News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Network Security
Average Rating:
Rate this article:  
FBI Network Still Not So Secure, Says GAO FBI Network Still Not So Secure, Says GAO
By Frederick Lane
May 26, 2007 9:37AM

    Bookmark and Share
The GAO report about FBI network security illustrates that the FBI "underestimates the insider risk," according to Congressman James Sensenbrenner, who also said that the FBI is "ignoring the sad lessons of the past." Sensenbrenner wants "to see the FBI Director hold someone accountable for this indifference to network security," while the report outlines specific security flaws to be fixed.
 

Advertisement

A report issued by the U.S. Government Accountability Office (GAO) at the end of last month strongly criticizes the efforts by the Federal Bureau of Investigation (FBI) to protect "the confidentiality, integrity, and availability of law enforcement and investigative information" on its new Trilogy data Relevant Products/Services network.

The GAO listed seven specific flaws in the FBI's handling of data and maintenance of its new network, and concluded that, "Taken collectively, these weaknesses place sensitive information transmitted on the network at increased risk of unauthorized disclosure or modification, and could result in a disruption of service."

John Miller, the FBI's Assistant Director for Public Affairs, said that, "The majority of issues and recommendations brought up in the GAO report have been previously identified by the FBI through our own audits and internal controls. The report omitted the fact that the FBI already has corrective action plans in place that proactively and aggressively address information security Relevant Products/Services issues."

Dean Hall, the FBI's Deputy CIO, and Charles Fred Newberry, Jr., Section Chief for the Information Assurance Division, responded to the report and agreed with many of the GAO's technical recommendations. "However," they said, "the FBI takes exception with the GAO's conclusion that the collective result of the information security weaknesses identified by the GAO present an increased risk to FBI information. The FBI does not agree that it has placed sensitive information at an unacceptable risk for unauthorized disclosure, modification, or insider threat exploitation."

'Sad Lessons of the Past'

The GAO investigation was commissioned by U.S. Representative James Sensenbrenner (R-Ohio) when he was serving as chair of the House Judiciary Committee during the last Congress. In a press release, Rep. Sensenbrenner noted that similar problems were identified in 2001, and called on FBI Director Robert S. Mueller, III, to hold someone accountable for the network flaws.

"This report illustrates that the FBI underestimates the insider risk," said Sensenbrenner.

"This baffles me," he said, "given the incredible damage former FBI agent Robert Hanssen inflicted on the FBI's worldwide intelligence network, primarily because he knew exactly how to extract information from the system. Now the FBI has installed two-thirds of the Trilogy system at a cost approaching half a billion dollars, and, once again, it is ignoring the sad lessons of the past."

Not Just the FBI

Largely overlooked in the media coverage of the GAO report is the grim fact that the government oversight agency has been warning of similar problems for a full decade. "We have designated information security as a government-wide, high-risk area since 1997," the GAO report said, "a designation that remains today."

In December 2002, partially in response to those warnings, Congress passed the Federal Information Security Management Act (FISMA), which requires every federal agency to improve its information security. The FBI response to FISMA was the Information Technology Upgrade Project, which later became known as Trilogy.

The GAO report raises serious questions about whether the half-billion spent on Trilogy has been effectively allocated.
 

Advertisement


Advertisement


 Network Security
1.   Peer-to-Peer Software Ban Sought
2.   Los Alamos Computer Security Weak
3.   Security Firm Fortinet Plans IPO
4.   Heartland Restraining Order Denied
5.   Social-Networking Security a Concern


advertisement
Social-Networking Security a ConcernSocial-Networking Security a Concern
Facebook hijacking shows dangers.
Average Rating:
ICANN Approves International NamesICANN Approves International Names
Dramatic increase in users expected.
Average Rating:
Center Opens To Battle CybercrimeCenter Opens To Battle Cybercrime
Increasing threat from hackers seen.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware

  Go Green with IBM Blade Center
  

Network Security Spotlight
House Lawmakers Push Ban on Peer-to-Peer Software
Stung by an embarrassing electronic leak revealing ethics investigations into dozens of lawmakers, Congress moved to prohibit federal employees from using the file-sharing software blamed for the disclosure.
 
GAO: Los Alamos Computer Security Has Weaknesses
Security weaknesses uncovered in Los Alamos National Laboratory's computer network increase the risk of a classified-information breach, says the Government Accountability Office.
 
Computer Security Firm Fortinet Plans IPO This Week
Fortinet plans to go public in an initial public offering, giving investors a chance to tap a network security provider with sales that are expected to grow. The IPO could be valued at $137.5 million or more.
 

Enterprise Technology Spotlight
Flat Shipments Hurt Dell Despite Increased Earnings
Dell's earnings are up and expectations are solid, but the company's stock still took a hit after analysts signaled the company isn't playing a key role in the PC market recovery.
 
Smartphones: A Bigger Target for Security Threats
Smartphones are increasingly prevalent and adept at handling more tasks, including trading stocks, paying bills, and buying stuff online. That makes them attractive to thieves and hackers.
 
FBI Says Hackers Targeting Law Firms, PR Companies
Hackers are targeting law firms and public relations companies with a sophisticated e-mail scheme that breaks into their computer networks to steal sensitive data, often linked to large corporate clients.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2009 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.