Federal security incidents shoot up 650 percent

Share this article:
Federal agencies have, over the past five years, experienced a 650 percent increase in malware infections and other security incidents, according to a report from the U.S. Government Accountability Office (GAO).

Agencies reported a total of 41,776 incidents in 2010 – such as virus and worm outbreaks, unauthorized access ,and denial-of-service – compared to just 5,503 in 2006, according to the report, released Monday.

Further, GAO audits have uncovered governmentwide weaknesses in information security controls that are putting data and systems at an increased risk. Assessments conducted during 2010 revealed that all 24 major federal agencies had deficiencies related to access controls, as well as configuration and security management.

“Weakness in [agencies'] information security policies and practices compromised their efforts to protect against threats,” the report said.

The GAO has made hundreds of recommendations to agencies in 2010 and 2011 to address these problems, and while some progress has been made, most suggestions have not been fully implemented, according to the report.

The Internal Revenue Service (IRS), for example, has not sufficiently restricted employee access to databases, or remediated many other previously reported security issues.

“As a result, financial and taxpayer information remain unnecessarily vulnerable to insider threats and at increased risk of unauthorized disclosure, modification or destruction,” the report states.

And the IRS isn't alone.

In its report, the GAO also called out the Federal Deposit Insurance Corp. and the National Archives and Records Administration. Further, none of the 24 agencies have fully implemented an agencywide information security program, as required by the Federal Information Security Management Act (FISMA).

Despite the grim report card, the GAO noted that some progress has been made. The White House Office of Management and Budget (OMB), which is required by FISMA to develop and oversee agency implementation of information security, has launched a new online tool, called CyberScope, an application that went online in 2009, and is used to securely and efficiently report security-related information and provide analysis.

Additionally, the OMB developed new metrics meant to encourage agencies to focus on risk and improve information security.

Share this article:

Sign up to our newsletters

More in News

Brazilian president signs internet 'Bill of Rights' into law

Brazilian president signs internet 'Bill of Rights' into ...

President Dilma Rousseff signed the legislation on Wednesday at the NetMundial conference in Sao Paulo.

Android trojan sends premium SMS messages, targets U.S. users for first time

Android trojan sends premium SMS messages, targets U.S. ...

An SMS trojan for Android, known as FakeInst, has been observed sending premium SMS messages to users all over the world, including, for the first time, the United States.

Report: DDoS up in Q4 2013, vulnerability scanners leveraged to exploit sites

Report: DDoS up in Q4 2013, vulnerability scanners ...

Researchers observed 346 DDoS attacks in the final quarter of 2013 and attackers used Vega and Skipfish vulnerability scanners to exploit web flaws at financial companies.