Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Information-Security-News
[Top] [All Lists]

[ISN] IG critical of DOD IT

Subject: [ISN] IG critical of DOD IT
Date: Thu, 12 Jan 2006 03:25:47 -0600 (CST)
http://www.fcw.com/article91937-01-11-06-Web

By Frank Tiboni
Jan. 11, 2006 

The Defense Department poorly tracks information technology security 
and investments, causing the department, the Office of Management and 
Budget and Congress to make uninformed IT budget and policy decisions, 
according to DOD inspector general reports.

The military services and DOD agencies are not consistently reporting 
IT systems security data in two main databases. They include the IT 
Registry, which inventories DOD systems and provides their security 
status, and the IT Management Application, which contains DOD IT 
budget information, according to the "Security Status for Systems 
Reported in DOD IT Databases," The IG released the report last month.

"Specifically, 120 of 148 IT systems (81 percent) reported in the 
fiscal year 2006 President's Budget Capital Investment Reports did not 
match to reports on the same systems in the IT Registry, and 87 of 148 
IT Registry reports (59 percent) were not internally consistent 
between the system mission criticality and the mission assurance 
category data elements," the report states. The IG said the military 
services and department agencies also did not submit timely, accurate 
and complete IT certification and compliance statements to DOD's chief 
information officer.

The IG recommended several steps to fix the problem, including using 
automatic data integrity tools in the databases and penalizing 
department CIOs who did not implement controls. The IG asked the DOD 
CIO to respond to the report by Jan. 27.

This was the second report in seven months that is critical of the 
information in DOD databases. The IG criticized the military services 
and department agencies in June 2005 for not adequately reporting IT 
investments to OMB in support of the fiscal 2006 DOD budget.



_________________________________
InfoSec News v2.0 - Coming Soon! 
http://www.infosecnews.org 

<Prev in Thread] Current Thread [Next in Thread>
  • [ISN] IG critical of DOD IT, InfoSec News <=