Information Security:
Agencies Need to Develop and Implement Adequate Policies for Periodic Testing
GAO-07-65: Published: Oct 20, 2006. Publicly Released: Nov 20, 2006.
Additional Materials:
- Highlights Page:
- Full Report:
- Accessible Text:
Contact:
(202) 512-6244
contact@gao.gov
Office of Public Affairs
(202) 512-4800
youngc1@gao.gov
Agencies rely extensively on computerized information systems and electronic data to carry out their missions. To ensure the security of the information and information systems that support critical operations and infrastructure, federal law and policy require agencies to periodically test and evaluate the effectiveness of their information security controls at least annually. GAO was asked to evaluate the extent to which agencies have adequately designed and effectively implemented policies for testing and evaluating their information security controls. GAO surveyed 24 major federal agencies and analyzed their policies to determine whether the policies address important elements for periodic testing. GAO also examined testing documentation at 6 agencies to assess the quality and effectiveness of testing on 30 systems.
Federal agencies have not adequately designed and effectively implemented policies for periodically testing and evaluating information security controls. Agencies' policies often did not include important elements for performing effective testing. For example, none of the agencies' policies addressed how to determine the depth and breadth of testing according to risk. Also, agencies did not always address other important elements, including the identification and testing of security controls common to multiple systems, the definition of roles and responsibilities of personnel performing tests, and the frequency of periodic testing. The six case study agencies did not effectively implement policies for periodically testing and evaluating information security controls for the 30 systems reviewed. The methods and practices for testing and evaluating controls at the six agencies were not adequate to ensure that assessments were consistent, of similar quality, and repeatable. For example, these agencies did not always sufficiently document their test methods and results, did not define the assessment methods to be used when evaluating security controls, did not test security controls as prescribed, and did not include previously reported remedial actions or weaknesses in their test plans to ensure they had been addressed. As a result, agencies may not have reasonable assurance that controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements of the agency. In addition, agencies may not be fully aware of the security control weaknesses in their systems, thereby leaving the agencies' information and systems vulnerable to attack or compromise.
Recommendations for Executive Action
Status: Closed - Implemented
Comments: In fiscal year 2011, we verified that OMB's fiscal year 2010 FISMA guidance instructed federal agencies to develop and implement policies on periodic testing and evaluation.
Recommendation: Because of the governmentwide weaknesses in the design and implementation of agencies' policies for periodically testing and evaluating security controls, the Director of the Office of Management and Budget should instruct federal agencies to develop and implement policies on periodic testing and evaluation.
Agency Affected: Executive Office of the President: Office of Management and Budget
Status: Closed - Implemented
Comments: In fiscal year 2011, we verified that OMB's fiscal year 2010 FISMA reporting guidance to the IGs requested that they report on the status of several program areas at their agency, including periodically testing and evaluating systems, which are covered under the continuous monitoring section.
Recommendation: Because of the governmentwide weaknesses in the design and implementation of agencies' policies for periodically testing and evaluating security controls, the Director of the Office of Management and Budget should revise instructions for future Federal Information Security Management Act reporting by requesting Inspectors General to report on the quality of agencies' periodic testing processes.
Agency Affected: Executive Office of the President: Office of Management and Budget
Status: Closed - Implemented
Comments: In fiscal year 2011, we verified that the Secretary of Commerce directed the Director, National Institute of Standards and Technology (NIST), to strengthen guidance on determining the depth and breadth of testing security controls through the issuance of NIST's Special Publication 800-53A, guide for conducting security assessments, which provides information on determining the depth and breadth of testing security controls.
Recommendation: The Secretary of Commerce should direct the Director, National Institute of Standards and Technology, to strengthen guidance on determining the depth and breadth of testing security controls.
Agency Affected: Department of Commerce
Explore the full database of GAO's Open Recommendations
»
Feb 3, 2021
-
Fixed-Price-Incentive Contracts:
DOD Has Increased Their Use but Should Assess Contributions to OutcomesGAO-21-181: Published: Feb 3, 2021. Publicly Released: Feb 3, 2021.
Jan 29, 2021
-
Federal Real Property:
Additional Documentation of Decision Making Could Improve Transparency of New Disposal ProcessGAO-21-233: Published: Jan 29, 2021. Publicly Released: Jan 29, 2021.
Jan 19, 2021
-
Federal Rulemaking:
Selected EPA and HHS Regulatory Analyses Met Several Best Practices, but CMS Should Take Steps to Strengthen Its AnalysesGAO-21-151: Published: Dec 17, 2020. Publicly Released: Jan 19, 2021.
Jan 13, 2021
-
Department of Energy Contracting:
Improvements Needed to Ensure DOE Assesses Its Full Range of Contracting Fraud RisksGAO-21-44: Published: Jan 13, 2021. Publicly Released: Jan 13, 2021.
Dec 16, 2020
-
Data Governance:
Agencies Made Progress in Establishing Governance, but Need to Address Key MilestonesGAO-21-152: Published: Dec 16, 2020. Publicly Released: Dec 16, 2020.
Dec 9, 2020
-
2020 Census:
The Bureau Concluded Field Work but Uncertainty about Data Quality, Accuracy, and Protection RemainsGAO-21-206R: Published: Dec 9, 2020. Publicly Released: Dec 9, 2020.
Dec 3, 2020
-
2020 Census:
Census Bureau Needs to Assess Data Quality Concerns Stemming from Recent Design ChangesGAO-21-142: Published: Dec 3, 2020. Publicly Released: Dec 3, 2020. -
2020 Census:
Census Bureau Needs to Ensure Transparency over Data QualityGAO-21-262T: Published: Dec 3, 2020. Publicly Released: Dec 3, 2020.
Nov 30, 2020
-
Federal Buying Power:
OMB Can Further Advance Category Management Initiative by Focusing on Requirements, Data, and TrainingGAO-21-40: Published: Nov 30, 2020. Publicly Released: Nov 30, 2020.
Nov 24, 2020
-
Disaster Response:
Agencies Should Assess Contracting Workforce Needs and Purchase Card Fraud RiskGAO-21-42: Published: Nov 24, 2020. Publicly Released: Nov 24, 2020.
Looking for more? Browse all our products here