Information security failing and ailing
It's not like we weren't already aware, but it was still sobering to learn that at a hearing on Wednesday, the Senate heard testimony by experts indicating that our government is losing the fight to keep information systems secure. No surprise that there was increased activity aimed at government networks in 2007, but to read that Tim Bennett (president of the Cyber Security Industry Alliance) said "Quite frankly, the bad guys are winning" was demoralizing.
This means we just have to step up the pace and stay ahead of breaches. I'm glad to see Bennett likened the situation to warfare - because that's what I consider it. When government networks are being attacked on a daily basis what else could you call it?
Even with FISMA (the 2002 Federal Information Security Management Act) in place, it looks like some agencies are just going through the motions in order to comply with regulations, but that effectiveness isn't being determined. I don't deny that there's better reporting of attacks now, but I don't agree that that's why we're seeing bigger numbers of attacks. It stands to reason that large, organized, criminal enterprises with lots of financial backing are responsible for the jump in the number of attacks.




