FedCFO Search Engine

@FedCFO Twitter Feed

Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Monday, July 21, 2014

Treasury Dept IT System Flagged for Security Issues

Serious tech troubles at the Treasury Department are so severe that they could disrupt accounting practices within a system that manages about $16.7 billion of federal debt.

The Government Accountability Office flagged at least 20 problems within the Bureau of the Fiscal Service’s tech system—all of which involve security management issues. Of the deficiencies GAO identified, 14 are brand new and six are problems that were detected in 2012 and were never corrected.
The auditors said the issues constitute a "significant deficiency" for financial reporting purposes. 

The weaknesses "increase the risk of unauthorized access, modification or disclosure of sensitive data and programs, which could result in the disruption of critical operations," Gary Engel, GAO director for financial management and assurance, wrote in an audit last week, NextGov first reported.
The Fiscal Service commissioner addressed the auditor’s findings and said the agency is currently taking actions to resolve the issues.
-Brianna Ehley, TheFiscalTimes.com
READ MORE...

Friday, May 30, 2014

Outdated DHS Financial Systems May Be Inhibiting Internal IT Controls, OIG Audit Says

In recent years, said a new Department of Homeland Security (DHS) Office of Inspector General (OIG) IT management report for the Fiscal Year 2013 DHS financial statement audit, “DHS’s financial system functionality may be inhibiting the agency’s ability to implement and maintain internal controls, notably IT applications controls supporting financial data processing and reporting at some components.”

“At most components,” OIG report, “the financial systems have not been substantially updated since being inherited from legacy agencies several years ago. Therefore, in FY 2013, we continued to evaluate and consider the impact of financial system functionality over financial reporting.”

In FY 2013, a total of 103 findings were issued, of which approximately 69 percent are repeated from last year.

According to the audit, approximately 35 percent of repeat findings were for IT deficiencies that management represented were corrected during FY 2013. The new findings in FY 2013 resulted both from additional IT systems and business processes within the scope of the audit this year and from control deficiencies identified in areas which were effective in previous years, and were noted at all DHS components.

Customs and Border Protection (CBP) and the Federal Law Enforcement Training Center (FLETC) had the greatest number of new findings.

OIG reported that “many key DHS financial systems are not compliant with the financial management systems requirements of the Federal Financial Management Improvement Act of 1996 and Office of Management and Budget (OMB) Circular Number A-127, Financial Management Systems, revised. DHS financial system functionality limitations add substantially to the department’s challenges of addressing systemic internal control weaknesses and limit the department’s ability to leverage IT systems to effectively and efficiently process and report financial data.”

With respect to DHS and its components’ financial systems’ IT controls, the audit “noted certain matters in the areas of security management, access controls, configuration management, segregation of duties and contingency planning.”

During the audit, “certain matters involving financial reporting internal controls (comments not related to IT) and other operational matters, including certain deficiencies in internal control” were discovered that are considered “to be significant deficiencies and material weaknesses,” and were communicated in writing to management and those charged with governance in KPMG’s Independent Auditors’ Report and in a separate letter to the Office of Inspector General and the DHS Chief Financial Officer.

-Anthony Kimery, HStoday.us
READ MORE...

Tuesday, April 29, 2014

Defense Dept. CIO Teri Takai Resigns

Teri Takai will be leaving her post as the Defense Department's chief information officer next month.
Takai submitted her resignation to Secretary of Defense Chuck Hagel, effective May 3, a DoD spokesperson confirmed Monday. A replacement hasn't yet been named.
Takai has served as the DoD's CIO since November 2010. While in that position, she was the principal advisor to Secretary Hagel for information management, information technology, and information assurance. She also oversaw non-intelligence space systems, critical satellite communications, navigation, and timing programs, as well as spectrum and telecommunications.

-Elena Malykhina, InformationWeek.com
READ MORE...

Friday, April 18, 2014

Federal watchdog says SEC security issues put financial data at risk

A congressional watchdog has tasked the U.S. Securities and Exchange Commission (SEC) with addressing a number of security weaknesses impacting its system.
On Thursday, the U.S. Government Accountability Office (GAO) released a report (PDF) detailing the issues, which included SEC not encrypting sensitive data, properly identifying and authenticating users, or securely configuring a vital financial system, leaving it vulnerable to attack.
According to the 25-page report, “the information security weaknesses existed, in part, because SEC did not effectively oversee and manage the implementation of information security controls during the migration of this key financial system to a new location."
The watchdog said that SEC did not adequately oversee a contractor it hired to migrate its systems to a different data center last June.
As a result of SEC's need to improve security controls, GAO determined that the agency – which regulates the securities market, including exchanges, brokers, dealers and investment firms – had a “significant deficiency in internal control over financial reporting for fiscal year 2013.”
-Danielle Walker, SCmagazine.com
READ MORE...

Thursday, October 13, 2011

OMB outlines expanded roles for federal CIOs

The White House budget director, Jack Lew, directed agency leaders to ensure their chief information officers are responsible for "true portfolio management for all IT [information technology]" and not "just policymaking."

In a new memo, Lew outlined four areas where CIOs should have a lead role:
  • Governance of agencies' IT portfolios.
  • Commodity IT purchases, such as data centers, desktops, email and business systems.
  • Management of large IT projects and programs.
  • Information security programs.

-Nicole Blake Johnson, FederalTimes.com
READ MORE...

Monday, September 26, 2011

Programmer, procurement staff failings contribute to software attacks

When hackers take advantage of a software flaw in a federal financial system to steal credit card numbers, procurement officers and program developers are both to blame for the intrusion, some information security specialists say.

Vulnerabilities stem from the inadequate training of software engineers, as well as inadequate requirements from acquisition officers. In the old days, when software operated in an isolated system, developers thought threats would be limited to that computer's physical area. In today's networked world, however, software is operating in environments that the developer may not have had in mind when building a program.

-Aliya Sternstein, NextGov.com
READ MORE...