SSA has problems with unauthorized software, IG says

Agency had 197 malware incidents in past year

The Social Security Administration doesn't do enough to protect its IT systems against unauthorized installation of software, SSA Inspector General Patrick O’Carroll said in a new report.

SSA employees and contractors must get approval to install non-agency software on SSA computers. However, the policy needs improvement and is not always followed, O’Carroll wrote in the report, dated Oct. 27.

SSA’s monitoring of agency software configurations was insufficient, coordination on software was lacking between local managers and central management, and no disciplinary action was taken against the employees responsible for seven security breaches in November 2009, the report states. SSA officials said discipline was unwarranted because employees downloaded malware unintentionally.


Related stories:

SSA teleworkers may put personal data at risk

SSA to create dozens of new datasets


SSA still has security and malware problems, the IG wrote. From Oct. 30, 2009, to Sept. 21, 2010, the agency had approximately 197 malware incidents in which an individual could have gained unauthorized access to or disabled SSA’s systems, the report states.

“Although we only reviewed seven software-related security incidents, the potential for a larger issue may exist if adequate controls are not implemented to prevent the installation of unauthorized software,” O’Carroll wrote.

The report recommends that SSA:

  • Consider revising its software approval policy to ensure that all software goes through a central management point, such as the Office of the CIO, and remind employees and contractors of the software policy.
  • Enforce the policy through disciplinary action, when appropriate.
  • Have all software monitoring directed by the Office of Telecommunications and Systems Operations with implementation by local managers.

SSA officials agreed with the recommendations.

About the Author

Alice Lipowicz is a staff writer covering government 2.0, homeland security and other IT policies for Federal Computer Week.

Featured

  • Defense
    Ryan D. McCarthy being sworn in as Army Secretary Oct. 10, 2019. (Photo credit: Sgt. Dana Clarke/U.S. Army)

    Army wants to spend nearly $1B on cloud, data by 2025

    Army Secretary Ryan McCarthy said lack of funding or a potential delay in the JEDI cloud bid "strikes to the heart of our concern."

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.