Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Report: VA's IT security still needs work

The gold standard, as promised? Not so much yet
 

Sign up to receive Security Resource Alerts

September 19, 2007 (Computerworld) -- The U.S. Department of Veterans Affairs has made some progress since a May 2006 data breach, but it has not completed 20 of 22 recommendations from an internal auditor, according to a report released Wednesday.

As of May, the VA had not yet addressed several "critical success factors" for transforming its IT management, the U.S. Government Accountability Office said in its report. The VA had only completed two of 22 recommendations from its inspector general following the breach, in which a laptop and hard drive containing personal records of 26.5 million veterans and family members were stolen from a VA employee's home.

The VA also needs to improve its IT asset control, the GAO said, referencing a July report showing about 2,400 missing IT devices at four VA locations in 2005 and 2006. While the VA has "many significant initiatives under way," problems persist, even in the programs meant to fix past problems, the GAO report said.

"We continue to see management weaknesses in these programs and initiatives, which are the very weaknesses that VA aims to alleviate," the GAO report said.

The VA has not completed a comprehensive security management program, recommended by the GAO, and it has not strengthened its critical infrastructure planning process, which was recommended by its inspector general, the GAO said.

In addition, the VA has worked with the U.S. Department of Defense for 10 years to share electronic medical records, but the two agencies are "far" from completing that work, the GAO said.

Robert Howard, the VA's assistant secretary for information and technology since last September, largely agreed with the GAO report while testifying before the Senate Veterans Affairs Committee Wednesday.

"Since the May 2006 data breach, the VA staff is now more aware of the importance of protecting our veterans' and employees' information and identities," Howard said. "While we do have a way to go here, I have definitely seen improvement."

The VA has encrypted more than 18,000 laptops since the breach, and it is rolling out software that blocks unauthorized data storage devices such as thumb drives from connecting to the VA's network, he said. The agency has also installed software that blocks VA employees from sending e-mail containing Social Security numbers, he said.

As the VA was rolling out the e-mail filtering software, the software caught about 7,000 e-mails containing Social Security numbers in just one month, Howard said.

The VA is also in the process of centralizing its long-criticized location-based IT structure, and the agency's goal is to compete the realignment by July, Howard said.

Senator Daniel Akaka, a Hawaii Democrat and committee chairman, noted that VA Secretary of Veterans Affairs Jim Nicholson promised the agency would become a "gold standard" for cybersecurity following the 2006 breach. "How close is VA to becoming the government leader in information security?" Akaka said.

Continued...
1 | 2 | NEXT  



Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"So first there is the Twitter phishing attack, and now an 18-year-old hacker gets into their admin tools and does..." Read more...
Read more Security posts or See all Blogs
Windows 7 public beta to be available Friday
Hack forces Twitter into 'full security review'
10 must-have free BlackBerry apps
More top stories...
Ballmer sets loose Windows 7 public beta
Fake LinkedIn profiles promise prurient pics, send patsies malware instead
Cisco down to business with gear for digital home
The downturn has softened the IT talent market but done little to weaken demand for SAP, .Net and other technical skills.
Every computer user hits a speed bump now and then. Here are some speedy, simple solutions to hardware, software, network, Internet and mobile-device crises.
From the iPhone 3G to 'unibody' MacBooks, 2008 was a standout year for Apple.
We've got reviews and videos of the new Ubuntu 8.10, Fedora 10 and openSUSE 11.1.
Get the latest news, reviews and more about Microsoft's newest desktop operating system
Find wage data for 50 IT job titles.
All Zones
Business Continuity Zone
The File Data Management Zone
Security Management Zone
The SAS Zone
Business Intelligence and Analytics Zone
The Enterprise Search Zone
Software as a Service Zone
The Security Zone

Ads by TechWords

See your link here
Process Automation with Symantec
Process Automation with Symantec
View this new webcast today!
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Creating a green data center to help reduce energy costs and gain a competitive advantage
Download this new white paper today!
(Source: VMware) With today's rapid IT growth, companies are looking to consolidate datacenter operations to achieve space and cost savings. And as energy costs continue to rise, datacenter efficiency becomes even more important. This IBM report details how companies are reducing energy usage and costs to gain a completive advantage.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Extend Your VPN
Smart Security Choices for Mobile Workers
Leverage Web-based Remote Access to Boost Productivity
View more whitepapers 


Webcast: The Automation of IT Compliance Programs: Reducing Risk, Cost and Complexity of Corporate Compliance
To meet the growing number of industry and federal regulations, businesses spend significant time, effort, and budget determining how to best meet continuously evolving IT compliance requirements this new Forrester Research and Juniper Networks Webcast led by industry experts who examine global IT security and compliance trends, common IT compliance issues and challenges, and best practices for successful IT compliance programs.

View this webcast 
Whitepaper: Tackling the Top Five Network Access Control Challenges
The major challenge enterprises face today is how to create innovative business models and to increase productivity by opening the network to a dynamic workforce, while at the same time protecting critical assets from the vulnerabilities that openness and user mobility bring. In addition, to comply with industry and governmental regulations, enterprises must prove that they have stringent controls in place to restrict access to sensitive data. This paper describes the top five networking access control challenges that companies like yours are facing and solutions that they are deploying today.

Download this white paper 
Whitepaper: Addressing PCI Compliance with a Comprehensive Network Access Control Solution
The Payment Card Industry (PCI) is one of the most comprehensive data security standards in a cluster of regulations that have emerged over the past decade. Meeting its requirements is both complicated and expensive for many companies. Learn how a comprehensive access control solution allows retailers and consumer organizations adhere to the core tenets of PCI, and delivering the necessary information and reports needed for compliance audits.
Download this white paper 
Whitepaper: Control System Cyber Vulnerabilities and Mitigation of Risk for Utilities
Today's global industrial infrastructure includes thousands of electric utilities, water/wastewater management companies, oil and gas suppliers, chemical manufacturers and other facilities critical to daily functioning. Learn why relying on off-the-shelf operating systems and Internet-based remote access control to carry out production tasks, traditional control networks can leave today's global industrial infrastructures vulnerable to hackers, extortionists, worms, viruses and application-level attacks. Deploying network-based security can protect these at-risk systems–without requiring infrastructure replacement.
Download this white paper