Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

5/17/2019
10:00 AM
Gus Hunt
Gus Hunt
Commentary
Connect Directly
LinkedIn
RSS
50%
50%

A Trustworthy Digital Foundation Is Essential to Digital Government

Agencies must take steps to ensure that citizens trust in the security of government's digital channels.

The age of digital government is upon us. Consider the following:

  • Roughly 92% of American taxpayers filed their tax returns electronically in 2017 — that adds up to more than 126 million Americans. These are impressive numbers considering that only 67% of taxpayers e-filed a decade ago and 31% in 2001.
  • More than 34 million Americans conduct their business with the Social Security Administration online.
  • About 8.5 million people enrolled in individual health plans for 2019 through the HealthCare.gov website.
  • More than 702,000 patients received healthcare through Veterans Affairs Department telehealth programs in 2016. That number appears to be rising steadily.
  • Grants.gov processes roughly a quarter-million federal grant submissions to distribute more than $100 billion in grants annually.
  • The US Census will conduct its first online decennial census next year. The outcome will be used to reapportion representation in Congress and distribute more than $675 billion per year in federal funds to support schools, hospitals, roads, public works, and other vital programs.

It's clear that we finally have a digital government, and the government will continue to increase its use of digital services. Therefore, agencies must take steps to ensure that citizens' trust and confidence in the security and reliability of those digital channels is high. 

However, surveys show that the public remains skeptical. A 2017 survey by the Pew Research Center showed that half of the respondents lacked confidence in the federal government's ability to protect their data. So, although millions of Americans are conducting online transactions with the government every day, many are still uneasy about it.  

Even CEOs are concerned. According to an Accenture survey, 90% say a trustworthy digital economy is critical to their organization's future growth, but only 30% are very confident in the security of the Internet. And this is forecast to decline to 25% slowly over the next five years.

As a nation, we are investing billions of modernization dollars to deliver and execute more government services digitally. We must be sure that these digital services are resilient, enabling trust, by building security into those services from the ground up. Citizens must trust that their digital interactions with government are secure, safe, and authentic. Without that trust, basic government functions will be questioned, and the effectiveness and efficiencies that modern, digital capabilities promise to deliver will be put at risk.

The following steps can help ensure that federal IT modernization efforts result in platforms and systems that are highly secure and resilient to cyberattacks:

  • Bake security into the design, architecture, and application of modernization efforts.
  • Design assets to be cyber resilient and therefore difficult to attack, minimizing the impact and potential loss when an event happens and continuously delivering the intended capability — no matter what.
  • Leverage software-defined networking, which makes network pathways harder to find and attack.

Another important consideration is the governance, strategies, operating models, and policies that drive our cyber behaviors and activities. Some of those include:

  • Providing governance and standards for the global community's approaches and responses to security threats.
  • Establishing minimum security standards for Internet of Things-related devices in the global marketplace.
  • Leading international conversations over how individuals, organizations, and nations should be expected to behave on the Internet and decide on the appropriate response protocols when codes of conduct are violated.

By pursuing and aligning the right investments, decisions, and actions today, federal leaders can not only better protect federal digital operations, they can also help drive a trust turnaround for American citizens that will power the next phase of digital government.

Related Content:

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Gus Hunt is Managing Director and Cyber Strategy Lead for Accenture Federal Services. He is responsible for developing differentiated approaches to dealing with the cyber threat environment and growing AFS's cyber practice. Before joining AFS, Hunt was chief architect and the ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
dearsudamasir102050
0%
100%
dearsudamasir102050,
User Rank: Apprentice
6/16/2019 | 1:15:20 AM
happy fourth of july
this is awesome to come here and take benifits of you

 

 

 
COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/30/2020
'Act of War' Clause Could Nix Cyber Insurance Payouts
Robert Lemos, Contributing Writer,  10/29/2020
6 Ways Passwords Fail Basic Security Tests
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/28/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How to Measure and Reduce Cybersecurity Risk in Your Organization
In this Tech Digest, we examine the difficult practice of measuring cyber-risk that has long been an elusive target for enterprises. Download it today!
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5425
PUBLISHED: 2020-10-31
Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the SSO operator dashboard at the same time, with the same username, from two different identity provider...
CVE-2020-15703
PUBLISHED: 2020-10-31
There is no input validation on the Locale property in an apt transaction. An unprivileged user can supply a full path to a writable directory, which lets aptd read a file as root. Having a symlink in place results in an error message if the file exists, and no error otherwise. This way an unprivile...
CVE-2020-5991
PUBLISHED: 2020-10-30
NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bounds read or write operation may lead to code execution, denial of service, or information disclosure.
CVE-2020-15273
PUBLISHED: 2020-10-30
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. The issue affects the following components: Edit feed settings, Edit widget area, Sub site new registration, New category registration. Arbitrary JavaScript may be executed by entering specific characters in the account that can ac...
CVE-2020-15276
PUBLISHED: 2020-10-30
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.