Risk
10/13/2011
01:34 PM
Connect Directly
RSS
E-Mail
50%
50%

GAO: U.S. Still Lags on Terrorism Info Sharing

New presidential order aims to shore up the government's intelligence Information Sharing Environment.

Inside DHS' Classified Cyber-Coordination Headquarters
(click image for larger view)
Slideshow: Inside DHS' Classified Cyber-Coordination Headquarters
Despite making some significant progress in the last several years, the federal government still lacks an efficient system for sharing terrorist intelligence information among agencies and other entities that need access to it, according to a government watchdog agency.

Since the Sept. 11 attacks the federal government has been working to improve how agencies share data collected about terrorist activities not only within the federal government but also with state, local, and tribal authorities, according to the Government Accountability Office (GAO).

While federal agencies--notably the Department of Homeland Security (DHS)--have made some progress to disseminate valuable intelligence information effectively, they still do "not yet have a fully functioning Information Sharing Environment (ISE) in place," according to a GAO report released Wednesday.

Still, through its work to date on the ISE, the feds have developed data standards for sharing national security-related information, and, according to a presidential executive order handed down last week, the ISE is about to have an even higher profile.

[The feds are taking a new approach to fighting national security threats. Learn more: Homeland Security Revamps Cyber Arm.]

The order mandates that the ISE will play a coordinating role across new interagency governing bodies that have been created to oversee the cybersecurity of information on classified networks. Those new organizations include the Classified Information Sharing and Safeguarding Office, the Senior Information Sharing and Safeguarding Steering Committee, and the interagency Insider Threat Task Force.

The ISE and other priority programs for information sharing were developed based on recommendations made by the GAO in 2008. Other efforts include the DHS' creation of a national, integrated network of fusion centers and the implementation of a system for state and local partners to report suspicious activity, according to the GAO.

While there has been progress made on multiple fronts, some of those efforts still face challenges that jeopardize their effectiveness, according to the GAO.

For example, the DHS fusion centers, which coordinate counterterrorist information and data collected by both government agencies and private companies, face budgetary concerns that threaten their ability to sustain and expand operations over the long term, according to the GAO.

Federal agencies plan to conduct annual assessments of the centers' capabilities and develop performance metrics by the end of the year. The assessment will help determine the centers' overall value to the ISE to help clarify their role going forward, according to the GAO.

Rather than make new recommendations to agencies in the report to improve the posture of the ISE, the GAO is advising the federal government to continue work already started based on past advice. "Full implementation of the recommendations is needed," the GAO said.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6306
Published: 2014-08-22
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

CVE-2014-0232
Published: 2014-08-22
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1)...

CVE-2014-3525
Published: 2014-08-22
Unspecified vulnerability in Apache Traffic Server 4.2.1.1 and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

CVE-2014-3563
Published: 2014-08-22
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.

CVE-2014-3594
Published: 2014-08-22
Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.