At a time when senior defense officials are sounding the alarms about the potential for a devastating cyber attack against America's critical infrastructure, the U.S. Department of Energy's inspector general has found dozens of unaddressed cyber vulnerabilities at key DOE facilities, including ones dealing with nuclear programs.
The good news? The overall number of cyber vulnerabilities at DOE has declined from 56 to 38 since 2011 as a result of better information technology security practices. The bad: 22 of those 38 vulnerabilities are brand-new while the remaining 16 went unresolved even after the inspector general noted them in 2011, according to a report released this month. This comes as the department has suffered "nearly 3,000 cyber-related incidents" over the past four years, the report says.
"Our review of the Offices of the Under Secretary for Nuclear Security, Under Secretary for Science and Under Secretary of Energy organizations identified various control weaknesses related to access controls, vulnerability management, system integrity of web applications, planning for continuity of operations and change control management," reads the report.
The report found that real live people (quaint, right?) could access places they weren't supposed to at six DOE facilities due to inadequate standards in physical controls - e.g., failing to properly keep track of who is allowed inside certain facilities. It also found networks and computers at some facilities had weak password protection - something that could make it easier for the wrong people to log onto DOE computers.
Meanwhile, 1,132 desktop computers (out of 1,952 that were inspected, or 58 percent) had unpatched software holes and dozens of servers were in the same shape. At eight locations, the IG found that 29 web applications dealing with financial, human resources and "general support" were vulnerable to hacking.
The report goes on to knock DOE for failing to implement known fixes and policies designed to enhance cyber security.
"The cyber security control weaknesses we identified were due, in part, to inadequate development and implementation of security control processes," the report says. "In particular, many sites developed policies and procedures that did not always satisfy Federal or Department security requirements."
Even when security policies were officially in place, some sites failed to follow them. This is exactly the type of problem that government officials constantly lament when they say that most cyber vulnerabilities could be addressed if organizations practiced basic IT "hygiene" - meaning they need to require strong passwords and frequently update software with security patches.
At the end of the day, these vulnerabilities, if left unchecked, leave the department open to "increased risk of compromise and/or loss, modification and non-availability of the Department's systems and the information residing within them."
The department agreed with the IG's findings (though it did quibble with some of the findings regarding security standards and policies, and said some of the vulnerabilities may involve acceptable levels of risk) and is moving to implement its recommendations for fixing the security holes, the report says.
While the report detailed numerous vulnerabilities, simply patching them may only result in a permanent game of catch up against hackers, said one cyber security expert.
"It reminded me of the results of most vulnerability assessment reports for any decently sized organization," said Richard Bejtlich, chief security officer of cybersecurity firm, Mandiant. "Vulnerabilities of all kinds are found, involving unpatched systems, code waiting to be exploited, and the like. The next report will look the same."
"It would have been much more useful if DOE had brought a third party to each of its sites to determine what intruders are actively exploiting those sites right now, then prioritize incident response and countermeasures to frustrate the adversary," he added. "Instead, I expect another round of trying to fix every problem, while intruders watch and evade any security 'improvements' that DOE applies."
John Reed is a national security reporter for Foreign Policy, where this first appeared. Previously, he edited Military.com's publication Defense Tech and was associate editor of DoDBuzz.
John Reed / Department of Energy still vulnerable to cyber attack - pressofAtlanticCity.com: Commentary
1-877-773-7724
SubscriberServices@pressofac.com
John Reed / Department of Energy still vulnerable to cyber attack
Posted: Thursday, November 22, 2012 12:01 am
John Reed / Department of Energy still vulnerable to cyber attack
At a time when senior defense officials are sounding the alarms about the potential for a devastating cyber attack against America's critical infrastructure, the U.S. Department of Energy's inspector general has found dozens of unaddressed cyber vulnerabilities at key DOE facilities, including ones dealing with nuclear programs.
The good news? The overall number of cyber vulnerabilities at DOE has declined from 56 to 38 since 2011 as a result of better information technology security practices. The bad: 22 of those 38 vulnerabilities are brand-new while the remaining 16 went unresolved even after the inspector general noted them in 2011, according to a report released this month. This comes as the department has suffered "nearly 3,000 cyber-related incidents" over the past four years, the report says.
"Our review of the Offices of the Under Secretary for Nuclear Security, Under Secretary for Science and Under Secretary of Energy organizations identified various control weaknesses related to access controls, vulnerability management, system integrity of web applications, planning for continuity of operations and change control management," reads the report.
The report found that real live people (quaint, right?) could access places they weren't supposed to at six DOE facilities due to inadequate standards in physical controls - e.g., failing to properly keep track of who is allowed inside certain facilities. It also found networks and computers at some facilities had weak password protection - something that could make it easier for the wrong people to log onto DOE computers.
Meanwhile, 1,132 desktop computers (out of 1,952 that were inspected, or 58 percent) had unpatched software holes and dozens of servers were in the same shape. At eight locations, the IG found that 29 web applications dealing with financial, human resources and "general support" were vulnerable to hacking.
The report goes on to knock DOE for failing to implement known fixes and policies designed to enhance cyber security.
"The cyber security control weaknesses we identified were due, in part, to inadequate development and implementation of security control processes," the report says. "In particular, many sites developed policies and procedures that did not always satisfy Federal or Department security requirements."
Even when security policies were officially in place, some sites failed to follow them. This is exactly the type of problem that government officials constantly lament when they say that most cyber vulnerabilities could be addressed if organizations practiced basic IT "hygiene" - meaning they need to require strong passwords and frequently update software with security patches.
At the end of the day, these vulnerabilities, if left unchecked, leave the department open to "increased risk of compromise and/or loss, modification and non-availability of the Department's systems and the information residing within them."
The department agreed with the IG's findings (though it did quibble with some of the findings regarding security standards and policies, and said some of the vulnerabilities may involve acceptable levels of risk) and is moving to implement its recommendations for fixing the security holes, the report says.
While the report detailed numerous vulnerabilities, simply patching them may only result in a permanent game of catch up against hackers, said one cyber security expert.
"It reminded me of the results of most vulnerability assessment reports for any decently sized organization," said Richard Bejtlich, chief security officer of cybersecurity firm, Mandiant. "Vulnerabilities of all kinds are found, involving unpatched systems, code waiting to be exploited, and the like. The next report will look the same."
"It would have been much more useful if DOE had brought a third party to each of its sites to determine what intruders are actively exploiting those sites right now, then prioritize incident response and countermeasures to frustrate the adversary," he added. "Instead, I expect another round of trying to fix every problem, while intruders watch and evade any security 'improvements' that DOE applies."
John Reed is a national security reporter for Foreign Policy, where this first appeared. Previously, he edited Military.com's publication Defense Tech and was associate editor of DoDBuzz.
Posted in Commentary on Thursday, November 22, 2012 12:01 am.
Similar Stories
Most Read
Opinion Home
Editorial Cartoons
Commentary
Editorials
Letters
Recent Polls
Your Lawmakers
Connect with us
By Dave Enscoe, Advertising Department More »
SEARCH PROPERTIES
Place A Classified Ad »
By Tim Spell, Motor Matters More »
SEARCH CARS+
Place A Classified Ad »
Most of the nation’s casino markets have finally recovered from the recession, propelling revenue from slot machines and table games to near-record levels in 2012, according to a new report on the economic health of the gambling industry. More »
SEARCH JOBS+
Place A Classified Ad »
PLACE YOUR CLASSIFIED AD IN PRINT
AND ONLINE TODAY »
Browse Classified Categories
Place A Classified Ad »
Featured Businesses
Add your business here »Boardwalk Honda
Pleasantville, NJ 08232 [Map]
609-428-4475
Pappy's Fishin' Stuff
Ocean City, NJ 08226 [Map]
609-398-6996
Up The Creek Tavern ...
Keyport, NJ 07735 [Map]
732-739-0214
Gutter Giants LLC
Egg Harbor Township, NJ 08234 [Map]
Absecon Bay Sportsme...
Absecon, NJ 08201 [Map]
609-484-0409
Montreal Inn
Cape May, NJ 08204 [Map]
609-884-7011
Simple Escape Spa
Galloway, NJ 08205 [Map]
609-464-2313
Copiers Plus
Egg Harbor Township, NJ 08234 [Map]
609-645-7587
Maynard's Cafe
Margate City, NJ 08402 [Map]
609-822-8423
Handcrafted Cabinetr...
West Creek, NJ 08092 [Map]
609-891-0166
Surrey Beach House ...
Ventnor City, NJ 08406 [Map]
609-822-6550
Mangos Restaurant Llc
Margate City, NJ 08402 [Map]
609-487-7450
Shore Orthopaedic Un...
Somers Point, NJ 08244 [Map]
609-927-1991
Perfect Solutions So...
Northfield, NJ 08225 [Map]
609-601-5252
Duke O'fluke
Somers Point, NJ 08244 [Map]
609-926-2280
Fish Finder the
Brigantine, NJ 08203 [Map]
609-264-0918
Tuckahoe Bike Shop
Woodbine, NJ 08230 [Map]
609-628-0101
Rio Nails And Spa
Rio Grande, NJ 08242 [Map]
609-463-8868
Richard T Fauntleroy Pc
Pleasantville, NJ 08232 [Map]
609-646-4466
Professional Physcal...
N. Cape May, NJ 08204 [Map]
609-884-9800
Foschi Studio
Linwood, NJ 08221 [Map]
609-927-3044
Mouse Trap Bowling A...
Woodbine, NJ 08270 [Map]
609-861-2695
Tackle Direct
Somers Point, NJ 08244 [Map]
609-788-3819
Buck Tails Outfitters
Mays Landing, NJ 08330 [Map]
609-829-2229
Up The Creek Marina
Absecon, NJ 08201 [Map]
609-272-9252
Ventnor Heights Auto...
Ventnor City, NJ 08406 [Map]
609-823-0520
Bloomingsales
Brigantine, NJ 08203 [Map]
609-266-6667
Wild Styles/Boost Mo...
Rio Grande, NJ 08242 [Map]
609-846-7030
Sunnyland Child Care...
Ventnor City, NJ 08406 [Map]
609-823-4110
Rio Auto
Palermo, NJ 08225 [Map]
609-390-0001
Frank’s Jewelers
Egg Harbor Twp , NJ 08234 [Map]
609-641-4252
Coastal Designer Outlet
Ocean View, NJ 08230 [Map]
609-624-1544
...
Egg Harbor Township, NJ 08234 [Map]
609-788-8789
Fioretta Llc
Northfield, NJ 08225 [Map]
609-241-8628
KAS Website Design C...
Absecon, NJ 08201 [Map]
609-703-4696
Sack O' Subs
Ocean City, NJ 08226 [Map]
609-525-0460
Vip Skindeep Llc
Pleasantville, NJ 08232 [Map]
609-677-9900
Frankie's Pizza II
Mays Landing, NJ 08330 [Map]
609-625-7566
Ladies Invitational ...
Absecon, 08201 [Map]
Royal Suites Healthc...
Galloway, NJ 08205 [Map]
609-748-9900
Keeper Back Bay Fishing
Margate City, NJ 08402 [Map]
609-576-5998
Avalon Limousine Ser...
Egg Harbor Township, NJ 08234 [Map]
609-646-0008
Matt Blatt Kia
Egg Harbor Township, NJ 08234 [Map]
609-573-3100
Citywide Towing
Atlantic City, NJ 08401 [Map]
609-517-3871
Schooner Island Marina
Wildwood, NJ 08260 [Map]
609-729-8900
Skelly's Hi Point Pub
Absecon, NJ 08201 [Map]
609-641-3172
Pier 47
Wildwood, NJ 08260 [Map]
609-729-4774
Grace Energy
Rio Grande, NJ 08242 [Map]
609-465-5545
Raff's Recycling
Cape May Court House , NJ 08210 [Map]
609-465-7406
JBS Solar and Wind LLC
North Cape May, NJ 08204 [Map]
609-884-7373
Designer Consignment
Egg Harbor Twp , NJ 08234 [Map]
609-646-5444
Bob's Garden Center
Egg Harbor Township, NJ 08234 [Map]
609-641-6306
Linwood Care Center
Linwood, NJ 08221 [Map]
609-927-6131
Crabby's Restaurant
Mays Landing, NJ 08330 [Map]
609-625-2722
Sport Hyundai Dodge
Egg Harbor Township, NJ 08234 [Map]
609-646-1200
Bennett Chevy
Egg Harbor Twp., NJ 08234 [Map]
609-641-0444
Cape Regional Medica...
Cape May Court House, NJ 08210 [Map]
609-463-2000
Foglio's Abbey Floor...
Marmora , NJ 08223 [Map]
609-390-3876
Captain Andy's Marina
Margate City, NJ 08402 [Map]
609-822-0916
Beachcomber Coins & ...
Egg Harbor Twp, NJ 08234 [Map]
609-645-1031
Carl “Luke” Roth of ...
Villas, NJ 08251 [Map]
609-886-8200
Mays Landing Golf &...
Mays Landing, NJ 08330 [Map]
609-641-4411
Jack Facciolo, D.O.
Rio Grande, NJ 08242 [Map]
609-886-0800
Thompson Marine & En...
Egg Harbor Township, NJ 08234 [Map]
609-927-2415
Cape May County Hear...
Cape May Court House, NJ 08210 [Map]
609-465-9199
Eddie's Auto Body Shop
Erma, NJ 08204 [Map]
609-884-4613
Permanent Makeup by Amy
Egg Harbor Twp , NJ 08234 [Map]
609-383-2769
One Stop Bait & Tackle
Atlantic City, NJ 08401 [Map]
609-348-9450
Access Roofing & Con...
Atlantic City, NJ 08401 [Map]
888-661-0333
M & S Produce Outlet
Egg Harbor Township, NJ 08234 [Map]
609-383-8323
Newkirk Family Veter...
Egg Harbor Township, NJ 08234 [Map]
609-645-2120
Atlantic Limousine, Inc
Atlantic City, NJ 08401 [Map]
800-348-3484
Oreck Floor Care Center
Mays Landing, NJ 08330 [Map]
609-272-7590
Black Horse Auto Sales
Egg Harbor Township, NJ 08234 [Map]
609-272-1877
The Boat Shop
Manahawkin, NJ 08050 [Map]
609-597-1271
English Creek Supply
Egg Harbor Twp, NJ 08234 [Map]
609-641-6168
Historic Cold Spring...
Cape May, NJ 08204 [Map]
609-898-4504
On a Mission
Pleasantville, NJ 08232 [Map]
609-646-4483
Mama Mia Of Eht
Egg Harbor Township, NJ 08234 [Map]
609-484-8877
Dolfin Dock Inc
Somers Point, NJ 08244 [Map]
609-927-1730
C-Jam Yacht Sales
Somers Point, NJ 08244 [Map]
609-927-1175
Find Local Businesses
Popular Categories
Sections
Services
Contact Us
Contacts By DepartmentThe Press of Atlantic City Media Group
PO Box 3100
1000 West Washington Ave.
Pleasantville, NJ 08232-3100
1-877-773-7724
609-272-7000 SubscriberServices@pressofac.com
Search
© Copyright 2013, pressofAtlanticCity.com, Pleasantville, NJ. Powered by BLOX Content Management System from TownNews.com. [Terms of Use | Privacy Policy]