Defense
Defense contractors aren’t securing sensitive information, watchdog finds
Contractors routinely fail to secure the Defense Department’s unclassified information from cyberthreats when it’s housed on their systems and networks, according to a new report from the department’s watchdog agency.
The DOD inspector general released a report July 25 after reviewing how DOD information is protected on contractor’s networks and systems. The IG found that contractors were not consistently adhering to DOD’s cybersecurity standards, which are based on controls created by the National Institute of Standards and Technology.
Specifically, contractors failed to use multifactor authentication, enforce strong password use, identify and mitigate vulnerabilities or document and track cybersecurity incidents. Administrators also improperly assigned access privileges that did not align with users’ responsibilities, the report stated.
According to the IG, the department “does not…