At a time when senior defense officials are sounding the alarms about the potential for a devastating cyber attack against America's critical infrastructure, the U.S. Department of Energy's inspector general has found dozens of unaddressed cyber vulnerabilities at key DOE facilities, including ones dealing with nuclear programs.
The good news? The overall number of cyber vulnerabilities at DOE has declined from 56 to 38 since 2011 as a result of better information technology security practices. The bad: 22 of those 38 vulnerabilities are brand-new while the remaining 16 went unresolved even after the inspector general noted them in 2011, according to a report released this month. This comes as the department has suffered "nearly 3,000 cyber-related incidents" over the past four years, the report says.
"Our review of the Offices of the Under Secretary for Nuclear Security, Under Secretary for Science and Under Secretary of Energy organizations identified various control weaknesses related to access controls, vulnerability management, system integrity of web applications, planning for continuity of operations and change control management," reads the report.
The report found that real live people (quaint, right?) could access places they weren't supposed to at six DOE facilities due to inadequate standards in physical controls - e.g., failing to properly keep track of who is allowed inside certain facilities. It also found networks and computers at some facilities had weak password protection - something that could make it easier for the wrong people to log onto DOE computers.
Meanwhile, 1,132 desktop computers (out of 1,952 that were inspected, or 58 percent) had unpatched software holes and dozens of servers were in the same shape. At eight locations, the IG found that 29 web applications dealing with financial, human resources and "general support" were vulnerable to hacking.
The report goes on to knock DOE for failing to implement known fixes and policies designed to enhance cyber security.
"The cyber security control weaknesses we identified were due, in part, to inadequate development and implementation of security control processes," the report says. "In particular, many sites developed policies and procedures that did not always satisfy Federal or Department security requirements."
Even when security policies were officially in place, some sites failed to follow them. This is exactly the type of problem that government officials constantly lament when they say that most cyber vulnerabilities could be addressed if organizations practiced basic IT "hygiene" - meaning they need to require strong passwords and frequently update software with security patches.
At the end of the day, these vulnerabilities, if left unchecked, leave the department open to "increased risk of compromise and/or loss, modification and non-availability of the Department's systems and the information residing within them."
The department agreed with the IG's findings (though it did quibble with some of the findings regarding security standards and policies, and said some of the vulnerabilities may involve acceptable levels of risk) and is moving to implement its recommendations for fixing the security holes, the report says.
While the report detailed numerous vulnerabilities, simply patching them may only result in a permanent game of catch up against hackers, said one cyber security expert.
"It reminded me of the results of most vulnerability assessment reports for any decently sized organization," said Richard Bejtlich, chief security officer of cybersecurity firm, Mandiant. "Vulnerabilities of all kinds are found, involving unpatched systems, code waiting to be exploited, and the like. The next report will look the same."
"It would have been much more useful if DOE had brought a third party to each of its sites to determine what intruders are actively exploiting those sites right now, then prioritize incident response and countermeasures to frustrate the adversary," he added. "Instead, I expect another round of trying to fix every problem, while intruders watch and evade any security 'improvements' that DOE applies."
John Reed is a national security reporter for Foreign Policy, where this first appeared. Previously, he edited Military.com's publication Defense Tech and was associate editor of DoDBuzz.
John Reed / Department of Energy still vulnerable to cyber attack - pressofAtlanticCity.com: Commentary
1-877-773-7724
SubscriberServices@pressofac.com
John Reed / Department of Energy still vulnerable to cyber attack
Posted: Thursday, November 22, 2012 12:01 am
John Reed / Department of Energy still vulnerable to cyber attack
At a time when senior defense officials are sounding the alarms about the potential for a devastating cyber attack against America's critical infrastructure, the U.S. Department of Energy's inspector general has found dozens of unaddressed cyber vulnerabilities at key DOE facilities, including ones dealing with nuclear programs.
The good news? The overall number of cyber vulnerabilities at DOE has declined from 56 to 38 since 2011 as a result of better information technology security practices. The bad: 22 of those 38 vulnerabilities are brand-new while the remaining 16 went unresolved even after the inspector general noted them in 2011, according to a report released this month. This comes as the department has suffered "nearly 3,000 cyber-related incidents" over the past four years, the report says.
"Our review of the Offices of the Under Secretary for Nuclear Security, Under Secretary for Science and Under Secretary of Energy organizations identified various control weaknesses related to access controls, vulnerability management, system integrity of web applications, planning for continuity of operations and change control management," reads the report.
The report found that real live people (quaint, right?) could access places they weren't supposed to at six DOE facilities due to inadequate standards in physical controls - e.g., failing to properly keep track of who is allowed inside certain facilities. It also found networks and computers at some facilities had weak password protection - something that could make it easier for the wrong people to log onto DOE computers.
Meanwhile, 1,132 desktop computers (out of 1,952 that were inspected, or 58 percent) had unpatched software holes and dozens of servers were in the same shape. At eight locations, the IG found that 29 web applications dealing with financial, human resources and "general support" were vulnerable to hacking.
The report goes on to knock DOE for failing to implement known fixes and policies designed to enhance cyber security.
"The cyber security control weaknesses we identified were due, in part, to inadequate development and implementation of security control processes," the report says. "In particular, many sites developed policies and procedures that did not always satisfy Federal or Department security requirements."
Even when security policies were officially in place, some sites failed to follow them. This is exactly the type of problem that government officials constantly lament when they say that most cyber vulnerabilities could be addressed if organizations practiced basic IT "hygiene" - meaning they need to require strong passwords and frequently update software with security patches.
At the end of the day, these vulnerabilities, if left unchecked, leave the department open to "increased risk of compromise and/or loss, modification and non-availability of the Department's systems and the information residing within them."
The department agreed with the IG's findings (though it did quibble with some of the findings regarding security standards and policies, and said some of the vulnerabilities may involve acceptable levels of risk) and is moving to implement its recommendations for fixing the security holes, the report says.
While the report detailed numerous vulnerabilities, simply patching them may only result in a permanent game of catch up against hackers, said one cyber security expert.
"It reminded me of the results of most vulnerability assessment reports for any decently sized organization," said Richard Bejtlich, chief security officer of cybersecurity firm, Mandiant. "Vulnerabilities of all kinds are found, involving unpatched systems, code waiting to be exploited, and the like. The next report will look the same."
"It would have been much more useful if DOE had brought a third party to each of its sites to determine what intruders are actively exploiting those sites right now, then prioritize incident response and countermeasures to frustrate the adversary," he added. "Instead, I expect another round of trying to fix every problem, while intruders watch and evade any security 'improvements' that DOE applies."
John Reed is a national security reporter for Foreign Policy, where this first appeared. Previously, he edited Military.com's publication Defense Tech and was associate editor of DoDBuzz.
Posted in Commentary on Thursday, November 22, 2012 12:01 am.
Similar Stories
Most Read
Opinion Home
Editorial Cartoons
Commentary
Editorials
Letters
Recent Polls
Your Lawmakers
Connect with us
By Dave Enscoe, Advertising Department More »
SEARCH PROPERTIES
Place A Classified Ad »
By Arv Voss, Motor Matters More »
SEARCH CARS+
Place A Classified Ad »
WASHINGTON — The U.S. economy added 175,000 jobs in May — a steady pace that shows strength in the face of tax increases and government spending cuts if not enough to reduce still-high unemployment. More »
SEARCH JOBS+
Place A Classified Ad »
PLACE YOUR CLASSIFIED AD IN PRINT
AND ONLINE TODAY »
Browse Classified Categories
Place A Classified Ad »
Featured Businesses
Add your business here »Citywide Towing
Atlantic City, NJ 08401 [Map]
609-517-3871
Linwood Care Center
Linwood, NJ 08221 [Map]
609-927-6131
Handcrafted Cabinetr...
West Creek, NJ 08092 [Map]
609-891-0166
Pappy's Fishin' Stuff
Ocean City, NJ 08226 [Map]
609-398-6996
Frank’s Jewelers
Egg Harbor Twp , NJ 08234 [Map]
609-641-4252
Duke O'fluke
Somers Point, NJ 08244 [Map]
609-926-2280
Keeper Back Bay Fishing
Margate City, NJ 08402 [Map]
609-576-5998
JBS Solar and Wind LLC
North Cape May, NJ 08204 [Map]
609-884-7373
Cape Regional Medica...
Cape May Court House, NJ 08210 [Map]
609-463-2000
English Creek Supply
Egg Harbor Twp, NJ 08234 [Map]
609-641-6168
M & S Produce Outlet
Egg Harbor Township, NJ 08234 [Map]
609-383-8323
Perfect Solutions So...
Northfield, NJ 08225 [Map]
609-601-5252
Beachcomber Coins & ...
Egg Harbor Twp, NJ 08234 [Map]
609-645-1031
The Boat Shop
Manahawkin, NJ 08050 [Map]
609-597-1271
Grace Energy
Rio Grande, NJ 08242 [Map]
609-465-5545
Fish Finder the
Brigantine, NJ 08203 [Map]
609-264-0918
Mangos Restaurant Llc
Margate City, NJ 08402 [Map]
609-487-7450
Ventnor Heights Auto...
Ventnor City, NJ 08406 [Map]
609-823-0520
Access Roofing & Con...
Atlantic City, NJ 08401 [Map]
888-661-0333
Thompson Marine & En...
Egg Harbor Township, NJ 08234 [Map]
609-927-2415
Matt Blatt Kia
Egg Harbor Township, NJ 08234 [Map]
609-573-3100
Royal Suites Healthc...
Galloway, NJ 08205 [Map]
609-748-9900
Bob's Garden Center
Egg Harbor Township, NJ 08234 [Map]
609-641-6306
Permanent Makeup by Amy
Egg Harbor Twp , NJ 08234 [Map]
609-383-2769
Mays Landing Golf &...
Mays Landing, NJ 08330 [Map]
609-641-4411
Copiers Plus
Egg Harbor Township, NJ 08234 [Map]
609-645-7587
Sunnyland Child Care...
Ventnor City, NJ 08406 [Map]
609-823-4110
Simple Escape Spa
Galloway, NJ 08205 [Map]
609-464-2313
Atlantic Limousine, Inc
Atlantic City, NJ 08401 [Map]
800-348-3484
Dolfin Dock Inc
Somers Point, NJ 08244 [Map]
609-927-1730
Jack Facciolo, D.O.
Rio Grande, NJ 08242 [Map]
609-886-0800
Gutter Giants LLC
Egg Harbor Township, NJ 08234 [Map]
Professional Physcal...
N. Cape May, NJ 08204 [Map]
609-884-9800
Rio Nails And Spa
Rio Grande, NJ 08242 [Map]
609-463-8868
Historic Cold Spring...
Cape May, NJ 08204 [Map]
609-898-4504
Carl “Luke” Roth of ...
Villas, NJ 08251 [Map]
609-886-8200
Boardwalk Honda
Pleasantville, NJ 08232 [Map]
609-428-4475
Eddie's Auto Body Shop
Erma, NJ 08204 [Map]
609-884-4613
Fioretta Llc
Northfield, NJ 08225 [Map]
609-241-8628
Captain Andy's Marina
Margate City, NJ 08402 [Map]
609-822-0916
Wild Styles/Boost Mo...
Rio Grande, NJ 08242 [Map]
609-846-7030
Foschi Studio
Linwood, NJ 08221 [Map]
609-927-3044
Richard T Fauntleroy Pc
Pleasantville, NJ 08232 [Map]
609-646-4466
Bennett Chevy
Egg Harbor Twp., NJ 08234 [Map]
609-641-0444
Skelly's Hi Point Pub
Absecon, NJ 08201 [Map]
609-641-3172
Oreck Floor Care Center
Mays Landing, NJ 08330 [Map]
609-272-7590
Pier 47
Wildwood, NJ 08260 [Map]
609-729-4774
Montreal Inn
Cape May, NJ 08204 [Map]
609-884-7011
Foglio's Abbey Floor...
Marmora , NJ 08223 [Map]
609-390-3876
Up The Creek Tavern ...
Keyport, NJ 07735 [Map]
732-739-0214
On a Mission
Pleasantville, NJ 08232 [Map]
609-646-4483
KAS Website Design C...
Absecon, NJ 08201 [Map]
609-703-4696
Up The Creek Marina
Absecon, NJ 08201 [Map]
609-272-9252
Coastal Designer Outlet
Ocean View, NJ 08230 [Map]
609-624-1544
Bloomingsales
Brigantine, NJ 08203 [Map]
609-266-6667
Shore Orthopaedic Un...
Somers Point, NJ 08244 [Map]
609-927-1991
C-Jam Yacht Sales
Somers Point, NJ 08244 [Map]
609-927-1175
Tackle Direct
Somers Point, NJ 08244 [Map]
609-788-3819
Black Horse Auto Sales
Egg Harbor Township, NJ 08234 [Map]
609-272-1877
Absecon Bay Sportsme...
Absecon, NJ 08201 [Map]
609-484-0409
Tuckahoe Bike Shop
Woodbine, NJ 08230 [Map]
609-628-0101
Newkirk Family Veter...
Egg Harbor Township, NJ 08234 [Map]
609-645-2120
One Stop Bait & Tackle
Atlantic City, NJ 08401 [Map]
609-348-9450
Raff's Recycling
Cape May Court House , NJ 08210 [Map]
609-465-7406
Mouse Trap Bowling A...
Woodbine, NJ 08270 [Map]
609-861-2695
Schooner Island Marina
Wildwood, NJ 08260 [Map]
609-729-8900
Mama Mia Of Eht
Egg Harbor Township, NJ 08234 [Map]
609-484-8877
Frankie's Pizza II
Mays Landing, NJ 08330 [Map]
609-625-7566
Avalon Limousine Ser...
Egg Harbor Township, NJ 08234 [Map]
609-646-0008
Rio Auto
Palermo, NJ 08225 [Map]
609-390-0001
Sack O' Subs
Ocean City, NJ 08226 [Map]
609-525-0460
...
Egg Harbor Township, NJ 08234 [Map]
609-788-8789
Designer Consignment
Egg Harbor Twp , NJ 08234 [Map]
609-646-5444
Ladies Invitational ...
Absecon, 08201 [Map]
Maynard's Cafe
Margate City, NJ 08402 [Map]
609-822-8423
Surrey Beach House ...
Ventnor City, NJ 08406 [Map]
609-822-6550
Vip Skindeep Llc
Pleasantville, NJ 08232 [Map]
609-677-9900
Crabby's Restaurant
Mays Landing, NJ 08330 [Map]
609-625-2722
Sport Hyundai Dodge
Egg Harbor Township, NJ 08234 [Map]
609-646-1200
Cape May County Hear...
Cape May Court House, NJ 08210 [Map]
609-465-9199
Buck Tails Outfitters
Mays Landing, NJ 08330 [Map]
609-829-2229
Find Local Businesses
Popular Categories
Sections
Services
Contact Us
Contacts By DepartmentThe Press of Atlantic City Media Group
PO Box 3100
1000 West Washington Ave.
Pleasantville, NJ 08232-3100
1-877-773-7724
609-272-7000 SubscriberServices@pressofac.com
Search
© Copyright 2013, pressofAtlanticCity.com, Pleasantville, NJ. Powered by BLOX Content Management System from TownNews.com. [Terms of Use | Privacy Policy]