NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Policy
Slice by Program

U.S. agency CIOs: IT security remains top concern

By: Grant Gross, IDG News Service (Washington Bureau)(02-28-2007)

IT security is at the top of the priority list for U.S. government chief information officers.

It's also an area where CIOs are making progress, according to a survey released Monday by the Information Technology Association of America.

CIOs told the ITAA, a trade group based in Arlington, Virginia, that they made progress in certifying their IT systems, training IT workers and other employees about cybersecurity, and setting up IT security policies during 2006, said Paul Wohlleben, a partner with Grant Thornton LLP's Global Public Sector, and chairman of ITAA's CIO survey project.

Even as multiple reports of missing government laptops and other devices containing personal information came to light last year, federal CIOs said they're making "incremental progress" toward achieving federal cybersecurity mandates, Wohlleben said.

CIOs, responding in face-to-face surveys during which they were promised anonymity, told ITAA they're also making progress integrating security into their information architecture, instead of "bolting on" security afterward, he said.

And CIOs said they've made progress implementing information privacy programs, although in many cases, the progress was simply getting a privacy program off the ground, Wohlleben said.

"Quite frankly, there's not a lot of maturity out there," he said of privacy programs. "For a lot of agencies, they're really taking credit for getting this started. Some things take quite a while to achieve in the federal space."

The survey, made up of 47 government CIOs or related officials, found some frustration with agency information security practices, Wohlleben said. Many CIOs said they don't have authority over personal inventory rules covering devices such as laptops, even though the high-profile breaches last year involved laptops, hard drives or other similar devices.

"There's a wide range of devices that are not even under the CIOs' control," he said.

In May, the U.S. Department of Veterans Affairs announced that a laptop and hard drive containing the personal information of 26.5 million military veterans and family members had been stolen from an employee's home. Police later recovered the hardware, but the theft set off a series of hearings in Congress about information security practices at the VA and other federal agencies.

Some CIOs talked about efforts to encrypt information on devices, and others talked about disabling devices such as flash drives, Wohlleben said.

"There's that tension between efficiency and security," he said. "All the CIOs are dealing with that every day."

In addition to lost devices, CIOs expressed concern about network intrusions, Wohlleben said. There's a fear of the unknown -- that they're "not in total or near-total control," he said.

Among other issues federal CIOs identified as top challenges this past year:

-- Enterprise management of IT: CIOs want to see better IT management processes and tools, and they see the need for better project management.

-- Enterprise applications: CIOs say that efforts to modernize application systems pose difficult challenges. Projects are complex, requiring improvement to project management and governance capabilities.

In addition to IT security, among the issues CIOs identified as achievements was consolidating IT infrastructure. CIOs reported progress in consolidating IT infrastructure into a common, centrally managed platform, ITAA said.

Related content:

US agency loses data containing 26 million IDs

Data theft could prompt US federal privacy law

Collaboration key to protecting government data

Data loss sweeping at US govt agencies, report says

Tale of the tape raises alarms

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Stalled PCI DSS compliance efforts put Canadian organizations in limbo: Hereb�s how to get back on track
You might have long ago abandoned your efforts to achieve full PCI DSS compliance, but herebs a report that offers some helpful ideas to get back on track again. It highlights the five bsticking pointsb that typically hinders PCI DSS compliance progress and suggests how to get unglued from the mess.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada