Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Microsoft Gives Users Choice, When It Has To | Main | How to Respond to a Data Breach »

Do As I Say, Not As I Do: Homeland Security Coming Up Short on Info Security

The Department of Homeland Security is getting hammered for poor security. While specific incidents make for headlines and stinging questions by investigators, it’s the more systemic problems we should focus on.

Take for example a question from the chairman of the House of Representatives Homeland Security Committee reported in CNET News:

"How can we ask the private sector to better train employees and implement more consistent access controls when DHS allows employees to send classified e-mails over unclassified networks and contractors to attach unapproved laptops to the network?" Thompson asked at a hearing held by a subcommittee that deals with cybersecurity issues.

Sounds pretty bad and is good fodder for headlines. But what was the outcome of the contracts attaching unauthorized laptops to the network? Obviously the unauthorized device was detected. Did the user gain access to any network resources, was the device logically isolated and physically removed shortly after detection? The answers to these questions matter but they are just the tip of the proverbial iceberg.

The real issue is how DHS implements security management. How well do they manage security policies, enforce procedures, monitor network activity, manage identities and access controls, implement change management, and patch applications? These kinds of questions don’t grab headlines but they make all the difference in effective security.

Here are some comments that should worry us (again from CNET News):

Government Accountability Office auditors at Wednesday's hearing said various components of Homeland Security still aren't doing enough to limit access to their systems, authenticate and identify users, encrypt sensitive data and keep logs of user activity.

And the US-Visit program, which is used to verify the identity of foreigners, suffers from easily fixed problems:

The flaws are mostly due to "bad configurations" that could be fixed both easily and cheaply, he said. But because of the deficiencies, there's no way of knowing whether the database associated with the computer systems has already been hacked, he said.

And the cherry on top, from Keith Rhodes, one of the authors of a GAO report on DHS information security.

"I did not see controls in place that would prevent (hacking), I did not see defensive perimeters, and I did not see detections systems in place that would let you know whether it had or had not" been hacked.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/336

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net