Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • IT Management

    How to Protect Privileged Access to Critical Government Systems

    Written by

    Robert Grapes
    Published June 17, 2009
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Despite being saddled with significant economic concerns, President Obama-recognizing the significant importance of cyber-security to the nation-ordered a 60-day review of United States information security and the systems that support Critical Infrastructure Protection (CIP)-or in this case, cyber CIP. This call to action recognizes that a failure to implement proper security measures can facilitate internal and external threats to the confidentiality, integrity and availability of the nation’s critical infrastructure.

      In January 2009, the U.S. Government Accountability Office (GAO) published the GAO-09-271 update to their High-Risk Series report, which outlines federal information and cyber CIP concerns. The report stated that protecting the federal government’s information systems and the nation’s critical infrastructure is a topline challenge, but this requires resolving deficiencies that have not yet been broadly identified.

      The report also stated the importance of fully implementing effective security programs. The following challenges are too important to go unaddressed:

      Challenge No. 1: Cyber-security as top-level priority

      Earning cross-agency buy-in is critical for managing threats effectively, and for ensuring centralized and controlled access to vital information and systems.

      Challenge No. 2: Establishing and implementing consistent security initiatives

      Mandating policies can be a complex and daunting task, but with insufficient processes in place to enable full accountability, agencies become susceptible to internal and external threats.

      Challenge No. 3: Preventing system disruption

      Dynamic and complex technology environments-including virtualized, cloud computing or service-oriented infrastructures-make managing information access extremely difficult, requiring flexible controls and solutions to adapt and prevent interruptions (or worse).

      Challenge No. 4: Improving warning capabilities

      Access to critical information assets must be monitored and managed intensively in all facets of the organization. Implementing proactive warning systems can circumvent critical incidents, limiting exposure to agency credentials and vital information that can open the agency to extreme governance risks (both inside and outside its walls).

      Challenge No. 5: Strengthening incident recovery

      While mitigating occurrences is the first line of defense, the ability to recover from incidents quickly without exposing critical information and access needs to be improved upon. When events do arise, privileged information and access are compromised without a disaster recovery plan in place.

      Government agencies by their very nature must be unfailingly vigilant in trusting secure information to external and internal resources-if only because the information they control can financially, legally or even physically endanger the public’s well-being if it falls into the wrong hands.

      How to Protect Vital Information

      How to protect vital information

      By taking the following three simple steps, federal agencies can employ a proactive approach to prevent breaches and protect vital information assets-avoiding the devastation and havoc that even one rogue person can inflict. The three steps are:

      Step No. 1: Know who has access to privileged information

      Federal agencies must assess who has access to what data, enabling them to understand and manage access as appropriate.

      Step No. 2: Apply appropriate policies to protect sensitive information

      Federal agencies must create an actionable plan and put it into place, applying privileged passwords and access management controls throughout each level of information.

      Step No. 3: Update security and access credentials regularly to monitor and maintain control

      By implementing a regimented program to automatically update access management and passwords, federal agencies will ensure that the right people have the right amount of control over vital information.

      In conclusion, by taking the necessary steps to address these security challenges, federal agencies will be positioned for better governance, less risk and greater compliance. This will ultimately serve to protect the public’s trust and keep national security risks at bay.

      Robert Grapes is Chief Technologist at Cloakware. Robert has more than 17 years of professional experience in the technology sector. Prior to joining Cloakware in 2004, Robert spent many years with Entrust Technologies as a software toolkit product manager, with Cognos in vertical analyst relations and with Allen-Bradley as a control systems automation developer. Robert’s expertise on enterprise security and Governance, Risk Management and Compliance (GRC) has enabled many large government and financial service organizations to meet their audit requirements for PCI-DSS, FISMA, FERC and other regulations, while reducing risk and improving operational efficiency. He can be reached at robert.grapes@cloakware.com.

      Robert Grapes
      Robert Grapes
      Robert Grapes is Chief Technologist at Cloakware. Robert has more than 17 years of professional experience in the technology sector. Prior to joining Cloakware in 2004, Robert worked at Entrust Technologies as a software toolkit product manager, at Cognos in vertical analyst relations, and at Allen-Bradley as a control systems automation developer. Robert's expertise on enterprise security and Governance, Risk Management and Compliance (GRC) has enabled many government and financial service organizations to meet their audit requirements for PCI-DSS, FISMA, FERC and other regulations.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×