«

»

Sep
23

Congress to IT security: Happy fiscal New Year

From: GCN

Posted by William Jackson

Priorities for securing government’s IT infrastructure for the coming fiscal year include defending against insider threats posed by unmanaged privileged access and expanded continuous monitoring to address the growing complexity of outsider threats. But these issues could be dwarfed by the challenge of just keeping the lights on come Oct. 1.

“Security is probably the biggest issue we’ve got, because it underlies so much of the other things we are trying to do,” said Paul Christman, public sector vice president at Dell Software. “It can’t go on hiatus.”

Yet the fools on the Hill see the world spinning ’round toward the new budget year without any serious plans for enacting a budget to support critical operations. No doubt essential personnel will remain at their desks in the event of a shutdown, but without updated technology to support them, security will suffer.

“We’re finding it very challenging to assess and predict priorities, because our customers cannot assess and predict their priorities,” Christman said. “Funding has become chaotic and erratic.”

If there is any budget for fiscal 2014, insider threats are likely to be top-of-mind for administrators. A steady drumbeat of stories raises the question of how to manage the physical and logical access given to people agencies have decided to trust. On the IT side, systems administrators and others with privileged accounts often have way too much freedom, putting systems and the information they contain at risk.

The first step in controlling this access is effective policy. Most agencies and offices probably already have a good policy in place, Christman said. But there often are few if any controls to enforce it. Technology must match policy with the ability to monitor, track and audit the activity of those who are given the keys to the kingdom. This has been driven home by the activities of Chelsea (nee Bradley) Manning and Edward Snowden. The National Security Agency, smarting from the Snowden leaks, has responded by reducing the number of systems administrators and instituting a two-man rule requiring separate sets of credentials for access to sensitive resources.

This process would be burdensome and unnecessary for most agencies, which could effectively monitor activity with software. But that requires money, and money requires a budget.

Read Complete Article

Leave a Reply

Please Answer: *