Accurate, Focused Research on Law, Technology and Knowledge Discovery Since 2002

DOE IG – The Department's Unclassified Cyber Security Program – 2011

DOE IG Evaluation Report – The Department’s Unclassified Cyber Security Program – 2011, DOE/IG-0856 October 2011

  • “The Department had taken steps over the past year to address previously identified cyber security weaknesses and enhance its unclassified cyber security program. While these were positive steps, additional action is needed to further strengthen the Department’s unclassified cyber security program and help address threats to its information and systems. For example, our FY 2011 evaluation disclosed that corrective actions had been completed for only 11 of the 35 cyber security weaknesses identified in our FY 2010 review. In addition, we identified numerous weaknesses in the areas of access controls, vulnerability management, web application integrity, contingency planning, change control management, and cyber security training. While many of the same or similar issues had been noted in prior FISMA reports, the number of weaknesses identified represented a 60 percent increase over our FY 2010 review.”
  • Sorry, comments are closed for this post.