Government watchdog: Feds fail to implement vast majority of cybersecurity recommendations
Full article624 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The Government Accountability Office says there's an urgent need for an updated national cybersecurity to hold federal agencies accountable.
The Government Accountability Office said Thursday that U.S. federal departments have implemented just 40% of the cybersecurity recommendations the watchdog agency has issued since 2010.
The lethargic pace in which government agencies put in place cybersecurity precautions and best practices underlines the need for the Biden administration to “urgently” release a comprehensive national cybersecurity strategy with effective oversight, the GAO said in its report.
The GAO said that the updated national cybersecurity strategy, which the administration is reportedly planning to release soon, should address key “desirable characteristics of national strategies” such as performance measures that was missing in President Trump’s 2018 cybersecurity strategy.
“We stressed that moving forward, the incoming administration needed to either update the existing strategy and plan or develop a new comprehensive strategy that addresses those characteristics,” the report noted.
The GAO noted that only about 145 of its 335 recommendations have been put in place. The agency recommended such actions establishing the national cyber director and the General Service Administration updating their security plans.
The report is the first in a four-part series the GAO plans to release reviewing gaps in the federal government’s approach to cybersecurity policy. One area of concern that the agency pointed out involved supply chain management. It noted that no federal agency has fully implemented its supply chain guidance.
The Office of Management and Budget and the Department of Homeland Security, meanwhile, have only partially addressed recommendations to solve the cybersecurity workforce shortage, according to the report. While both agencies have addressed some aspects such as training employees to fill vacant positions and streamlining the hiring process, neither have established an implementation team or plan to address workforce shortages.
“Without these practices in place, OMB and DHS will likely be unable to make significant progress towards solving the cybersecurity workforce shortage,” the GAO wrote.
Additionally, the GAO said that while efforts to better secure operational technology and internet-connected devices are underway, the Departments of Energy, Health and Human Services and DHS have not effectively established performance metrics for these initiatives.
The forthcoming Biden cybersecurity plan is expected to call for new cybersecurity mandates that could impose cybersecurity regulations on critical infrastructure organizations. After a spree of high-profile attacks such as the Colonial Pipeline ransomware attack, policymakers have called for an end of voluntary recommendations for the vital industries.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/government-watchdog-cybersecurity-recommendations/