Search FCW


Subscribe Now!
Table of Contents
Sprint
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Training and Certification
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
researchstore
resourcecenter
Communications for Continuity Operations

Oracle Resource Center
NEW - Data Center Virtualization
NEW - Air Force ELSG Contract Guide
NEW - Security Management
NEW - DOD and Security Guide
Networx Contract Guide
SEWP IV Contract Guide
Priority Report: Virtualization
NEW - CHESS formerly ASCP
New - SATCOM II

More >>



Latest News
ADVERTISEMENT





 

Agencies hit security mark

By Mary Mosquera
Published on June 27, 2008

Comment

Click here to comment on this article


Related story links

Agencies push ahead on security efforts

Security pieces come together

GAO: Common desktop configuration holds promise for better security


Newsletters

You might also be interested in these FCW newsletters:

Daily
Management

To learn more, click here.


The June 30 deadline is approaching for Trusted Internet Connections (TIC) and the Federal Desktop Core Configuration (FDCC) has arrived, and now agencies are preparing to move past the starting line.

Under TIC, agencies consolidated and reduced the number of external connections to the Internet and began to monitor the traffic passing through the remaining nodes, said Mike Smith, program manager of the Information System Security Line of Business at the Homeland Security Department’s National Cyber Security Directorate.

Agencies now await decisions by the Office of Management and Budget on plans they submitted for further gateway reductions. The plans also include agencies’ assessments of whether they can do that work themselves or need another agency or a contractor to provide the services. OMB’s target is to have only 100 Internet connections governmentwide. OMB’s preliminary estimates indicate that the agencies’ plans would reduce the number to 235, Smith said. There were more than 4,300 gateways before TIC.

“We’re actively in the process of developing implementation plans regardless of who is designated as what. We still have to go through this process of understanding how we’re going to implement TIC,” Smith said at a June 25 cybersecurity conference sponsored by the Digital Government Institute.

Tom Kellermann, vice president of security awareness at Core Security Technologies, said TIC and other OMB initiatives are tremendous leaps forward toward a defense-in-depth strategy, but TIC access providers should undergo regular penetration testing to identify weak points. 

“Closing ports to limit access and to increase intrusion detection is significant, but the access providers still provide a weak link in the chain of security, and their security assurance should be regularly vetted,” he said.

The National Institute of Standards and Technology has released updated security settings for agencies to adopt when they update PCs to Windows XP and Vista operating systems under FDCC. NIST made the changes in the settings in response to public comments and analysis of agency reports on their experiences implementing the settings. The settings provide a standard desktop view so agencies can make security improvements, such as virus patches, faster and more effectively.


upcoming event

Enterprise Architecture 2008 - Washington, DC
September 9 - September 10, 2008

Occupational Health & Safety Executive Summit - Arlington, VA
October 6 - October 7, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email