From: Federal Times
By NICOLE BLAKE JOHNSON
Federal agencies are struggling to secure their information systems despite shelling out $14.6 billion on cybersecurity in fiscal 2012, according to an annual report released Monday.
The annual Federal Information Security Management Act report (PDF) details agencies’ progress in securing their systems from cyber attacks and other security risks, as well as efforts to meet administrative cybersecurity goals.
According to the report, the largest federal agencies spent 90 percent of their IT security costs on personnel, about 5 percent on cybersecurity tools, 3 percent on developing risk-based security programs and about 1 percent each on testing IT security and training personnel, according to the report. That’s an overall increase from the total $13.3 billion agencies spent on cybersecurity in fiscal 2011.
“While a number of agencies are clearly on the right path, more steps need to be taken to enhance the overall federal government’s information security management,” Sen. Tom Carper, D-Del., said in a statement.
“Federal agencies need to fully implement meaningful security programs that can withstand the serious cyber challenges we face today and will face for the foreseeable future,” he said.
Some agencies, such as the Office of Personnel Management, have improved their ability to automate security checks of their networks, detect vulnerabilities through agency-sponsored security or penetration testing and ensure network traffic is routed through secure Internet connections. But a number of agencies, including the Veterans Affairs Department, are failing to encrypt emails and detect and block unauthorized software from uploading and crippling their networks and systems, the report found.
Leave a Reply