A Republican lawmaker in the US Congress has issued his annual “report card” on computer security within government agencies. His finding: A majority flunked, and the remainders — including agencies critical to America’s homeland defense — barely receive passing grades.
Stephen Horn, a five-term California congressman, has graded agencies on several information technology management topics over the years. His most recent report card rates 24 federal agencies and awarding “Fs” to 16 of them.
“It is a disappointing feeling to announce that the executive branch of the federal government has received a failing grade for its computer security efforts,” says Horn, outgoing chairman of the House Government Reform Committee’s Government Efficiency, Financial Management and Intergovernmental Relations Subcommittee.
Last year, Horn gave the government an overall grade of D-minus, with seven agencies getting F grades. Horn and other officials attribute the worsening grades to a more thorough investigation into IT security.
In 1991, Horn collected information using a questionnaire developed by his staff. This year, however, he based his grades on the first comprehensive evaluations of agencies’ security programs mandated under the Government Information Security Reform Act (GISRA). Agency chief information officers and inspectors general submitted those reports last September to the Office of Management and Budget (OMB).
After realizing that assessing their systems was becoming increasingly important, agencies conducted other security reviews, resulting in a greater awareness of security vulnerabilities, says Robert Dacey, director of information security issues at the General Accounting Office.
“Not surprisingly, this has led to the identification of additional areas of weakness at some agencies,” Dacey says.
With creation of the US Office of Homeland Security and a cyberspace security adviser, “it is important that federal information security be guided by a comprehensive strategy for improvement” with detailed plans and the resources to back them up, Dacey says.
The Information Technology Association of America, a Washington-based trade group, says Horn’s latest security grades are “unacceptable,” and is calling for more funding. “It’s important to recognize this challenge, but it is also equally important to put in place the investment to address it,” says Shannon Kellogg, ITAA’s vice-president of information security programs.
“The reality is that the CIOs [computer information officers] in all these agencies are expected to take money for security out of hide.”
However, US President George W. Bush is reluctant to spend more on IT security, citing a recent OMB report that sees no significant relationship between the percentage of IT spending on security and the soundness of the security at an agency. “The more IT systems that agencies and inspectors general review, the more security weaknesses they are likely to find,” explains Mark Forman, the report’s author, who serves as associate director of IT and e-government at OMB.
Forman says that his own analysis “reveals that while progress has been made, there remain significant weaknesses.” One problem, says Forman, is that “many agencies are not adequately prioritizing their IT investments.” They ask for money to develop new systems but have largely failed to improve the security of those they already operate.
Forman estimates that agencies will spend at least $2.7 billion on security in fiscal 2002 — and they must learn to spend it more wisely, Forman adds. “We don’t believe that simply adding more money will solve the problem,” says Forman.
The Bush administration also says it is dissatisfied with security data it is supplied in GISRA reports, and is now asking government agencies to provide more details on internal efforts to strengthen IT security.
“This is the best set of information we’ve gotten so far, [but] we want more,” Forman says. “When we get into the details, I think we’re going to find a mixed bag, and that’s where we need to go in the next year.”
OMB is now asking federal agencies to reallocate money to conduct more in-depth assessments, especially for a program called Project Matrix.
The Critical Infrastructure Assurance Office developed the Matrix program to identify agencies’ critical assets, prioritize them from the most to the least critical and determine how co-dependent they are on one another. Several agencies have completed the assessment. OMB has directed other government agencies to reallocate fiscal 2002 funds for Matrix reviews.
Once the reviews are completed, OMB will identify several government-wide activities and lines of business for additional Matrix reviews to create a horizontal view of the government’s vulnerabilities, Forman says. For fiscal 2003, says Forman, OMB will continue to follow the policy set by former President Bill Clinton that denies funding to any IT program that fails to include funds for information security.
OMB will also use the GISRA reports and budget meetings with agencies “to determine whether OMB must take steps to assist agencies in quickly correcting their most serious weaknesses,” says Forman.
Send questions and comments to: [email protected]
— Arab News Features 6 February 2003

