One factor limiting the roll-out: The government mandate requires using the next generation of smart cards, called Personal Identification Verification (PIV) card, which cards are only now coming to market, Alterman says.To make things even worse for federal agencies, "very little of the money is being funded" by the federal government, he adds. "Agencies have to pay for this out of existing budgets, and most agencies have had retrenchment in their budgets over the last couple of years."This is an awkward time to levy a new security requirement without providing money for it," Alterman says. "The agencies will comply, but this has been a major issue for them."Meanwhile, a congressional report in March giving the federal government a D+ grade on computer security for two years straight has opened debate about the relevance of the grading system."Because of inattention to information security in a multitude of federal agencies, clearly Congress will be more focused on whether they're doing their job," says Paul Kurtz, the executive director of the Cyber Security Industry Alliance (CSIA), a trade consortium.Direction Uncertain
What direction Greg Garcia, as assistant secretary for cyber security and telecommunications, will take remains unknown. Just having someone in that position after it was unoccupied for 14 months is a positive move, notes Kurtz.One thing is certain: Garcia brings a wealth of IT-focused security experience to the job. He joins DHS after having served as the vice president of information security policy and programs for the Information Technology Association of America (ITAA), an industry trade association. Before that, Garcia served as a member of the professional staff, House Science Subcommittee on Research, where he managed science and research issues related to information technology. Earlier, Garcia served as Director of Global Government Relations and head of the Washington office for networking products vendor 3Com.Garcia will find himself working with a Congress that will be focusing on "securing personal information" in the wake of the Veterans Administration "incident," in which a laptop with millions of veterans' personal information was stolen. "That clearly will be an issue Congress will bring up next year," Kurtz says.-Jim Carr is an Aptos, Calif.-based freelance business and technology writer. Contact him at [email protected].POOR GRADES:
The good and the bad
FISMA mandates agencies to develop inventories of IT resources and to test their systems for security vulnerabilities. They must also create remediation plans for potential attacks or outages. Reports prepared by agency CIOs and inspector generals must indicate whether their departments meet FISMA standards.
In the March 2006 report card, eight of the 24 agencies evaluated received F grades for 2005. In addition to the DHS and the DOD, agencies getting Fs included the departments of State, Energy, Interior, Agriculture, Veterans Affairs, and Health and Human Services. The grades for the DOD, Interior, and State fell from D, C+ and D+, respectively, in 2004.
Other agencies whose 2005 grades dropped from a year ago included the Department of Transportation (falling to a C- from an A-); the Department of Justice (to a D from a B-); and the Nuclear Regulatory Commission (to a D- from a B+). Seven agencies received grades of A- or better. The Department of Labor, the Social Security Administration, and the Environmental Protection Agency were among those with A+ grades.
At the other end of the spectrum, several agencies' scores jumped this year. The Office of Personnel Management saw its grade improve to an A+ from a C-, the National Science Foundation and the General Services Administration, climbed to an A and A-, from C+, and NASA's grade rose to a B- from a D-.
— Jim Carr
