Oversight

State IG: Broadcasters need tighter controls over user accounts

Shutterstock image. Copyright: Jane Kelly

The Broadcasting Board of Governors needs to do a better job tallying and disabling inactive user accounts to protect sensitive agency data, according to a recent oversight report.

An audit by the State Department's Office of Inspector General found that some accounts on the BBG's Microsoft Windows directory database are misidentified, and others lack an appropriately defined policy for when they become inactive and should be disabled. Auditors discovered 98 duplicate accounts, and eight accounts deemed inactive that were identified as privileged. Those privileged accounts were allowed increased network access and were exempted from log-ins to avoid being disabled.

Auditors were concerned that hackers who gained control over one of these non-user or privileged accounts could access BBG's servers, applications or confidential directory information.

The report also noted that, since fiscal 2010, OIG has repeatedly found issues with BBG's account management protocol, including insufficient password management standards and not following its own internal policies for disabling user accounts after the defined inactivity period.

OIG recommended that the agency CIO develop a way to separate and accurately identify user and non-user accounts, and issue definitions of when privileged and non-user accounts become inactive and should be disabled. BBG concurred with the recommendations, and said it will take corrective action.

About the Author

Chase Gunter is a former FCW staff writer.

Featured

  • Comment
    Pilot Class. The author and Barbie Flowers are first row third and second from right, respectively.

    How VA is disrupting tech delivery

    A former Digital Service specialist at the Department of Veterans Affairs explains efforts to transition government from a legacy "project" approach to a more user-centered "product" method.

  • Cloud
    cloud migration

    DHS cloud push comes with complications

    A pressing data center closure schedule and an ensuing scramble to move applications means that some Homeland Security components might need more than one hop to get to the cloud.

  • Comment
    Blue Signage and logo of the U.S. Department of Veterans Affairs

    Doing digital differently at VA

    The Department of Veterans Affairs CIO explains why digital transformation is not optional.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.