ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Become a ZDNet.co.uk member

Tom Espiner

View blog's RSS Feed

Security Bullet In

Communiques from the security front, sir

Friday 25 May 2007, 3:58 PM

FBI network security slammed

Posted by Tom Espiner

The FBI has been given a dressing down by the US Government Accountability Office (GAO) over its network security.

In a report entitled "FBI Needs to Address Weaknesses in Critical Network", the GAO said that the FBI was not doing enough to guard its law enforcement data from insider threats.

The GAO had this to say about the spooks' security systems:

"Certain information security controls over the critical internal network reviewed were ineffective in protecting the confidentiality, integrity, and availability of information and information resources.

Specifically, FBI did not consistently
(1) configure network devices and services to prevent unauthorized insider access and ensure system integrity;
(2) identify and authenticate users to prevent unauthorized access;
(3) enforce the principle of least privilege to ensure that authorized access was necessary and appropriate;
(4) apply strong encryption techniques to protect sensitive data on its networks;
(5) log, audit, or monitor security-related events;
(6) protect the physical security of its network; and
(7) patch key servers and workstations in a timely manner.
Taken collectively, these weaknesses place sensitive information transmitted on the network at risk of unauthorized disclosure or modification, and could result in a disruption of service, increasing the bureau’s vulnerability to insider threats."

In a press release, responding to the GAO criticisms, John Miller, FBI assistant director for public affairs, admitted that the dressing down was valid, but said the FBI was already taking action on it:

"The majority of the issues and recommendations brought up in the GAO report have been previously identified by the FBI through our own audits and internal controls. The report omitted the fact that the FBI already has corrective action plans in place that proactively and aggressively address information security issues," said Miller.

Considering the number of attacks against governmental systems by hackers and by other governments, I wonder how much information has been compromised?


Comments on this post

Tom Espiner
  • Tom Espiner
  • London, UK
  • Member since: October 2006
ZDNet Staff

Contacts

Number of Contacts: 1

Contacts' Latest Discussions

Number of Tracked Discussions: 381

roger andre roger andre

Beware Of Sneaky Services

Sunday 6 July 2008, 1:27 AM

7 comments
roger andre roger andre

Beware Of Sneaky Services

Thursday 3 July 2008, 7:18 PM

7 comments
roger andre roger andre

facebook lockdown

Thursday 3 July 2008, 1:47 PM

3 comments
roger andre roger andre

Beware Of Sneaky Services

Thursday 3 July 2008, 1:38 PM

7 comments

Contacts' Latest Blogs

Number of Contacts Blogs: 1