![]() ![]() The ESN project was the response and it was brought in under budget and on schedule. The FCC situation began with the 2011 discovery of a breach during an upgrade of the commission’s security and monitoring systems. Administrators aren’t crazy about it either and would gladly change things if they had the budget, time and resources they need. Maybe they can go back and fix it properly later - after putting out the next fire. Duct tape isn’t pretty, but admins do what they have to do to keep things running. Results often are hard to quantify and measure, so adherence to process can the best way to tell if requirements have been met.īut the guys on the front lines spend a lot of time putting out fires and patching things, with little time for paperwork. Process and documentation are important because they help ensure repeatability of results and keep everyone on the same page while doing a job. Auditors evaluate how something is done rather than what is accomplished. The conflict is an old one and has implications for IT security. The case is a good example of the conflict between the requirements of auditors who evaluate regulatory compliance and the demands on frontline administrators who must deal with real-world threats while keeping systems running. ![]() ![]() The Government Accountability Office said that the security of the commission’s Enhanced Secured Network was compromised because the FCC did not implement appropriate security controls and follow proper procedures in project development and deployment.īut FCC countered that the ESN was an emergency response, “designed to avoid an increase in security risks posed by delays in implementation,” and that even with cutting corners, “the FCC’s network is stronger, better, and more secure than it was before the commission started these upgrade efforts.” The Federal Communications Commission was dinged in a recent audit for cutting corners while upgrading network security in response to a breach. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. Archives
March 2023
Categories |