- NYT’s David Brooks: Obama has ‘manhood problem’ in Middle East
- Ted Cruz thanks Obama for denying visas to terrorists
- Survivors recall chaos, fear in Everest avalanche
- General Mills apologizes for ‘right to sue’ confusion, reverses policy
- Dealer wanted in U.S. for art fraud nabbed in Spain
- Easter morning delivery for space station
- Boxer Rubin ‘Hurricane’ Carter dies at 76
- Probe could complicate Rick Perry’s prospects
- Ukraine, Russia trade blame for eastern shootout
- Obamas head to church on Easter morning
While advising the public on cybersecurity, FCC failed on its own defenses
When the Federal Communication Commission’s computer systems were breached in Sept. 2011, it decided to take action to improve cybersecurity.
But more than a year and $10 million later, investigators found the agency is back at square one. In fact,fcc.pdf”> the security improvements the FCC had taken were largely useless, according to a report by the Government Accountability Office, Congress‘ watchdog arm.
“FCC’s information remained at unnecessary risk of inadvertent or deliberate misuse, improper disclosure, or destruction. Further, addressing these deficiencies could require costly and time consuming rework,” the report said.
The FCC is the agency that regulates broadcasts from radio to television to satellite. If Beyonce had a “wardrobe malfunction” on Sunday like the Janet Jackson Super Bowl halftime show several years ago, the FCC is in charge of handing out fines to the television networks and stations in charge of the program.
It also has taken a high-profile role in cybersecurity, creating a special office to communicate threats and solutions to the public and offering small businesses advice on how to repel attacks.
Hacking attempts on government computers are up 780 percent over the past six years, according to GAO. So when FCC security was breached, the agency started the Enhanced Secured Network (ESN) project to protect it’s computers, and the White House Office of Management and Budget authorized it to spend $10 million on the improvements.
Investigators, however, found that little had been improved, mostly because FCC officials weren’t sure what they needed in cybersecurity improvements.
Officials at the broadcast regulator agency didn’t get control of the project from the start, investigators said, including developing a poor cost estimate, project schedule and risk assessment.
The report noted this was unusual for FCC, which usually does a much better job testing and integrating new security improvements.
But without a clear idea of what they needed, FCC personnel hadn’t fine-tuned the security upgrades to get the best protection, GAO said. A program to combat malicious software was installed but never fully used to help fend off attacks. Databases with stored passwords weren’t always encrypted well enough.
As a result, the agency “limited the effectiveness of its security enhancements and did not sufficiently protect the initial deployments from the security threats that the project is intended to mitigate.”
David Robbins, the Managing Director of FCC, said the agency would try to improve some of the mistakes noted in the GAO report, but said the security improvements have largely been successful. The investigation, he said, came at a time when the agency was trying to hurriedly make corrections, and since then improvements have been made.
“The FCC’s overall network security is in a better place now as a result of the ESN project,” Robbins said. “We look forward to sharing our further progress with Congress and the GAO at a later time, when these security initiatives are more fully deployed and developed.”
TWT Video Picks
Women losing coverage under Obamacare, too
- Scalia to students on high taxes: At a certain point, 'perhaps you should revolt'
- Former Ranger breaks silence on Pat Tillman death: I may have killed him
- Special Forces' suicide rates hit record levels casualties of 'hard combat'
- Feds approve powdered alcohol; 'Palcohol' available later this year
- Army goes to war with National Guard, seizes Apache attack helicopters
- U.S. Navy to turn seawater into jet fuel
- Rep. Debbie Wasserman Schultz: Vulnerable Democrats must 'run their own race'
- Harry Reid blasts Bundy ranch supporters as 'domestic terrorists'
- NYT's David Brooks: Obama has 'manhood problem' in Middle East
- CHARLES: Holder's undermining of the law deserving of contempt
Top 10 handguns in the U.S.