Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
United States Security IT

Three US Agencies Get Failing Grades For Not Following IT Best Practices (theregister.com) 19

The Government Accountability Office has issued reports criticizing the Department of Homeland Security, Environmental Protection Agency, and General Services Administration for failing to implement critical IT and cybersecurity recommendations.

DHS leads with 43 unresolved recommendations dating to 2018, including seven priority matters. The EPA has 11 outstanding items, including failures to submit FedRAMP documentation and conduct organization-wide cybersecurity risk assessments. GSA has four pending recommendations.

All three agencies failed to properly log cybersecurity events and conduct required annual IT portfolio reviews. The DHS' HART biometric program remains behind schedule without proper cost accounting or privacy controls, with all nine 2023 recommendations still open.
This discussion has been archived. No new comments can be posted.

Three US Agencies Get Failing Grades For Not Following IT Best Practices

Comments Filter:
  • by algaeman ( 600564 ) on Tuesday August 05, 2025 @03:47PM (#65568372)
    The DHS has tons of budget to hire new people, so I'm sure this will get fixed ASAP. Right? Right?!
  • Security? (Score:5, Insightful)

    by kbrannen ( 581293 ) on Tuesday August 05, 2025 @03:55PM (#65568382)

    It seems really ironic that the Department of Homeland Security is failing to "implement critical IT and cybersecurity recommendations".

    • by gweihir ( 88907 )

      They only apply standards to others, not to themselves. Sounds familiar, doesn't it?

    • It seems really ironic that the Department of Homeland Security is failing to "implement critical IT and cybersecurity recommendations".

      The department of homeland security has long been known as the chief purveyor of insecurity.

  • by Tough Love ( 215404 ) on Tuesday August 05, 2025 @04:41PM (#65568470)

    Suggest the number one recommendation be: bin Microsoft. Close 99% of the holes right there, never mind the licensing evil.

    • by gweihir ( 88907 )

      That would mean stopping to make bad tech decisions. Somehow I do not see that happening.

  • by Bahbus ( 1180627 ) on Tuesday August 05, 2025 @05:22PM (#65568566) Homepage

    The government's AI will totally fix these issues without raising new ones. /s

  • by sconeu ( 64226 ) on Tuesday August 05, 2025 @05:45PM (#65568610) Homepage Journal

    Who at GAO is getting the axe for delivering bad news?

  • Go to just about any government website, and you'll see 1990's era craftsmanship.

  • The 2018 report is the least of our data security issues.

    DOGE went and hacked back doors into all the systems and then loaded our data into systems where they could play with it. They didn't have to go through any interview process. Some had criminal records.

Systems programmers are the high priests of a low cult. -- R.S. Barton

Working...