Why Auditors’ InfoSec Advice Is Ignored

From: GovInfoSecurity.com

Rapid Pace of Change Makes Compliance a Big Challenge

As director of information security issues at the U.S. Government Accountability Office, Gregory Wilshusen dispenses advice to agencies to improve their security – recommendations that aren’t always heeded.

But Wilshusen understands why his advice isn’t always followed, saying several factors make it more difficult for agencies to protect IT.

“Federal IT and communications systems are highly complex and dynamic with multiple technologies, operating systems and networks that are increasingly interconnected to deliver services and conduct operations,” Wilshusen told me in response to questions about agencies complying with IT security audits. “The complexity and rapidity of change in agency IT environments inherently introduce risk as they become more difficult to manage and secure.”

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *