On BNET: Turn your iPhone into an air mouse
BNET Business Network:
BNET
TechRepublic
ZDNet

November 20th, 2006

Agencies fail to comply with FISMA

Posted by Richard Koman @ November 20, 2006 @ 10:21 AM

Categories: Government technology, IT Management

Tags: ZDNet Government

Federal agencies are failing to test their IT security controls consistently, a new General Accounting Office report has found, Government Accounting News reports.

“Federal agencies have not adequately designed and effectively implemented policies for periodically testing and evaluating information security controls,” the GAO concluded after surveying 24 major agencies and conducting in-depth case studies on 30 IT systems at six of the agencies.

The report was ordered by Rep. Tom Davis (R-Va.), the original sponsor of FISMA, the Federal Information Security Management Act. Apparently no agencies are compliant with the law, passed in 2002.

"What this shows is that we have a long way to go to ensure Americans the information their government keeps about them is safe," Davis said in a release. "We're going to do this, but it's going to take time."

GAO recommends that OMB instruct agencies to develop and implement policies on periodic testing and evaluation, and revise instructions for future FISMA reporting by inspectors general to include assessments on the quality of agencies’ testing processes.

“We received oral comments on a draft of this report from representatives” at OMB, the GAO reported. “The representatives agreed to consider our recommendations as part of their oversight responsibilities for information security at federal agencies.”

  • Talkback
  • Most Recent of 1 Talkback(s)
U.S. federal agencies do okay  Laura Taylor | 11/22/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here