Resources and data at the Department of Energy (DOE) at risk because the agency hasn’t done enough to strengthen its cybersecurity, according to a report (PDF) released last week by Gregory Friedman, the DOE’s inspector general.
Although the DOE has taken steps to strengthen its cybersecurity, Friedman said vulnerabilities continue to expose the department’s critical systems to compromise. Some of those deficiencies are the same ones highlighted in past years, according to the report.
The Federal Information Security Management Act (FISMA) requires the inspector general to conduct an annual independent evaluation of whether the department’s unclassified cybersecurity program adequately protects data and information systems. According to Friedman, the DOE still needs to:
— Complete a department-wide inventory of its information systems;
— Perform necessary systems certifications and accreditations;
— Devise contingency plans to ensure that some of its critical systems can continue or resume operations in the event of an emergency or disaster;
— Shore up existing security weaknesses to prevent unauthorized system modification or the loss or disclosure of information.
According to Friedman, the DOE “did not always implement or properly execute existing departmental and federal cybersecurity requirements. In a number of instances, cybersecurity weaknesses … were not addressed in a timely manner or tracked to resolution. As a consequence, the department’s information systems and networks and the data they contain remain at risk of compromise.”
Even though the department has made progress in dealing with cybersecurity-related problems, the risk that its information systems, networks, and the data they contain may be compromised is higher than necessary, Friedman said. He noted that the department is now implementing a cybersecurity revitalization plan and said that officials must focus on the problems that have been identified if they expect to substantially reduce the risks uncovered so far.
“At the time of our evaluation, the department had been subjected to 132 significant cybersecurity incidents, consisting primarily of attempts to compromise information by unauthorized users, malicious code and worms during FY 2006 — a 22% increase over last year,” Friedman said. “Inadequate protective measures leave valuable information technology resources vulnerable to cyberattacks from internal and external sources and could result in data tampering and disruption of critical operations.”
In a written response to the report, Thomas Pyke, the DOE’s CIO, said his department continues to work on improving its cybersecurity practices.




