Feds more confident about network security, survey finds

News
Nov 13, 20063 mins

That's because they're spending more time on it, Cisco-commissioned study says.

Federal IT officials are spending more time on security issues than in the past, which is causing them to be more confident about the security of their networks. That’s the key finding of a second annual survey on network security commissioned by Cisco.

Federal IT officials are spending more time on security issues than in the past, which is causing them to be more confident about the security of their networks. That’s the key finding of a second annual survey on network security commissioned by Cisco.

More than half of the survey respondents said they feel more secure with their agencies’ security than they did two years ago. While 58% said they feel more secure than they did in 2004, 30% said they feel about the same and 12% said they feel less secure.

Mandatory security requirements are eating up more time for federal IT officials. Sixty-three percent of the survey respondents said they are spending more time dealing with security requirements than they did last year.

Nonetheless, network security still keeps federal IT officials up at night. What worries them most is the idea of reduced operations and service delivery due to security breaches. Another concern is loss of privacy with employee data or citizen data.

“The most interesting change this year over last year is that there is more management attention being paid to security in both the business and IT side of the agency,’’ says Dan Kent, director of systems engineering for Cisco’s federal organization. “Twenty-five percent of the people surveyed are spending more than 50% of their time on security and compliance issues. That’s why they are feeling more secure about their infrastructures.’’

Survey respondents report ongoing challenges to improving network security. More than half of the survey respondents cited funding, existing architectures and the lack of standards as significant barriers to improving network security. Other security threats cited were remote access for mobile workers and inadequately trained users.

One reason for the growing confidence about network security is that top management is taking the issue seriously. Two-thirds of survey respondents said a permanent CISO had been named or was in the process of being named at their agencies.

A key driver for agency action on network security is the Federal Information Systems Management Act of 2002, known as FISMA. FISMA mandates yearly audits of computer and network security, and federal agencies are focused on achieving FISMA compliance and getting top marks on their FISMA report cards.

The main challenges for meeting FISMA compliance were management and staff issues and funding, survey respondents said.

“FISMA is no longer a policy check box or an event,’’ Kent says. “It’s becoming part of their operations.’’

Federal agencies use a mix of internal staff and outside contractors to develop and implement security solutions. Eighty percent of survey respondents said they use internal resources, while 59% said they use outside consultants and 50% said they use systems integrators.

Market Connections conducted telephone interviews of 200 defense and civilian agency IT decision makers for this survey.