{"id":1805,"date":"2023-09-29T17:03:04","date_gmt":"2023-09-29T17:03:04","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud\/cybersecurity-gaps-plague-state-department-gao-report"},"modified":"2023-09-29T17:03:04","modified_gmt":"2023-09-29T17:03:04","slug":"cybersecurity-gaps-plague-us-state-department-gao-report-warns","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/09\/29\/cybersecurity-gaps-plague-us-state-department-gao-report-warns\/","title":{"rendered":"Cybersecurity Gaps Plague US State Department, GAO Report Warns"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.png?w=640&#038;ssl=1\"><\/p>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p>The US Department of State must fully implement its cybersecurity risk program and take additional steps to better protect its IT network and systems, a 92-page <a href=\"https:\/\/www.gao.gov\/assets\/gao-23-107012.pdf\" target=\"_blank\" rel=\"noopener\">report by the General Accounting Office (GAO)<\/a> warns.<\/p>\n<p>The State Department has completed the authorization process for less than half (44%) its nearly 500 information systems, and has yet to implement a department-wide continuous monitoring system.<\/p>\n<p>On the positive side, the department has identified risk management roles and responsibilities and developed a cyber risk management strategy.<\/p>\n<p>However, &#8220;until the department implements required risk management activities, it lacks assurance that its security controls are operating as intended,&#8221; the report noted. &#8220;Moreover, State is likely not fully aware of information security vulnerabilities and threats affecting mission operations.&#8221;<\/p>\n<p>And those threats are likely myriad.<\/p>\n<h2 class=\"regular-text\">State Dept. Faces Rafts of Outstanding Cyber To-Dos<\/h2>\n<p>The report, which forms part of the GAO&#8217;s extensive work on the US government&#8217;s cybersecurity and information security challenges, tallied 15 recommendations for executive actions that remain outstanding.<\/p>\n<p>First and foremost among them is the recommendation that the State Department instruct the CIO to develop and maintain a department-wide risk profile prioritizing the department&#8217;s most significant risks.<\/p>\n<p>Following that, the State Department must develop plans to mitigate the vulnerabilities tallied by the CIO, and then conduct bureau-level risk assessments for the 28 bureaus that owned information systems the GAO reviewed.<\/p>\n<p>The report noted the department also faces challenges in implementing its incident response program, updating and testing information system contingency plans, and configuring its inventory database properly.<\/p>\n<p>An improvement of the overall IT infrastructure security is essential, including replacing outdated hardware and software installations, some of which have been in use for more than 13 years.<\/p>\n<p>&#8220;This includes replacing the 23,689 hardware systems and 3,102 occurrences of network and server operating system software installations,&#8221; the report noted.<\/p>\n<p>The State Department&#8217;s CIO also faces limitations in securing IT systems due to shared management responsibilities and poor communication, the report added.<\/p>\n<p>While the CIO oversees the main network and sets standards, individual bureaus handle many tasks independently, including equipment purchases, IT system management, and funding.<\/p>\n<p>The report concluded this lack of coordination also leads to confusion among information system security officers regarding requirements.<\/p>\n<p>These deficiencies are largely a result of the department&#8217;s isolated culture and inadequate communication between the CIO and the individual bureaus.<\/p>\n<p>&#8220;Until State addresses these and other deficiencies, the CIO faces challenges managing and overseeing the department&#8217;s cybersecurity program, including risk management and incident response, and the department&#8217;s systems remain vulnerable,&#8221; the report warned.<\/p>\n<p>Meanwhile, a looming shutdown of the federal government threatens to cause additional cybersecurity complications across a host of agencies and departments, with the CISA stating it would <a href=\"https:\/\/www.darkreading.com\/cloud\/government-shutdown-poised-to-stress-nation-s-cybersecurity-supply-chain\" target=\"_blank\" rel=\"noopener\">furlough more than 80% of staff indefinitely<\/a> if Congress can&#8217;t reach an agreement to fund the federal government.<\/p>\n<h2 class=\"regular-text\">Infrastructure at Risk From Foreign Threats<\/h2>\n<p>The report follows the successful attack of 25 US government agencies by <span>Chinese hackers<\/span> \u2014 including the State Department \u2014 in May, resulting in the <a href=\"https:\/\/www.darkreading.com\/cloud\/microsoft-365-breach-risk-widens-millions-of-azure-ad-apps\" target=\"_blank\" rel=\"noopener\">theft of 60,000 emails<\/a> from senior officials.<\/p>\n<p>In the email breach, a stolen Microsoft account (MSA) key allowed the Storm-0558 APT to forge authentication tokens to masquerade as authorized <a href=\"https:\/\/www.darkreading.com\/cloud\/azure-ad-log-in-with-microsoft-authentication-bypass-affects-thousands\" target=\"_blank\" rel=\"noopener\">Azure Active Directory (AD) users<\/a>, obtaining access to Microsoft 365 enterprise email accounts and the potentially sensitive information contained within.<\/p>\n<p>In April 2022, the State Department announced the creation of a <a href=\"https:\/\/www.darkreading.com\/risk\/state-department-announces-bureau-of-cyberspace-and-digital-policy\" target=\"_blank\" rel=\"noopener\">Bureau of Cyberspace and Digital Policy<\/a> to help shape norms of responsible government behavior in cyberspace and help US allies bolster their own cybersecurity programs, reflecting the growing importance of cybersecurity in national policy, economy, and defense.<\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud\/cybersecurity-gaps-plague-state-department-gao-report\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The US Department of State must fully implement its cybersecurity<\/p>\n","protected":false},"author":12,"featured_media":1806,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-1805","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.png?fit=435%2C410&ssl=1",435,410,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.png?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.png?fit=300%2C283&ssl=1",300,283,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.png?fit=435%2C410&ssl=1",435,410,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.png?fit=435%2C410&ssl=1",435,410,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.png?fit=435%2C410&ssl=1",435,410,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.png?fit=435%2C410&ssl=1",435,410,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.png?fit=435%2C410&ssl=1",435,410,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.png?resize=435%2C410&ssl=1",435,410,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.png?resize=435%2C410&ssl=1",435,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/cybersecurity-gaps-plague-us-state-department-gao-report-warns.png?fit=435%2C410&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1805","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=1805"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1805\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/1806"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=1805"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=1805"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=1805"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}