site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies


kvn864

join:2001-12-18
Glendale, AZ
kudos:1

reply to FF4m3

Re: Confirmed: Anonymous Hacked The Federal Reserve

This quickly gets annoying. I just can’t believe the government agencies have no power to stop/prevent such an event.


DigitalXeron
There is a lack of sanity

join:2003-12-17
Hamilton, ON

3 edits

said by kvn864:

This quickly gets annoying. I just can’t believe the government agencies have no power to stop/prevent such an event.

It's not as much that they don't have the power, it is that implementing BCPs (Best Current Practices) on security is often deemed by management as "too expensive", "unneeded" or "too many resources", "too restrictive/cumbersome" among other excuses.

For these agencies to implement BCPs, there would be a requirement to lose some of the convenience for both their employees and management themselves. For instance among the conveniences that would be lost: being able to carry unencrypted data or the like on storage devices, laptops and so forth (User excuse: "Encryption is too hard") or to be able to carry that data off site in the first place to work on it at home (Management Excuse: "Staff need to be able to finish their work to remain productive"), staff bringing personal devices onto the agency network (User excuse: "I need to be in constant contact with my contacts to be able to deal with issues quickly") or the like.

The problem is that at the end of the day, the government agencies themselves are not held accountable and make the illusion that every successful breach is by someone who was too good for their defences and the only recourse is to send law enforcement after them. Meanwhile internal operating procedures don't change (despite claims that they do) and the same sort of breaches happen again and again.

There is an underlying political issue to all of this that is outside of the scope of operational information security (and is more of a law/policy/governmental structure issue), but suffice it to say: US Government agencies are run much like corporations: There can never be fault with them, it's always someone else's fault that the attacks are successful, even if they can be guarded against.
--
--Kradorex Xeron
[an error occurred while processing this signature]

Friday, 24-May 17:33:47 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics