OMB eyes new metrics for security at federal agencies

News
Jul 21, 20094 mins

Current metrics are too focused on compliance, federal CIO says

The White House Office of Management and Budget is looking for better ways to measure the readiness of government agencies to fend off cyberthreats, according to federal CIO Vivek Kundra.

The White House Office of Management and Budget (OMB) is exploring new ways to measure the readiness of government agencies to deal with cyberthreats, according to federal CIO Vivek Kundra.

The new metrics are necessary because the ones currently in use focus largely on agency compliance with the Federal Information Security Act (FISMA), Kundra said in a letter to Gregory Wilshusen, director of the Government Accountability Office (GAO). As such they are “trailing, rather than leading indicators” of cybersecurity readiness. “We need metrics that give insight into agencies’ security postures and possible vulnerabilities on an ongoing basis.”

Kundra’s letter was in response to an assessment of government-wide information security readiness done by the GAO. The 66-page GAO report — along with Kundra’s response — was released last week. It highlights “persistent weaknesses” in the information security controls deployed by the government agencies covered by FISMA, including inadequate access and configuration management controls, improper segregation of administrative duties and inadequate business continuity planning.

The GAO noted that in fiscal year 2008, 20 of the 24 major agencies covered under FISMA reported that their security controls represented either a ‘significant’ or a ‘material’ weakness. The same weaknesses were identified in similar reports released by the GAO in July 2007 and June 2005.

Although the agencies have made some progress in dealing with security issues, the GAO pointed out that many critical security vulnerabilities remain unaddressed. “Weaknesses in information security controls continue to threaten the confidentiality, integrity, and availability of the sensitive data maintained by federal agencies,” Wilshusen wrote in his report. These weaknesses leave federal agencies and data “vulnerable to external as well as internal threats.”

Wilshusen noted several security incidents in 2008 and early in 2009, including a security breach at the Federal Aviation Administration that exposed confidential data on 45,000 employees; another involving hackers based in China breaking into a U.S. Senator’s computers; and one involving the leak of sensitive information about the president’s Marine One helicopter. Agencies will remain exposed to threats unless they implement “the hundreds of recommendations” the GAO and its inspector general have been making, the report said.

The GAO report also raised issues with OMB’s annual reporting instructions to agencies, calling them unclear and insufficient. It criticized the OMB for not including enough information about the security vulnerabilities at federal agencies in its annual report to Congress and for failing to “approve” or “disapprove” agency information security programs.

In his response, Kundra said that the White House is working with CIOs and chief information security officers to develop better ways of measuring the effectiveness of government agency security programs. He called the current reporting process cumbersome and said the OMB is working on Web-enabling FISMA reporting procedures. He pushed back at Wilshusen’s assessment that the OMB was not adequately reviewing agency FISMA reports and insisted that such reviews are being done.

Critics have been calling for an overhaul of FISMA reporting procedures for some time. FISMA, which emerged in the aftermath of the Sept. 11, 2001 terrorist attacks, requires agencies to develop processes for testing their security controls and contingency plans, and mandates that they adopt standard system configurations, set incident response and breach disclosure policies, and implement programs for security training and for system accreditation and certification.

Though it was initially seen as a much-needed way of bolstering security, there has been growing concern that many agencies now see the FISMA process as little more than a paperwork exercise yielding few improvements. Rather than requiring agencies to actually show that their security controls work, FISMA simply requires them to show that they have deployed security measure.

jvijayan

Jaikumar Vijayan is a freelance technology writer specializing in computer security and privacy topics. He writes for CSO Online, Dark Reading and Security Boulevard, among other outlets. He has also written for eWEEK, InformationWeek, TechTarget, Security Intelligence, Government Computer News, Datamation, and Information Security Magazine.

Jai was previously as senior editor at Computerworld, where he covered information security topics targeted at an enterprise IT audience. In addition to breaking news stories, he wrote features and analysis based on commentary and interviews with technical experts, security executives and other IT leaders. While at Computerworld, he won several awards for excellence in technology journalism.

Prior to Computerworld, Jai covered technology issues for The Economic Times in Bangalore, India. He has a Master's degree in Statistics and lives in Naperville, Ill.

More from this author