Government Accountability Office Report Slams FBI Internal Security


Ah, FBI slammed again, it’s not the first time this has happened.

Remember when a Consultant Breached FBI’s Computers?

It also reminds me of when Homeland Security Scored an F for Internal Security AGAIN

The Government Accountability Office, the federal government’s watchdog agency, Thursday released a report critical of the FBI’s internal network, asserting it lacks security controls adequate to thwart an insider attack.

In the report, titled “Information Security: FBI Needs to Address Weaknesses in Critical Network,” the authors — Gregory Wilshusen, GAO’s director of information security issues, and Chief Technologist Keith Rhodes — said the FBI lacks adequate network security controls.

The FBI “has an incomplete security plan,” the report concluded.

Those who are supposed to protect eh?

The bureau, which had the opportunity to review the GAO’s findings before publication, responded that it wasn’t arguing with some of the technical observations expressed in the GAO report, but disagreed that the FBI is open to unacceptable risk of an insider attack.

In a letter of response to the GAO, Dean Hall, the FBI’s deputy CIO, and Zalmal Azni, the FBI’s CIO, noted, “The FBI concurs with many of the GAO’s technical recommendations and the programmatic recommendation to continue the implementation of information security activities in order to fully establish a comprehensive Information Assurance Program.”

Let’s hope they can make less excuses and just sort it out.

Source: PC World

Posted in: Hacking News

,


Latest Posts:


tko-subs - Detect & Takeover Subdomains With Dead DNS Records tko-subs – Detect & Takeover Subdomains With Dead DNS Records
tko-subs is a tool that helps you to detect & takeover subdomains with dead DNS records, this could be dangling CNAMEs point to hosting services and more.
Arcane - Tool To Backdoor iOS Packages (iPhone ARM) Arcane – Tool To Backdoor iOS Packages (iPhone ARM)
Arcane is a simple script tool to backdoor iOS packages (iPhone ARM) and create the necessary resources for APT repositories.
SharpHose - Asynchronous Password Spraying Tool SharpHose – Asynchronous Password Spraying Tool
SharpHose is an asynchronous password spraying tool in C# for Windows environments that takes into consideration fine-grained password policies and can be run over Cobalt Strike's execute-assembly.
Axiom - Pen-Testing Server For Collecting Bug Bounties Axiom – Pen-Testing Server For Collecting Bug Bounties
Project Axiom is a set of utilities for managing a small dynamic infrastructure setup for bug bounty, basically a pen-testing server out of the box with 1-line.
Quasar RAT - Windows Remote Administration Tool Quasar RAT – Windows Remote Administration Tool
Quasar is a fast and light-weight Windows remote administration tool coded in C#. Used for user support through day-to-day administrative work to monitoring.
Pingcastle - Active Directory Security Assessment Tool Pingcastle – Active Directory Security Assessment Tool
PingCastle is a Active Directory Security Assessment Tool designed to quickly assess the Active Directory security level based on a risk and maturity framework.


3 Responses to Government Accountability Office Report Slams FBI Internal Security

  1. Alfred Farrington June 21, 2007 at 1:35 am #

    Hmmm seems like they are spending alot of money and still can’t get it right. Seems like our same good ol government.

  2. Bogwitch June 21, 2007 at 2:00 pm #

    The article paints an all-too-familiar story – IT and security departments taking the blame for a lack of funding.
    I have no doubt that agencies like the FBI rely too heavily on staff vetting which, unfortunately, is not completely reliable. Just because someone has passed a background check, does not always mean they are trustworthy….
    However, the biggest problem is convincing any organisation that investment in information security is worthwhile. It is very difficult to convince organisations to perceive that there is a return on investment let alone to attempt to calculate that return.
    Until this happens, IT departments and information security departments will always take the blame for poor security management.

  3. Sandeep Nain July 11, 2007 at 1:56 am #

    Well i am sure their budget does have a huge amount sanctioned for IT Security.. and that money must have been shown used too…

    is it just me who is thinking that… management over their is just assuming that their infrastructure is secure and putting the money in their bank accounts instead…

    sounds like corruption to me and not just the IT (in)security