with respect to requirements in 2010. Good to see the numbers rising in 2011, but with as many threats out there as there are you'd think the one place that would have a greater (if not the greatest) level of protection is the US Gov't. I suppose even the government faces the issue of deployment as we find in many enterprises.


The blogs and comments posted on EnterpriseEfficiency.com do not reflect the views of TechWeb, EnterpriseEfficiency.com, or its sponsors. EnterpriseEfficiency.com, TechWeb, and its sponsors do not assume responsibility for any comments, claims, or opinions made by authors and bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.

More Blogs from David Wagner
David Wagner   5/17/2013   15 comments
Geeks have come a long way in society recently. Seems like everyone is watching Game of Thrones, or one of 20 sexy vampire shows, or the newest Star Trek reboot that used to be all for us ...
David Wagner   5/16/2013   4 comments
One of the more compelling events at this year's Blackberry Live was an intimate conversation between Blackberry CEO, Thorsten Heins, and Nick Fry, former CEO of the Mercedes AMG Petronas ...
David Wagner   5/15/2013   6 comments
Earlier today at the Blackberry Live conference, Linda Campbell, Blackberry's Director for Strategic Alliances, laid out her vision for the future of M2M. It is a vision where machines not ...
David Wagner   5/10/2013   25 comments
Do you remember when this was considered the clothing of the future?
David Wagner   5/9/2013   4 comments
New research by Behnam Tabrizi published in Harvard Business Review demonstrates an increased need for IT to empower middle-level managers (MLMs) to effectively promote change and innovation.
Latest Archived Broadcast
Data visualization can make complex data easier to grasp. Our expert guest will talk about the hows, whys, and whats of bringing the big picture to your enterprise.
May 28th 2pm EDT Tuesday
On-demand Video with Chat
NBA CIO Michael Gliedman will tell us why the NBA decided to create NBA.com/stats
6/18/2013 -   Please join us for the "IT Convergence Strategies: Why, When and How " to learn more about: • 5 truths about infrastructure convergence today that go beyond the hype • How to exploit the 4 phases of convergence maximum efficiency and agility • Key milestones to plan for on the convergence journey • Why integrated management is a critical component of convergence plans • The importance of an open, modular approach, such as Dell’s active infrastructure, to building a converged data center
E2 IT Migration Zones
IT Migration Zone - UK
Office 365 Finds Fans
Cutting Through the Modern App Confusion
Microsoft Hints at Changes to Windows 8
IT Migration Zone - FR
S’équiper ou non d’un logiciel anti-virus ?
Microsoft passe au facteur deux
Windows Azure Infrastructure Services est disponible !
IT Migration Zone - DE
Microsofts Surface Pro kommt nach Deutschland
Zum Schmunzeln: drei neue Werbeclips für Windows 8
Like Us on Facebook
Twitter Feed
Enterprise Efficiency Twitter Feed
Dell IT Insights
Dell Market Response Twitter Feed
E2 Linked-in Group Ad
Site Moderators Wanted
Enterprise Efficiency is looking for engaged readers to moderate the message boards on this site. Engage in high-IQ conversations with IT industry leaders; earn kudos and perks. Interested? E-mail:
moderators@enterpriseefficiency.com
Dell's Efficiency Modeling Tool
The major problem facing the CIO is how to measure the effectiveness of the IT department. Learn how Dell’s Efficiency Modeling Tool gives the CIO two clear, powerful numbers: Efficiency Quotient and Impact Quotient. These numbers can be transforma¬tive not only to the department, but to the entire enterprise.

Read the full report
The State of Enterprise Efficiency in the Virtual Era: Virtualization – Smart Approaches to Maximize Gains
Virtualization is a presence in nearly all enterprise data centers. But not all companies are using it to its best effect. Learn the common characteristics of success, what barriers companies face, and how to get the most from your efforts.

Read the full report
Informed CIO: Dollars & Sense: Virtual Desktop Infrastructure
Cut through the VDI hype and get the full picture -- including ROI and the impact on your Data Center -- to make an informed decision about your virtual desktop infrastructure deployments.

Read the full report
SPONSORED BY DELL
BRIEFINGS
CASE STUDIES
EBOOKS
PUBLIC SECTOR RESOURCES
VIDEOS
WHITE PAPERS
A Video Case Study – Translational Genomics Research Institute
e2 Video
On the Case
TGen IT: Where We're Going Next

7|11|12   |   08:12   |   10 comments


Now that TGen has broken new ground in genomic research by using Dell's storage, cloud, and high-performance computing solutions, the company discusses what will come next for it and for personalized medicine.
On the Case
Better Care Through Better Communications

6|6|12   |   02:24   |   12 comments


The achievements of the TGen/Dell project could improve how all people receive healthcare, because they are creating ways to improve end-to-end communication of medical data.
On the Case
TGen IT: Where We Are Now

5|15|12   |   06:58   |   5 comments


TGen is breaking new ground in genomic research by using Dell's storage, cloud, and high-performance computing solutions.
On the Case
TGen IT: Where We Were

4|27|12   |   06:45   |   10 comments


The Translational Genomics Research Institute wanted to save lives, but its efforts were hobbled by immense computing challenges related to collecting, processing, sharing, and storing enormous amounts of data.
On the Case
1,200% Faster

4|18|12   |   02:27   |   12 comments


Through their partnership, Dell and TGen have increased the speed of TGen’s medical research by 1,200 percent.
On the Case
IT May Improve Children's Chances of Survival

4|17|12   |   02:12   |   8 comments


IT is helping medical researchers reach breakthroughs in a way and pace never seen before.
On the Case
Medical Advances in the Cloud

4|10|12   |   1:25   |   5 comments


TGen and Dell are pushing the boundaries of computing, and harnessing the power of the cloud to improve healthcare.
On the Case
TGen: Living the Mission

4|9|12   |   2:25   |   3 comments


TGen's CIO puts the organizational mission at the heart of everything the IT staff does.
On the Case
TGen Speeding Up Biomedical Research to Save More Lives

4|5|12   |   1:59   |   8 comments


The Translational Genomics Research Institute is revamping its computing to improve speed, storage, and collaboration – and, most importantly, to save lives.
On the Case
Computing Power Helping to Save Children's Lives

3|28|12   |   2:13   |   3 comments


The Translational Genomics Institute’s partnership with Dell is enabling them to treat kids with neuroblastoma more quickly and save more lives.
Ivan Schneider
Clash of the Tableau 8: Release the Kraken!

5|17|13   |   2:42   |   No comments


Tableau 8 has some great data visualization and presentation capabilities, but it's best paired with a strong data analysis framework.
Tom Nolle
Using Virtualization – for Real!

5|13|13   |   2:10   |   No comments


There's a lot of hype about virtualization of networks, NaaS, and SDN, but there's a couple of proven applications that enterprises could adopt right now and potentially save money and improve operations.
Tom Nolle
Is UC Becoming Oxymoronic or Just Moronic?

5|9|13   |   2:12   |   No comments


Skype/Outlook UC integration means we're going to have competition and fragmentation of UC client architectures, but is that bad? Modern devices can support IM, email, voice, and video clients, so maybe it's the back end of UC we need to be worried about.
E2 Editors
Windows vs. Integrated Circuit CPUs

4|17|13   |   4:45   |   5 comments


The editors make their predictions about what will win the next match-up in the E2 Tournament of IT Revolutionaries.
E2 Editors
Radio vs. Public Internet Access

4|17|13   |   4:34   |   14 comments


The editors make their predictions about what will win the next match-up in the E2 Tournament of IT Revolutionaries.
E2 Editors
Mainframes vs. Servers

4|17|13   |   4:34   |   16 comments


The editors make their predictions about what will win the next match-up in the E2 Tournament of IT Revolutionaries.
E2 Editors
TCP/IP vs. Printing Press

4|17|13   |   3:07   |   5 comments


The editors make their predictions about what will win the next match-up in the E2 Tournament of IT Revolutionaries.
E2 Editors
BYOD vs. E-Commerce

4|12|13   |   3:12   |   11 comments


The editors make their predictions about what will win the next match-up in the E2 Tournament of IT Revolutionaries.
E2 Editors
Telecommuting vs. Outsourcing

4|12|13   |   4:19   |   7 comments


The editors make their predictions about what will win the next match-up in the E2 Tournament of IT Revolutionaries.
E2 Editors
Personal Computer vs. Mobile Devices

4|12|13   |   4:28   |   20 comments


The editors make their predictions about what will win the next match-up in the E2 Tournament of IT Revolutionaries.
E2 Editors
Smartphones vs. Productivity Software

4|12|13   |   3:09   |   13 comments


The editors make their predictions about what will win the next match-up in the E2 Tournament of IT Revolutionaries.
Tom Nolle
There's More to Mobility Than the Mobile Worker

4|9|13   |   2:03   |   5 comments


Workers are now used to portable device support throughout their everyday lives. We should be looking at the policy of providing fixed-desk devices to support stationary workers. Could portable support be smarter?
Ivan Schneider
From Kim Jong-Un's Trackball to Nuance Voice Ads

4|5|13   |   3:21   |   9 comments


Input devices run the gamut, from the humble Missile Command-style trackball to advanced speech recognition. Unfortunately, these input devices can be used for evil as well as good. Case in point: mobile ads that want you to talk to them.
Tom Nolle
Data/Storage Wish List for Enterprises

4|3|13   |   2:19   |   1 comment


Enterprises want three things in storage systems: First is some speech-recognition way of capturing videoconference data for indexing; second is semantic/AI analysis of emails and IM for content indexing; third is a better system for managing hierarchical layers of storage.
E2 Editors
E2 Editors Go Mad! Episode 3

3|28|13   |   3:22   |   12 comments


March Madness: Susan and Curt face off in a battle over Microsoft Excel, and whether or not it deserved its own spot on the E2 Tournament of IT Revolutionaries.