Oversight

GAO finds Census Bureau vulnerable to cyberattack

cyber attack button

A litany of IT shortcomings will put the Census Bureau at the mercy of hackers and other nefarious activity until the agency implements a comprehensive information security program, according to the Government Accountability Office.

A report released Feb. 20 concluded that although the Census Bureau has taken steps to protect the information and systems that support its mission, it has not effectively adopted appropriate information security controls to protect those systems.

Security controls are used to regulate who or what can access the bureau’s systems. Census officials, for example, did not adequately control connectivity to key network devices and servers or identify and authenticate users. They also failed to limit user access rights and permissions, encrypt data, monitor systems and network or ensure appropriate physical security controls were adopted.

The main reason for these flaws is the agency’s lack of a sweeping information security program to ensure controls are effectively established and maintained. The Federal Information Security Management Act requires all agencies to create and adopt an information security program.

The agency also failed to keep certain security management program policies current and had not revised its IT security program and policies since April 2010. Intra-agency guidelines require Census to update its policies at least once a year.

"Until the bureau implements a complete and comprehensive security program, it will have limited assurance that its information and systems are being adequately protected against unauthorized access, use, disclosure, modification, disruption or loss," GAO warned.

About the Author

Camille Tuutti is a former FCW staff writer who covered federal oversight and the workforce.

Featured

  • Cybersecurity

    DHS floats 'collective defense' model for cybersecurity

    Homeland Security Secretary Kirstjen Nielsen wants her department to have a more direct role in defending the private sector and critical infrastructure entities from cyberthreats.

  • Defense
    Defense Secretary James Mattis testifies at an April 12 hearing of the House Armed Services Committee.

    Mattis: Cloud deal not tailored for Amazon

    On Capitol Hill, Defense Secretary Jim Mattis sought to quell "rumors" that the Pentagon's planned single-award cloud acquisition was designed with Amazon Web Services in mind.

  • Census
    shutterstock image

    2020 Census to include citizenship question

    The Department of Commerce is breaking with recent practice and restoring a question about respondent citizenship last used in 1950, despite being urged not to by former Census directors and outside experts.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.