- Al Sharpton, Trayvon Martin’s parents rally against Fla. ‘stand your ground’ law
- Hillary Clinton campaign got illicit funds from D.C. scandal figure
- Obama administration backs off plan to cut prescription-drug program
- Tickets linked to stolen passports purchased by Iranian middleman
- More than 3,500 police planned for Boston Marathon
- Ottawa day care suspends 2-year-old for ‘outside’ cheese sandwich
- Liam Neeson tells NYC mayor to ‘man up’ in horse carriage fight
- Real-life Dr. Doolittle to reveal how to talk to animals
- Climate change could bring back smallpox, researchers say
- Shoe-bomb witness to speak from London at N.Y. trial
While advising the public on cybersecurity, FCC failed on its own defenses
When the Federal Communication Commission’s computer systems were breached in Sept. 2011, it decided to take action to improve cybersecurity.
But more than a year and $10 million later, investigators found the agency is back at square one. In fact,fcc.pdf”> the security improvements the FCC had taken were largely useless, according to a report by the Government Accountability Office, Congress‘ watchdog arm.
“FCC’s information remained at unnecessary risk of inadvertent or deliberate misuse, improper disclosure, or destruction. Further, addressing these deficiencies could require costly and time consuming rework,” the report said.
The FCC is the agency that regulates broadcasts from radio to television to satellite. If Beyonce had a “wardrobe malfunction” on Sunday like the Janet Jackson Super Bowl halftime show several years ago, the FCC is in charge of handing out fines to the television networks and stations in charge of the program.
It also has taken a high-profile role in cybersecurity, creating a special office to communicate threats and solutions to the public and offering small businesses advice on how to repel attacks.
Hacking attempts on government computers are up 780 percent over the past six years, according to GAO. So when FCC security was breached, the agency started the Enhanced Secured Network (ESN) project to protect it’s computers, and the White House Office of Management and Budget authorized it to spend $10 million on the improvements.
Investigators, however, found that little had been improved, mostly because FCC officials weren’t sure what they needed in cybersecurity improvements.
Officials at the broadcast regulator agency didn’t get control of the project from the start, investigators said, including developing a poor cost estimate, project schedule and risk assessment.
The report noted this was unusual for FCC, which usually does a much better job testing and integrating new security improvements.
But without a clear idea of what they needed, FCC personnel hadn’t fine-tuned the security upgrades to get the best protection, GAO said. A program to combat malicious software was installed but never fully used to help fend off attacks. Databases with stored passwords weren’t always encrypted well enough.
As a result, the agency “limited the effectiveness of its security enhancements and did not sufficiently protect the initial deployments from the security threats that the project is intended to mitigate.”
David Robbins, the Managing Director of FCC, said the agency would try to improve some of the mistakes noted in the GAO report, but said the security improvements have largely been successful. The investigation, he said, came at a time when the agency was trying to hurriedly make corrections, and since then improvements have been made.
“The FCC’s overall network security is in a better place now as a result of the ESN project,” Robbins said. “We look forward to sharing our further progress with Congress and the GAO at a later time, when these security initiatives are more fully deployed and developed.”
TWT Video Picks
By David Keene
Conference showed that the values Reagan cherished still endure
- Hillary Clinton campaign received funds from Jeffrey Thompson
- Kim Jong-un calls for execution of 33 Christians
- Senate Democrats, Republicans spar over restoring unemployment benefits
- Unanimous Senate passes bill on military sex assault to give victims more say in prosecution
- Atheists sue to remove 'Ground Zero Cross' from 9/11 museum
- Mitch McConnell on beating tea party: 'We are going to crush them'
- Bill Clinton poses for photo with Bunny Ranch prostitutes
- Sharyl Attkisson resigns from CBS after months of talks
- George Zimmerman signs autographs at Orlando gun show
- DHS accused of holding U.S. citizen at airport, using emails to pry into her sex life
Pope Francis meets his 'mini-me'
Celebrity deaths in 2014
Winter storm hits states — again