Four U.S. agencies — the departments of Homeland Security, Justice, Defense and State — are apparently still having trouble complying with some of the requirements of the Federal Information Security Management Act (FISMA) of 2002, according to the U.S. Government Accountability Office (GAO).
Four years since federal agencies began reporting on their progress in implementing the requirements of FISMA, several are still struggling to meet all of the requirements for a variety of reasons, according to the GAO.
In a report dated Aug. 31, the GAO found, for instance, that the Department of Defense has been particularly challenged in trying to develop a complete inventory of major systems. The problem there has to do with the different definitions the department uses for what constitutes a “system,” the GAO report said.
Meanwhile, the Department of Homeland Security’s (DHS) FISMA problems center on security training issues: The tool DHS uses to report security training activities only counts each course taken by an employee — not whether an individual has taken any required, specialized courses.
Each of the four agencies also had trouble demonstrating that it had controls in place for monitoring and evaluating the effectiveness of its own security controls.
“The challenges in implementing these requirements arose from various weaknesses, including inadequate tools and gaps or inconsistencies in guidance,” the GAO noted. “Until the departments address their challenges and fully implement effective department-wide information security programs, increased risk exists that they will not be able to effectively protect the confidentiality, integrity and availability of their information and information systems.”
The report was based on an investigation of the challenges each of the departments faced in complying with FISMA. Federal agencies governed by the requirement are required to implement a specific set of information security controls and processes for protecting confidential data. They include the need for an inventory of all major systems, common security configurations, training measures, testing and evaluating controls and form security certification processes.
Each agency’s Inspector General is required to provide the White House Office of Management and Budget (OMB) with an annual FISMA progress report detailing the steps the department has taken to implement the required controls.
The GAO report appeared to draw a mixed response from each of the departments studied.
In a formal response to the findings, a Defense Department assistant secretary refused to accept the GAO’s recommendation that the Defense Department implement a department-wide definition for what constitutes a major system. The agency argued that it already had such a definition in place and would continue to use that definition. The department also refused to concur with the GAO’s assessment of its overall FISMA compliance.
Similarly, State department officials challenged the GAO’s characterization that its issues have hindered FISMA implementation. Rather than being obstacles, the issues mentioned in the FISMA report have already been identified as weaknesses that the agency is addressing, the State Department said in a response.




