美国网络安全:美国数据危险2021年报告(英)-47页_2mb
报告摘要
Federal Cybersecurity: America's Data Still at Risk
Summary
Core Content
This report, issued by the Committee on Homeland Security and Governmental Affairs of the U.S. Senate, evaluates the cybersecurity status of eight key federal agencies two years after the 2019 Portman-Carper Report, which highlighted systemic cybersecurity failures across the federal government. The findings indicate that despite legal mandates and repeated audits, these agencies continue to fail in securing sensitive data, including personally identifiable information (PII) and national security secrets.
Main Findings
1. Persistent Cybersecurity Failures
- Seven out of eight agencies still fail to meet basic cybersecurity standards.
- The DHS was the only agency that implemented an effective cybersecurity program in 2020.
- Common issues include:
- Failure to protect PII adequately.
- Inadequate IT asset inventories.
- Delayed installation of security patches.
- Use of unsupported legacy systems, which are costly and insecure.
- Weaknesses in access management and multi-factor authentication.
- Inconsistent notification of cyber incidents to Congress.
2. Major Cyber Incidents
- SolarWinds attack (2020): Russian hackers exploited a supply chain vulnerability in SolarWinds software, infiltrating nine federal agencies, including DHS, State, Energy, and Treasury. The breach went undetected for nine months.
- Pulse Connect Secure breach (2021): Chinese hackers accessed multiple federal agencies through a vulnerability in the remote access product Pulse Connect Secure, bypassing authentication and accessing sensitive data.
- Overall increase in cyber incidents: The White House reported 30,819 information security incidents in 2020, an 8% increase from 2019.
3. Inspector General Ratings
- The average cybersecurity maturity rating for the eight agencies was C-.
- HUD, USDA, and HHS received C ratings.
- State, DOT, Education, and SSA received D ratings.
- DHS received a B rating, the highest among the agencies.
4. Systemic Issues
- No single point of accountability exists for federal cybersecurity, leading to a fragmented and inefficient approach.
- The Federal Government lacks a unified cybersecurity strategy, making it difficult to address the evolving threat landscape.
- The DHS Inspector General failed to submit its annual evaluation to Congress in 2020, unlike other agencies.
- Legacy systems remain a critical vulnerability, with seven agencies still operating unsupported IT systems.
5. Inadequate Implementation of Cybersecurity Programs
- The EINSTEIN program, a flagship cybersecurity initiative by DHS, has significant limitations in detecting and preventing intrusions.
- HHS has not fully implemented EINSTEIN and the Continuous Diagnostics and Mitigation (CDM) program, despite legal requirements.
- SSA failed to implement key requirements from the Federal Cybersecurity Enhancement Act of 2015.
Key Recommendations
1. Risk-Based Budgeting
- The Office of Management and Budget (OMB) should require federal agencies to adopt a risk-based budgeting model for IT investments to prioritize spending on vulnerabilities most likely to be exploited.
2. Centralized Cybersecurity Coordination
- A centrally coordinated approach should be established to ensure accountability and consistency in government-wide cybersecurity efforts.
3. Enhancement of Shared Services
- CISA's Cybersecurity Quality Services Management Office should expand shared services offerings, particularly in endpoint detection and operational effectiveness of EINSTEIN.
4. Modernization of EINSTEIN
- DHS should provide Congress with a plan to modernize the EINSTEIN program and justify its cost.
5. Update FISMA Metrics
- The annual FISMA reporting metrics should be updated to prioritize risk-based indicators that reflect the maturity of an agency's cybersecurity program.
6. Legislative Reforms
- Congress should update the Federal Information Security Modernization Act (FISMA) of 2014:
- To reflect current best practices.
- To formalize CISA’s role as the operational lead for federal cybersecurity.
- To require notification of certain cyber incidents to CISA.
- To define "major incident" more clearly for timely reporting to Congress.
Background
1. FISMA and Cybersecurity Legislation
- FISMA (Federal Information Security Management Act) was enacted in 2002 to establish permanent legal requirements for federal agency cybersecurity.
- It was updated in 2014 by the Federal Information Security Modernization Act, which aimed to modernize cybersecurity practices and improve coordination between agencies.
- FISMA mandates annual independent evaluations of agency cybersecurity programs and requires compliance with minimum management controls.
2. NIST Cybersecurity Framework
- The NIST Cybersecurity Framework, updated in 2018, provides a risk-based approach to managing cybersecurity risk.
- It includes five functions: Identify, Protect, Detect, Respond, and Recover.
- DHS and OMB use these functions to align their FISMA metrics and evaluate agency performance.
Conclusion
Despite legal mandates and past reports highlighting significant weaknesses, the federal government’s cybersecurity posture remains fragile and inconsistent. With the increasing sophistication of cyber threats, the current system is inadequate to protect sensitive data. The report calls for comprehensive reforms, including better coordination, modernization of key programs, and updated legal frameworks, to ensure that federal data is adequately protected.
试读结束,高清完整版pdf/doc/ppt,请点下载