All the latest UK technology news, reviews and analysis

US government failing on digital security

by Iain Thomson

30 Jul 2008

Comment: 1

  • Tweet this
White House
An investigation into 24 major federal agencies has uncovered widespread lapses in security

A report by the US Government Accountability Office has found that key federal departments are failing to take data security seriously.

The 15-month investigation into 24 major federal agencies found that around 70 per cent of laptops and handhelds do not use encryption, leaving the data available to anyone.

Since 2007 new rules from the Office of Management and Budget (OMB) require all federal laptops to be encrypted, but these are largely being ignored.

The GAO Report to Congressional Requesters (PDF) warned that many departments had not even begun to identify what data should be encrypted.

"We are recommending that the OMB clarify a government-wide encryption policy to address agency efforts to plan for and implement encryption technologies," said the report.

"We are also making recommendations to selected agencies to properly install and configure FIPS-compliant encryption technologies, to develop policies and procedures to manage encryption, and to provide encryption training to personnel."

The report highlighted some unusually poor practice, including employees at Nasa refusing to put encryption software on their laptops, and members of the Department of Education who were not told that encryption software was installed.

The report makes 20 recommendations to improve the level of data security in government, including large scale education programmes and a generic data encryption policy that can be rolled out across agencies.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Business Readiness/ Change manager

As part of a major implementation of a new inventory...

Information/Data Architect - MDM - SOA

Information/Data Architect - MDM - Master Data Management...

Softwaren Developer - .Net/SQL Server

Code Red Associates (CRA) is a leading supplier of Permanent...

Senior Test Analyst, Quality Assurance, QA, To £47,000 + Benefits

A fantastic opportunity has arisen for an experienced...

To send to more than one email address, simply separate each address with a comma.