Federal agencies face obstacles in implementing FISMA

News
Oct 4, 20073 mins

Four U.S. agencies — the departments of Homeland Security, Justice, Defense and State — are apparently still having trouble complying with some of the requirements of the Federal Information Security Management Act (FISMA) of 2002, according to the U.S. Government Accountability Office (GAO).

Four years since federal agencies began reporting on their progress in implementing the requirements of FISMA, several are still struggling to meet all of the requirements for a variety of reasons, according to the GAO.

In a report dated Aug. 31, the GAO found, for instance, that the Department of Defense has been particularly challenged in trying to develop a complete inventory of major systems. The problem there has to do with the different definitions the department uses for what constitutes a “system,” the GAO report said.

Meanwhile, the Department of Homeland Security’s (DHS) FISMA problems center on security training issues: The tool DHS uses to report security training activities only counts each course taken by an employee — not whether an individual has taken any required, specialized courses.

Each of the four agencies also had trouble demonstrating that it had controls in place for monitoring and evaluating the effectiveness of its own security controls.

“The challenges in implementing these requirements arose from various weaknesses, including inadequate tools and gaps or inconsistencies in guidance,” the GAO noted. “Until the departments address their challenges and fully implement effective department-wide information security programs, increased risk exists that they will not be able to effectively protect the confidentiality, integrity and availability of their information and information systems.”

The report was based on an investigation of the challenges each of the departments faced in complying with FISMA. Federal agencies governed by the requirement are required to implement a specific set of information security controls and processes for protecting confidential data. They include the need for an inventory of all major systems, common security configurations, training measures, testing and evaluating controls and form security certification processes.

Each agency’s Inspector General is required to provide the White House Office of Management and Budget (OMB) with an annual FISMA progress report detailing the steps the department has taken to implement the required controls.

The GAO report appeared to draw a mixed response from each of the departments studied.

In a formal response to the findings, a Defense Department assistant secretary refused to accept the GAO’s recommendation that the Defense Department implement a department-wide definition for what constitutes a major system. The agency argued that it already had such a definition in place and would continue to use that definition. The department also refused to concur with the GAO’s assessment of its overall FISMA compliance.

Similarly, State department officials challenged the GAO’s characterization that its issues have hindered FISMA implementation. Rather than being obstacles, the issues mentioned in the FISMA report have already been identified as weaknesses that the agency is addressing, the State Department said in a response.

jvijayan

Jaikumar Vijayan is a freelance technology writer specializing in computer security and privacy topics. He writes for CSO Online, Dark Reading and Security Boulevard, among other outlets. He has also written for eWEEK, InformationWeek, TechTarget, Security Intelligence, Government Computer News, Datamation, and Information Security Magazine.

Jai was previously as senior editor at Computerworld, where he covered information security topics targeted at an enterprise IT audience. In addition to breaking news stories, he wrote features and analysis based on commentary and interviews with technical experts, security executives and other IT leaders. While at Computerworld, he won several awards for excellence in technology journalism.

Prior to Computerworld, Jai covered technology issues for The Economic Times in Bangalore, India. He has a Master's degree in Statistics and lives in Naperville, Ill.

More from this author