State's systems are vulnerable
GAO: How State can improve security Provide a central management point and continuing processes to coordinate security measures. Write risk assessment procedures. Write comprehensive security policies. Increase user awareness about security. Monitor the effectiveness of security policies and controls.
GAO:
How State can
improve security
| Provide a central management point and continuing processes to coordinate security measures. | |
| Write risk assessment procedures. | |
| Write comprehensive security policies. | |
| Increase user awareness about security. | |
| Monitor the effectiveness of security policies and controls. The State Departments unclassified automated information systems can easily fall Our penetration tests revealed that States sensitive but unclassified GAO auditors did not only gain access to sensitive information, but they could also The penetration test revealed that hackers, both inside and outside of State, could A State Department spokesman, speaking on condition of anonymity, acknowledged that We believe we have corrected some of the problems in the report, and were He did not specify which problems had been corrected. State received both classified and unclassified versions of the GAO report and State officials also agreed to formalize and document risk management decisions, revise Although State has some projects under way to improve security, it does not have During the penetration tests, GAO auditors accessed States networks with dial-up The GAO auditors also said States internal network controls were inadequate. For Finally, the audit showed that the buildings access was easy because employee Auditors entered many State buildings and facilities without required passwords, the During a tour of one facility, auditors found an unattended computer logged onto a LAN. In an unlocked area, auditors found an unattended PC and gained supervisor-level access Although GAO gave the department adequate grades for its Internet security, the office The report faulted top management for not supporting the creation of a sound security Currently, States top managers are not demonstrating the commitment |




