Search FCW


Subscribe Now!
Table of Contents
Sprint
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Training and Certification
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
researchstore
resourcecenter
Communications for Continuity Operations

Oracle Resource Center
NEW - Data Center Virtualization
NEW - Air Force ELSG Contract Guide
NEW - Security Management
NEW - DOD and Security Guide
Networx Contract Guide
SEWP IV Contract Guide
Priority Report: Virtualization
NEW - CHESS formerly ASCP
New - SATCOM II

More >>



Latest News
ADVERTISEMENT





 

FEMA still weak on IT security, auditors say

By Alice Lipowicz
Published on August 4, 2008

Comment

Click here to comment on this article


Related story links

The audit report


Newsletters

You might also be interested in these FCW newsletters:

Daily
Management

To learn more, click here.


The Federal Emergency Management Agency is still struggling to secure its information technology systems with 31 weaknesses carried over from previous years and 13 new weaknesses identified in fiscal 2007, according to a new audit report released by Homeland Security Department Inspector General Richard Skinner.

FEMA corrected 10 weaknesses last year, and it developed new policies, processes and procedures to comply with cybersecurity guidelines, states the report on FEMA’s IT issues related to financial controls, written by the KPMG LLP auditing firm.

Overall, FEMA continues to suffer from weak controls on employee and contractor passwords, shortcomings in application service development and service continuity, and a weakness in its systemwide documentation, among other problems, the report states.

“These issues collectively limit FEMA’s ability to ensure that critical financial and operational data is maintained in a manner to ensure confidentiality, integrity and availability,” the report states.

“Consequently, these weaknesses negatively impacted the internal controls over FEMA financial reporting and its operation,” KPMG said. FEMA managers generally agreed with the findings.

Among the problems identified in the report:

  • There are 770 former FEMA and contractor employees with some level of active password privileges.
  • National Flood Insurance Program workstation deactivations are not programmed in compliance with security guidelines.
  • Changes to mainframe applications were documented only about half the time.

  • Excessive access privileges are in place on several applications.
  • FEMA’s Continuity of Operations plan has not been updated to reflect concerns raised by the IT Service Division Continuity of Operations Plan.


upcoming event

Enterprise Architecture 2008 - Washington, DC
September 9 - September 10, 2008

Occupational Health & Safety Executive Summit - Arlington, VA
October 6 - October 7, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email