By now it is not surprising when a government security assessment reveals problems. Alberta added themselves to the list with a report of serious lack of security controls and evidence that hackers had already intruded on government networks.
In what sounds like their first ever comprehensive security audit the Auditor-General issued a report that stated they had to curtail an investigation after the first 69 machines they inspected showed major vulnerabilities. They also suffered from the usual instances of passwords taped to keyboards, and loose physical controls on access to their data centers. One step the province took since last May was to hire a single person to oversee security - always a good measure.
Every government network should undergo regular assessments. The goal should be continuous improvement but also immediate slamming of those open doors. Complacency works for the hackers.
Richard Stiennon is a security industry analyst. He is currently consulting, speaking and writing on all manner of security topics for IT-Harvest, the IT research firm he founded to cover the security space. He was most recently chief marketing officer for Fortinet. He has served stints at PricewaterhouseCoopers, Gartner, and Webroot Software.
The opinions expressed in this Weblog are those of the writer and may not represent the opinions of Network World.
|
|
Have to borrow this
Have to borrow this "Complacency works for the hackers." It's so true as we have seen lately but I can tell seeing that a long, long time - like 30+ years in security related issues.
A bad day again(?) but I honestly can't understand what's so difficult? There are opportunistic people in the world who will use any and all means to make money (or to gain power and money)! Then there are "specialists", certified people(?) who are supposed to prevent that - who's winning?
Now - I don't know if the "a single person" is meant to be sarcastic, probably. But one single person knowing what has to be done AND has the authority is all what is needed. Of course, doesn't work today - we need task forces, committees, process, policies, blah, blah.. Really?
Post new comment