Hacking away at Energy

Even after almost 200 hacks of its systems in 2003, the Energy Department still has some holes in its cyberdefense, according to an inspector general's report released this week.

In response to cybersecurity weaknesses that resulted in 199 intrusions last year, Energy officials say they're taking several measures to protect the department's systems. But they continue to have difficulty finding, tracking and fixing previously reported cybersecurity weaknesses quickly, the inspector said in a report, "The Department's Unclassified Cyber Security Program -- 2004."

The report praised improvements, but highlighted omissions in cyberdefenses, such as:

Incomplete certification and accreditation of major systems.

Missing contingency plans for restoring systems after an emergency.

Continuing problems with access control, segregation of responsibilities for financial processing and correction of known security vulnerabilities. Energy officials say the problems will be rectified within the coming year.

"The department has taken a broad-based approach to making its systems and data as secure as possible," department spokesman Mike Waldron said. "In doing so, 90 percent of our systems were certified and accredited this year. Our goal is to have the remaining 10 percent certified next year." Energy officials recently formed an integrated project team.

Featured

  • Government Innovation Awards
    Government Innovation Awards - https://governmentinnovationawards.com

    Congratulations to the 2020 Rising Stars

    These early-career leaders already are having an outsized impact on government IT.

  • Cybersecurity
    cybersecurity (Rawpixel/Shutterstock.com)

    CMMC clears key regulatory hurdle

    The White House approved an interim rule to mandate defense contractors prove they adhere to existing cybersecurity standards from the National Institute of Standards and Technology.

Stay Connected