• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Gao Slams Federal Agencies For It Supply Chain Risk

GAO slams federal agencies for IT supply chain risk

You are here: Home / General Cyber Security News / GAO slams federal agencies for IT supply chain risk

Just times after the US government uncovered of a widespread hack by means of a third-party provider’s software, the US Government Accountability Business (GAO) has issued a report criticizing 23 civilian agencies for inadequate risk administration in their details and communications technology (ICT) supply chains.

The GAO report, “Federal Companies Have to have to Choose Urgent Action to Control Offer Chain Hazards,” examined how federal authorities companies managed risks from third-party hardware, software package, and products and services. It examined several corporations, which includes the Departments of Agriculture, Commerce, Instruction, and Vitality. The Business of Personnel Administration, which endured a large knowledge breach in 2015, was also in the review.

“Around a number of decades, we have described that the escalating dependence on a globally distributed provide chain — and the lack of management about and visibility into how ICT goods and companies are developed, built-in, and deployed — presents an raising sum of risk to federal agencies,” the report warned.

✔ Approved Seller by TheCyberSecurity.News From Our Partners
Avast Ultimate Suite 2021

Protect yourself against all threads using AVAST Ultimate Suite. AVAST Ultimate Suite protects your Windows, macOS and your Android via Avast Premium. In addition it comes with AVAST's well-known VPN service SecureLineVPN. Therefore, it will be a security and privacy in one package.

Get AVAST Ultimate Suite with 65% discount certified seller: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


It discovered ICT supply chain challenges, like the introduction of counterfeit products and solutions and the compromise of genuine kinds right before shipping.

“Danger actors attack all tiers of the provide chain and at every stage of the system advancement daily life cycle and, as a result, pose considerable risk to federal agencies,” it ongoing.

Auditors examined how agencies implemented 7 foundational provide chain risk management (SCRM) methods, including government oversight, producing an agency-extensive system, and developing SCRM needs for suppliers.

“None of the 23 organizations fully carried out all of the SCRM methods and 14 of the 23 businesses had not executed any of the techniques,” it warned, highlighting the security risks concerned.

Not a single company experienced set up a course of action to conduct company-extensive ICT source chain risk assessments, and 19 of them had no method to document their ICT provide chains.

Businesses complained they experienced no federal guidance on SCRM, the report pointed out. A federal group devoted to handling supply chain risk, the Federal Acquisition Security Council, was scheduled to issue steering this thirty day period.

Nevertheless, the Countrywide Institute of Standards and Technology (NIST) by now issued SCRM guidance in 2015 and up-to-date its cyber security framework to deal with supply chain risk in April 2018, the report mentioned. The Place of work of Administration and Finances (OMB) required organizations to tackle SCRM since 2016.

The GAO manufactured 145 recommendations to the companies, which includes earning somebody responsible for primary agency-vast SCRM activities and developing a tactic to secure ICT source chains. Seventeen organizations agreed with all the tips, but a single unknown organization agreed with none.

Previously launched privately in Oct, the report’s public release came in the wake of a prevalent authorities hack. Attackers compromised various govt departments via the SolarWinds IT checking technique in a hack so significant the FBI, CISA, and the ODNI coordinated a governing administration-extensive response. 

Some of the govt departments compromised in the attack, which includes the Section of the Treasury, Division of Commerce, and Homeland Security, had been amongst individuals protected in the GAO report.


Some pieces of this report are sourced from:
www.itpro.co.uk

Previous Post: «Cyber Security News Decade-Long Data Silo to Address Google-Fitbit Privacy Concerns
Next Post: Will the US Move to a Federal Privacy Law in 2021? Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • Big Tech Bans Social Networking App
  • Lack of Funding Could Lead to “Lost Generation” of Cyber-Startups
  • Unveiled: SUNSPOT Malware Was Used to Inject SolarWinds Backdoor
  • ‘I’ll Teams you’: Employees assume security of links, file sharing via Microsoft comms platform
  • DarkSide decryptor unlocks systems without ransom payment – for now
  • Researchers see links between SolarWinds Sunburst malware and Russian Turla APT group
  • Millions of Social Profiles Leaked by Chinese Data-Scrapers
  • Feds will weigh whether cyber best practices were followed when assessing HIPAA fines
  • SolarWinds Hack Potentially Linked to Turla APT
  • 10 quick tips to identifying phishing emails

Copyright © TheCyberSecurity.News, All Rights Reserved.