Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cybersecurity

    EPA Claims Vastly Improved Security

    Written by

    Matt Hines
    Published August 1, 2006
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Even with the renewed scrutiny being given to government IT systems in light of the recent laptop theft at the Department of Veterans Affairs, officials working with the Environmental Protection Agency say the organization has significantly improved its security operations.

      Guided by a seven-year contract granted to services provider Computer Sciences Corp. in 2002, the EPA maintains that it has applied a systemic approach to maturing its security operations, resulting in the agency being one of only five federal organizations that received a top ranking in a recent security scorecard issued by the House Committee on Government Reform.

      At the heart of the EPAs project has been an ongoing effort to come into compliance with the U.S. governments Federal Information Security Management Act, or FISMA, which requires executive agencies within the federal government to secure their IT systems. Passed by Congress in 2002, FISMA specifically demands that government organizations ensure that they have appropriate officials designated to oversee IT security and that those workers periodically review security controls for all information systems while enforcing user and device authentication.

      Under its deal with CSC, the EPA has outsourced its entire IT security operation to the service providers Raleigh, N.C., data center, including oversight of its WAN. The project directly handles security for 25,000 users in ten regions throughout the United States and also includes management by CSC of the EPAs data center, desktop management and call center operations, in addition to the security responsibilities.

      CSC officials say the company employed a strategic plan to help the EPA that included the completion of security gap analysis, followed by several major projects. That work included centralization of the agencys security incident response center, creation of a governance board to oversee and drive its technology decisions, and work to increase support for IT worker certification for development of security policy and architecture.

      By balancing its need to move quickly to improve security with a more comprehensive overall IT strategy, the EPA has been able to make strides that other, less-organized agencies have not, said John Kashishian, director of CSCs Network Information Assurance Solutions group.

      “The EPA has taken a consistent direction on security with a sense of urgency, but they also understand the systematic approach and how to best pace themselves, and budget, so theres never been a crisis throughout the project,” Kashishian said. “The main operational change theyve made is installing the security incident response center; that gives them the 24/7-type of protection that an organization of this size needs to respond to incidents and emerging threats.”

      While the EPA previously had a more de-centralized response system in place, having a single source of communications for security information throughout the agency has made a world of difference, according to CSC officials. When a virus outbreak or equipment theft challenges the organizations security, the EPA can respond much faster with the response center up and running, Kashishian said. Employing the center was also meant to improve the security of the information being handled by the IT group.

      In responding to the epidemic of stolen laptops in the federal sector and elsewhere, the executive said that the EPA has progressively improved encryption on all its mobile devices, and that the group is even considering a move to more thin-client systems to take data protection even further.

      /zimages/7/28571.gifGetting the right plan in place to deal with laptop thefts makes a world of difference, IT security experts say. Click here to read more.

      “Theres an operational balance that needs to be evaluated, they understand that mobility is key, but it all comes down to risk,” said CSCs Kashishian. “Were always looking to improve infrastructure and while were not in thin-client environment, the EPA is evaluating the pros and cons of moving toward a model where data is more centralized and people have fewer demands to carry the data in the device.”

      Among the security projects ongoing within the EPA is an increased emphasis on protecting systems from the so-called insider threat, or the notion of workers with legitimate IT privileges carrying out data theft or manipulation schemes. The agency will look to further improve its standing against such attacks by expanding its authentication systems and putting additional policies in place to govern the use of mobile devices, CSC officials said.

      /zimages/7/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      Matt Hines
      Matt Hines

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×