Industry


Ads by TechWords

See your link here


Martin McKeay's picture
Martin McKeay

Security Matters

VA couldn't have centralized security because of one word?

This shouldn't surprise me, but it does.  According to GovExec.com, the reason the Veterans Administration didn't have a centralized IT security authority was because the VA's general council argued that the CIO's responsibility was to 'ensure' FISMA compliance not 'enforce'.  In other words, this lawyer decided that the autonomy of the district offices was more important than the security of the information in their systems.  This was all because of the district offices wanted to protect their power and control over the local systems.

I've worked in in this sort of environment before, and it can't lead to any good.  Especially in large environments, there is a need for a central authority to set minimum requirements for security.  Otherwise each office has their own idea of what's important and how it should be secured, which leads to large gaps in security practices.  Often the local shops don't have anyone who's dedicated to security, or if they do, the person isn't properly trained.  I can't stand the establishment of fiefdoms in this manner, though it's well-known in the government sector.

What People Are Saying

Seems to me that FISMA is

Seems to me that FISMA is just another government reg that has no teeth. When did our lawmakers start forgetting about ENFORCEMENT?

Better be despised for too anxious apprehensions, than ruined by too confident security.
Edmund Burke (1729 - 1797)