ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

US Homeland Security CIO blamed for IT woes

Anne Broache CNET News.com

Published: 21 Jun 2007 10:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

In response to reports of persistent cybersecurity flaws at the US Department of Homeland Security, a top congressional Democrat on Wednesday questioned whether the agency's chief information officer deserves to keep his job.

The department charged with safeguarding the security of US computer systems has not been setting a good example and chief information officer Scott Charbo hasn't shown he's serious about fixing its vulnerabilities, said Bennie Thompson, chairman of the House of Representatives Homeland Security Committee.

"How can we ask the private sector to better train employees and implement more consistent access controls when DHS [the Department of Homeland Security] allows employees to send classified emails over unclassified networks and contractors to attach unapproved laptops to the network?" Thompson asked at an afternoon hearing held by a subcommittee that deals with cybersecurity issues.

He was referring to the Homeland Security department's revelation, as part of an ongoing subcommittee probe into its information-security practices, that it experienced 844 security-related "incidents" on its computer systems in 2005 and 2006. Those episodes included unauthorised users hooking up personal computers to government networks, unauthorised software installations, classified emails travelling over unclassified networks, suspicious botnet activity, Trojans and virus infections, classified data spillages and misconfigured firewalls.

Charbo, for his part, downplayed the lengthy list, saying that they didn't indicate actual penetrations of the system and varied widely in the level of severity. "Those are events that we report on as a data-gathering tool," the IT chief told the politicians, adding that he was confident all breaches considered significant had been addressed properly.

The congressional panel that convened Wednesday's hearing has been probing the extent to which various federal agencies are equipped to handle cyberthreats. At a hearing in April, committee members accused officials at the Commerce and State Departments of being ill-prepared to handle such threats in light of reports of intrusions from Chinese hackers, and they warned that Homeland Security would be undergoing scrutiny next.

Criticism of that department's cybersecurity efforts from Congress and federal auditors is hardly new. Some would argue the department has shown minor signs of improvement this year since it pulled up its federal information security "grade" from an "F" to a "D".

Competition

Blogger at Large competition
Blogger at Large

The deadline's fast approaching on our contest to win a trip to San Francisco and a Centrino Pro laptop to blog from the Intel Developer Forum. To enter, just start posting entries to our On the Road group blog.

Read more +

Even so, Government Accountability Office (GAO) auditors at Wednesday's hearing said various components of Homeland Security still aren't doing enough to limit access to their systems, authenticate and identify users, encrypt sensitive data and keep logs of user activity.

The GAO is preparing to release a report based on a year-long investigation that it says documents "pervasive" security flaws in Homeland Security's US-Visit program, which is designed to verify the identity of foreigners through fingerprint scans and is currently being used at several US ports of entry.

Keith Rhodes, one of the report's authors, said the GAO found that US-Visit is riddled with problems "across the board", which, left uncorrected, could put sensitive personal information at risk. The flaws are mostly due to "bad configurations" that could be fixed both easily and cheaply, he said. But because of the deficiencies, there's no way of knowing whether the database associated with the computer systems has already been hacked, he said.

"I did not see controls in place that would prevent [hacking], I did not see defensive perimeters, and I did not see detections systems in place that would let you know whether it had or had not" been hacked, Rhodes told the committee.

Charbo said he and department officials were still reviewing the draft version of that report but were prepared to address the weaknesses by the year's end.

On a broader level, Charbo said he realises the agency has improvements to make but urged the politicians not to overlook what he called "significant progress" during the past few years. For instance, it has "remediated" 7,000 weaknesses identified by auditors and has certified that 95 percent of its systems have appropriate controls in place — compared with only 26 percent in October 2005.

Others questioned whether the department has been dedicating enough of its overall technology budget to security. According to Homeland Security, it spent $12.5m (£6.2m) in 2004, $17.5m (£8.7m) in 2005, and $15m (£7.5m) in 2006 and 2007. Charbo justified those expenditures by saying they reflected "our strategic security plan".

The lone Republican present at the hearing, subcommittee co-chairman Michael McCaul, said he and others were considering introducing legislation that would force Homeland Security to come up with a "national strategic threat assessment" regarding US cybersecurity.

"This has never been done, it's long overdue, and the nation needs this to protect it," he said, adding that he feared a devastating cyberattack could be worse than the "effects of a weapon of mass destruction".

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Operations Manager (Technical pre-sales team)/ IT Manager- Abingdon, Oxfordshire

Interface Management and SLAs: Manage broad internal interfaces with other divisions (sales, implementations, network development, strategic projects ...

Information Security Manager

For more information about TUI Travel PLC, please visit www.tuitravelplc.com Information Security Manager Providing expert advice to system design ...

Associate Director of Business Intelligence

Informatics experience - Board level experience - Comfortable in Board level interactions - NHS Board level experience For more information or to ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment