{"id":40996,"date":"2014-03-28T09:32:21","date_gmt":"2014-03-28T13:32:21","guid":{"rendered":"http:\/\/valorguardians.com\/blog\/?p=40996"},"modified":"2014-03-28T09:46:49","modified_gmt":"2014-03-28T13:46:49","slug":"gao-report-va-should-improve-their-information-security","status":"publish","type":"post","link":"https:\/\/www.azuse.cloud\/?p=40996","title":{"rendered":"GAO report; VA should improve their information security"},"content":{"rendered":"<p><center><a href=\"https:\/\/www.azuse.cloud\/?attachment_id=40997\" rel=\"attachment wp-att-40997\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.azuse.cloud\/wp-content\/uploads\/2014\/03\/Veterans-Affairs2.jpg\" alt=\"Veterans-Affairs2\" width=\"259\" height=\"195\" class=\"alignnone size-full wp-image-40997\" \/><\/a><br \/>\n<\/center><\/p>\n<p>Yeah, I know, you&#8217;re grasping for your chair right now so you don&#8217;t fall out of it from the shock. The <a href=\"http:\/\/www.govinfosecurity.com\/report-va-needs-to-improve-infosec-a-6680\">Government Accountability Office conducted<\/a> a study which led them to conclude that the Department of Veterans&#8217; Affairs should really do more to protect veterans&#8217; personal information. I could have saved them some money;<\/p>\n<blockquote><p>The GAO report was released in conjunction with testimony provided by Gregory Wilshusen, GAO director of information security issues, during a March 25 hearing of the House Committee on Veterans Affairs&#8217; Subcommittee on Oversight and Investigations. The panel is considering draft legislation aimed at improving the VA&#8217;s information security.<\/p>\n<p>&#8220;Information security remains a long-standing challenge for the department,&#8221; Wilshusen said in his written testimony. &#8220;Specifically, VA has consistently had weaknesses in major information security control areas. For fiscal years 2007 through 2013, deficiencies were reported in each of the five major categories of information security controls as defined in our Federal Information System Controls Audit Manual.&#8221;<\/p>\n<p>VA information security control areas that have ongoing weaknesses include access control, configuration management, segregation of duties, contingency planning and security management, according to the GAO report.<\/p><\/blockquote>\n<p>So, Congress is drafting a bill. Because the VA can&#8217;t tighten their security on their own, apparently, they need Congress to tell them to do something that they should have been doing all along. Things like not allowing employees to leave their laptops unattended in their privately-owned vehicles where the computers can be stolen, along with the PII of millions of veterans. In downtown DC. Who could have seen that coming? Obviously, not the VA, at least not without a Congressional mandate.<\/p>\n<p>So, what, exactly, does the Veterans&#8217; Affairs Department do right? How long before the country comes to the realization that it&#8217;s a leadership  issue? The VA serves the VA, not veterans.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Yeah, I know, you&#8217;re grasping for your chair right now so you don&#8217;t fall out of &hellip; <a title=\"GAO report; VA should improve their information security\" class=\"hm-read-more\" href=\"https:\/\/www.azuse.cloud\/?p=40996\"><span class=\"screen-reader-text\">GAO report; VA should improve their information security<\/span>Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[143],"tags":[],"class_list":["post-40996","post","type-post","status-publish","format-standard","hentry","category-veterans-affairs-department"],"_links":{"self":[{"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/posts\/40996","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=40996"}],"version-history":[{"count":0,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/posts\/40996\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=40996"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=40996"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=40996"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}