Commerce considering managed service to fix cyber weakness

From: 1500AM

By Jason Miller

The Commerce Department wants to fix a glaring cyber weakness. It lacks full centralized enterprisewide cybersecurity reporting capabilities across its 90,000 computers.

The agency issued a request for information Jan. 15 asking vendors to describe capabilities across 11 areas and the cost for a managed cyber service.

The RFI stated the capabilities would “provide department-level situational awareness, a single, common operating picture of security for the department’s systems, remediation and response, and other centralized functions necessary to monitor and manage the department’s cybersecurity posture.”

The Commerce Department’s inspector general reported in November that one of the agency’s top management challenges was to strengthen the security and investments in IT.

“Over the years, we have repeatedly identified significant flaws in basic security measures protecting IT systems and information,” the IG report stated. “We have continually called for greater attention and stronger commitment from the department’s senior management to the basic security practices, which, if properly implemented, can effectively minimize or stop cyberattacks before a serious compromise occurs. In response to our fiscal years 2010 and 2011 recommendations, the department has updated its IT security policy for vulnerability scanning, secure configurations, and management of plans of action and milestones. However, the department needs to enforce these polices because we continue to find similar security weaknesses in departmentwide and bureau systems.”

For example, Commerce’s Economic Development Administration suffered a cyber attack that shut down its network last February.

Read Complete Article


Leave a Reply

Your email address will not be published.

Please Answer: *