FB pixel

U.S. senators voice concern over State Department cybersecurity

U.S. senators voice concern over State Department cybersecurity
 

A group of bipartisan U.S. senators have voiced their concern over State Department cybersecurity.

Senators Cory Gardner (R-CO), Ron Wyden (D-OR), Ed Markey (D-MA), Rand Paul (R-KY), and Jeanne Shaheen (D-NH), called on the State Department to adopt basic cybersecurity measures to protect against phishing, hacks, and other cyberattacks in a letter released yesterday.

Following multiple reports from outside auditors highlighting the department’s failure to adopt measures like multi-factor authentication and regular security audits, which are mandated by the Federal Cybersecurity Enhancement Act, the bipartisan group of five senators raised concerns in a joint letter to Secretary of State Mike Pompeo.

The senators said in the letter that a “password-only approach is no longer sufficient to protect sensitive information from sophisticated phishing attempts and other forms of credential theft.”

The letter also noted that according to a 2018 General Services Administration (GSA) assessment of federal cybersecurity, the State Department had only deployed enhanced access across 11 percent of required agency devices. This not only puts the department at risk, the senators wrote, but it also violates federal law that requires agencies to use multi-factor authentication for all computer accounts with “elevated privileges” utilized by personnel with administrative duties.

“The Department of State’s Inspector General (IG) found last year that 33 percent of diplomatic missions failed to conduct even the most basic cyber threat management practices, like regular reviews and audits,” said the senators. “The IG also noted that experts who tested these systems ‘successfully exploited vulnerabilities in email accounts of Department personnel as well as Department applications and operating systems.’

“We are sure you will agree on the need to protect American diplomacy from cyberattacks, which is why we have such a hard time understanding why the Department of State has not followed the lead of many other agencies and complied with federal law requiring agency use of multi-factor authentication.”

The letter reflects aggravation among lawmakers at the lack of movement on cybersecurity issues, especially after President Trump signed an executive order last year to hold agency heads accountable for increasing cybersecurity defenses.

In recent years, the Government Accountability Office (GAO) has issued literally dozens of audit reports to Congress and appropriate federal agencies, and made nearly 2,500 recommendations to these federal agencies to improve their implementation of information security and access security controls.

Article Topics

 |   |   | 

Latest Biometrics News

 

UK ICO plans guidance to build public confidence in AI, biometrics deployments

The UK Information Commissioner’s Office says in a response to government inquiries that it is making progress on the AI…

 

Unico accuses Experian subsidiary of freeloading face biometrics verifications

Brazil-headquartered Unico alleges that a competitor has been surreptitiously using its face biometric software to benefit from its identity verification…

 

Firms pursue continuous identity in push to meet agentic paradigm shift

Israeli cybersecurity startup NewCore has emerged from stealth boasting $66 million in investment from Cyberstarts, Index Ventures and Evolution Equity…

 

Roblox shows off Persona age estimation as it launches age-based accounts

Roblox is on a mission to prove that its facial age estimation system works as intended. The mega-popular gaming platform,…

 

iDAKTO acquires cybersecurity specialist Stelau to challenge digital ID leaders

iDAKTO has acquired France-based cybersecurity and digital identity infrastructure firm Stelau as it gears up to challenge the leading global…

 

How open standards are reshaping Colombia’s digital identity stack

Colombia’s five-day verifiable credentials bootcamp in Bogotá may have looked like a small technical exercise. In reality, it represented the…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events