The government watchdog evaluated the agencies on five control areas: access controls; configuration management controls; segregation of duties; contingency planning; and agencywide security management. It aimed to ensure agencies met the requirements under the Federal Information Security Management Act of 2002, which was amended by the Federal Information Security Modernization Act of 2014.
All 24 agencies had weak access controls, or “the policies and practices that limit or detect access to computer resources,” and security management, or “the policies, processes, and practices that provide a framework for ensuring that risks are understood and that effective controls are selected, implemented and operating as intended,” as defined by the report.
“GAO and [inspector generals] have made hundreds of recommendations to address these security control deficiencies, but many have not yet been fully implemented,” the report reads. “Until an evaluative component is incorporated into the implementation of the maturity model, the Office of Management and Budget will not have reasonable assurance that agency information security programs have been consistently evaluated.”
Click here to read the full GAO report.
More articles on cybersecurity:
Survey: 3 common ransomware infection vectors
Connecticut legislation classifying ransomware as a felony effective Oct. 1
SEC hack exposed personal data of 2 people
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.