Risk
10/13/2011
01:34 PM
Connect Directly
RSS
E-Mail
50%
50%

GAO: U.S. Still Lags on Terrorism Info Sharing

New presidential order aims to shore up the government's intelligence Information Sharing Environment.

Inside DHS' Classified Cyber-Coordination Headquarters
(click image for larger view)
Slideshow: Inside DHS' Classified Cyber-Coordination Headquarters
Despite making some significant progress in the last several years, the federal government still lacks an efficient system for sharing terrorist intelligence information among agencies and other entities that need access to it, according to a government watchdog agency.

Since the Sept. 11 attacks the federal government has been working to improve how agencies share data collected about terrorist activities not only within the federal government but also with state, local, and tribal authorities, according to the Government Accountability Office (GAO).

While federal agencies--notably the Department of Homeland Security (DHS)--have made some progress to disseminate valuable intelligence information effectively, they still do "not yet have a fully functioning Information Sharing Environment (ISE) in place," according to a GAO report released Wednesday.

Still, through its work to date on the ISE, the feds have developed data standards for sharing national security-related information, and, according to a presidential executive order handed down last week, the ISE is about to have an even higher profile.

[The feds are taking a new approach to fighting national security threats. Learn more: Homeland Security Revamps Cyber Arm.]

The order mandates that the ISE will play a coordinating role across new interagency governing bodies that have been created to oversee the cybersecurity of information on classified networks. Those new organizations include the Classified Information Sharing and Safeguarding Office, the Senior Information Sharing and Safeguarding Steering Committee, and the interagency Insider Threat Task Force.

The ISE and other priority programs for information sharing were developed based on recommendations made by the GAO in 2008. Other efforts include the DHS' creation of a national, integrated network of fusion centers and the implementation of a system for state and local partners to report suspicious activity, according to the GAO.

While there has been progress made on multiple fronts, some of those efforts still face challenges that jeopardize their effectiveness, according to the GAO.

For example, the DHS fusion centers, which coordinate counterterrorist information and data collected by both government agencies and private companies, face budgetary concerns that threaten their ability to sustain and expand operations over the long term, according to the GAO.

Federal agencies plan to conduct annual assessments of the centers' capabilities and develop performance metrics by the end of the year. The assessment will help determine the centers' overall value to the ISE to help clarify their role going forward, according to the GAO.

Rather than make new recommendations to agencies in the report to improve the posture of the ISE, the GAO is advising the federal government to continue work already started based on past advice. "Full implementation of the recommendations is needed," the GAO said.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4734
Published: 2014-07-21
Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.

CVE-2014-4960
Published: 2014-07-21
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.

CVE-2014-5016
Published: 2014-07-21
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to appl...

CVE-2014-5017
Published: 2014-07-21
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter...

CVE-2014-5018
Published: 2014-07-21
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Where do information security startups come from? More important, how can I tell a good one from a flash in the pan? Learn how to separate ITSec wheat from chaff in this episode.