Search FCW


Subscribe Now!
Table of Contents
Sprint
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
researchstore
resourcecenter
Sprint Communications for Continuity of Operations
Oracle Resource Center
NEW! SEWP IV Contract Guide
NEW! Priority Report: Virtualization
GSA: Your Customer Service Agency
Government Leadership Survey
Green Solutions Guide
Report: Information Sharing
DISA IT Strategy & Vision
Emergency Preparedness Report
Report: Green Computing
PEO EIS Guidebook
Content Library

More >>



Latest News
ADVERTISEMENT





 

OMB, DHS take various steps to secure networks

By Jason Miller
Published on October 23, 2007

Comment

Click here to comment on this article


Related story links

DHS offers baseline for U.S. IT security skills

OMB: Vista is an opportunity to set desktop standards

OMB, DHS outline data security best practices

OMB wants desktop standard written into contracts


Newsletters

You might also be interested in these FCW newsletters:

Daily
Management
Policy and Procurement
Security

To learn more, click here.


WILLIAMSBURG, Va. — Agencies report on average about 30 incidents a day in which an employee has lost personally identifiable information. And despite a constant barrage of memos from the Office of Management and Budget in the past 15 months detailing steps agencies should take to secure personal information, the number of data breaches will continue to rise, federal and private-sector experts say.

“Cybercrime is big business,” said Greg Garcia, the Homeland Security Department’s assistant secretary for cybersecurity and communications. “Some estimate that it is a $100 billion industry with botnets, phishing scams, adware and spyware attacks.”

Consequently, DHS and OMB are promoting a series of programs to try to close vulnerabilities and minimize the impact of the attacks.

Karen Evans, OMB’s administrator for e-government and information technology, said the government’s move to a standard desktop configuration for Microsoft Windows and the requirement of vendors’ products to run on the baseline without changing it will make a huge difference.

“We will have one standard configuration for the entire government — one means one,” Evans said at the 17th annual Executive Leadership Conference, sponsored by the Industry Advisory Council. “Every agency needs to have a governance process to test and make changes so applications don’t break.”

Evans said vendors must test their software against the virtual standard desktop the National Institute of Standards and Technology is providing.

“Agencies will not buy your products if it changes the standard desktop configuration settings,” Evans said. “We believe this will increase the security posture of agencies and they will not have to redo it for each application.”

The desktop standard also will help agencies move toward situational awareness where they can do real-time discovery and monitoring.

“That is the next area the Security Line of Business will address,” Evans said.

She said agencies have until February 2008 to install the standard desktop configuration. After that, OMB will take statistical samples of agencies to see which met the mandate. Evans also said they will ask agency inspectors general to evaluate agency progress.

“We will work with the [CIO] Council to put mechanisms in place to look at the statistical sample and see where agencies need help,” she said.


upcoming event

Enterprise Architecture 2008 - Washington, DC
September 9 - September 10, 2008

Occupational Health & Safety Executive Summit - Arlington, VA
October 6 - October 7, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email