Ad hoc cyber assessments at Commerce limit visibility over threats

0
136
U.S. Secretary of Commerce Gina Raimondo testifies during a hearing before the Subcommittee on Commerce, Justice, Science, and Related Agencies of Senate Appropriations Committee. A report from the Commerce Office of the Inspector General this week found that the assessments the department relies on to identify gaps in security and ensure its IT systems are safe from malicious hackers is badly in need of reform. (Photo by Alex Wong/Getty Images)

The Department of Commerce has failed to address known deficiencies in its internal assessments of IT systems and struggled to implement effective continuous monitoring of cybersecurity threats, according to an audit.

A report from the Commerce Office of the Inspector General this week found that the internal assessments the department relies on to identify gaps in security and ensure its IT systems are safe from malicious hackers is badly in need of reform. Specifically, nearly half of the department’s 256 IT systems do not have plans or alternative processes in place that outline how these systems should be effectively measured for security, despite a requirement to do so.

“After taking into consideration nonstandardized processes,…

Read More…