Securing data is never easy. It often requires the infusion of outside expertise to put together an effective information security strategy. Data stored on government servers is especially valuable to both individual fraudsters and nation-state actors, and government agencies have been under pressure to enhance their infrastructure security capabilities and take additional measures to protect sensitive records.

A recent audit of the U.S. government’s Office of Personnel Management (OPM) suggested that many agencies, including the OPM, still have a long way to go. To get their security programs off the ground, government organizations must build trust with the private sector and tap companies in the security industry to guide their efforts.

Auditing National Infrastructure Security

The OPM audit found that while the agency had improved its overall data protection program, a moratorium implemented during fiscal year 2015 on all security assessment and authorization activities effectively weakened its security posture. The following year, the OPM authorized a sprint that was designed to bring all systems into compliance. The purpose of the most recent audit was to evaluate the status of that effort.

Two-thirds of the wide area network (WAN) and local area network (LAN) security controls the inspection team tested were found to be either not satisfied or only partially satisfied. The auditors opined that in this state, the likelihood of being able to identify vulnerabilities is significantly reduced.

Even more critical is the absence of a standard LAN/WAN system security plan (SSP). In the auditor’s view, the SSP completeness is foundational. Without it, security teams lack inventory controls and knowledge of what is present within the network.

An Executive Order

Along with the audit, the White House issued its “Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure,” which gave each agency and department head 90 days to produce a risk management report to the secretary of the Department of Homeland Security (DHS) and the director of the Office of Management and Budget (OMB). The report must document “the risk mitigation and acceptance choices made by each agency head,” including strategic, operational and budgetary considerations as well as unmitigated vulnerabilities.

These agencies and departments are expected to use the National Institute of Standards and Technology’s (NIST) “Framework for Improving Critical Infrastructure Cybersecurity.” To that end, the NIST issued an implementation guide to help organizations comply with the executive order.

The Private Sector’s Perspective

As government agencies such as the OPM grapple with infrastructure security issues, cybersecurity experts have called for government organizations to think about these challenges from the private sector’s point of view. According to FCW, government agencies should focus on building trust with the security industry and, in turn, rely on the industry to evolve cybersecurity stratagems.

Additionally, the advisory board to the NIST challenged the House of Representatives’ Science, Space and Technology Committee’s approved legislation, which tasked the NIST with conducting cybersecurity audits of government agencies and departments. While the organization has always been associated with the creation of standards and guidance, the advisory board opined that the responsibility shift would “complicate its current mission as a neutral adviser.”

Meanwhile, the Information Security Oversight Office (ISOO)’s “2016 Report to the President” revealed that the cost to maintain classification management systems in 2016 was approximately $16.89 billion. The report also found that most government organizations had “established uniform procedures to ensure that automated information systems, including networks and telecommunications systems that store classified information, prevent access by unauthorized persons, ensure the integrity of the information and, to the maximum extent practicable, use common information technology standards and protocols.”

Waiting For an Invitation

U.S. government organizations certainly have their work cut out for them. The president’s executive order should make a significant dent in the initiative to bolster security across all agencies, but the government can’t do it alone. Private entities are ready and able to guide the government’s efforts to establish a plan to secure the nation’s infrastructure, but they appear to be waiting for an invitation.

More from Data Protection

The Importance of Modern-Day Data Security Platforms

Data is the backbone of businesses and companies everywhere. Data can range from intellectual property to critical business plans to personal health information or even money itself. At the end of the day, businesses are looking to grow revenue, innovate, and operationalize but to do that, they must ensure that they leverage their data first because of how important and valuable it is to their organization. No matter the industry, the need to protect sensitive and personal data should be…

Meeting Today’s Complex Data Privacy Challenges

Pop quiz: Who is responsible for compliance and data privacy in an organization? Is it a) the security department, b) the IT department, c) the legal department, d) the compliance group or e) all of the above? If you answered "all of the above," you are well-versed in the complex world of compliance and data privacy! While compliance is a complex topic, the patchwork of regulations imposed by countries, regions, states and industries further compounds it. This complexity has turned…

The Digital World is Changing Fast: Data Discovery Can Help

The rise in digital technology is creating opportunities for individuals and organizations to achieve unprecedented success. It’s also creating new challenges, particularly in protecting sensitive personal and financial information. Personally identifiable information (PII) is trivial to manage. It’s often spread across multiple locations and formats and can be challenging to find and classify. Organizations need a modern data discovery and classification solution to identify sensitive data across physical, virtual and public clouds. The Current State of Sensitive Data Discovery and…

Backdoor Deployment and Ransomware: Top Threats Identified in X-Force Threat Intelligence Index 2023

Deployment of backdoors was the number one action on objective taken by threat actors last year, according to the 2023 IBM Security X-Force Threat Intelligence Index — a comprehensive analysis of our research data collected throughout the year. Backdoor access is now among the hottest commodities on the dark web and can sell for thousands of dollars, compared to credit card data — which can go for as low as $10. On the dark web — a veritable eBay for…