Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

5/17/2019
10:00 AM
Gus Hunt
Gus Hunt
Commentary
Connect Directly
LinkedIn
RSS
50%
50%

A Trustworthy Digital Foundation Is Essential to Digital Government

Agencies must take steps to ensure that citizens trust in the security of government's digital channels.

The age of digital government is upon us. Consider the following:

  • Roughly 92% of American taxpayers filed their tax returns electronically in 2017 — that adds up to more than 126 million Americans. These are impressive numbers considering that only 67% of taxpayers e-filed a decade ago and 31% in 2001.
  • More than 34 million Americans conduct their business with the Social Security Administration online.
  • About 8.5 million people enrolled in individual health plans for 2019 through the HealthCare.gov website.
  • More than 702,000 patients received healthcare through Veterans Affairs Department telehealth programs in 2016. That number appears to be rising steadily.
  • Grants.gov processes roughly a quarter-million federal grant submissions to distribute more than $100 billion in grants annually.
  • The US Census will conduct its first online decennial census next year. The outcome will be used to reapportion representation in Congress and distribute more than $675 billion per year in federal funds to support schools, hospitals, roads, public works, and other vital programs.

It's clear that we finally have a digital government, and the government will continue to increase its use of digital services. Therefore, agencies must take steps to ensure that citizens' trust and confidence in the security and reliability of those digital channels is high. 

However, surveys show that the public remains skeptical. A 2017 survey by the Pew Research Center showed that half of the respondents lacked confidence in the federal government's ability to protect their data. So, although millions of Americans are conducting online transactions with the government every day, many are still uneasy about it.  

Even CEOs are concerned. According to an Accenture survey, 90% say a trustworthy digital economy is critical to their organization's future growth, but only 30% are very confident in the security of the Internet. And this is forecast to decline to 25% slowly over the next five years.

As a nation, we are investing billions of modernization dollars to deliver and execute more government services digitally. We must be sure that these digital services are resilient, enabling trust, by building security into those services from the ground up. Citizens must trust that their digital interactions with government are secure, safe, and authentic. Without that trust, basic government functions will be questioned, and the effectiveness and efficiencies that modern, digital capabilities promise to deliver will be put at risk.

The following steps can help ensure that federal IT modernization efforts result in platforms and systems that are highly secure and resilient to cyberattacks:

  • Bake security into the design, architecture, and application of modernization efforts.
  • Design assets to be cyber resilient and therefore difficult to attack, minimizing the impact and potential loss when an event happens and continuously delivering the intended capability — no matter what.
  • Leverage software-defined networking, which makes network pathways harder to find and attack.

Another important consideration is the governance, strategies, operating models, and policies that drive our cyber behaviors and activities. Some of those include:

  • Providing governance and standards for the global community's approaches and responses to security threats.
  • Establishing minimum security standards for Internet of Things-related devices in the global marketplace.
  • Leading international conversations over how individuals, organizations, and nations should be expected to behave on the Internet and decide on the appropriate response protocols when codes of conduct are violated.

By pursuing and aligning the right investments, decisions, and actions today, federal leaders can not only better protect federal digital operations, they can also help drive a trust turnaround for American citizens that will power the next phase of digital government.

Related Content:

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Gus Hunt is Managing Director and Cyber Strategy Lead for Accenture Federal Services. He is responsible for developing differentiated approaches to dealing with the cyber threat environment and growing AFS's cyber practice. Before joining AFS, Hunt was chief architect and the ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
dearsudamasir102050
0%
100%
dearsudamasir102050,
User Rank: Apprentice
6/16/2019 | 1:15:20 AM
happy fourth of july
this is awesome to come here and take benifits of you

 

 

 
Can Your Patching Strategy Keep Up with the Demands of Open Source?
Tim Mackey, Principal Security Strategist, CyRC, at Synopsys,  6/18/2019
Florida Town Pays $600K to Ransomware Operators
Curtis Franklin Jr., Senior Editor at Dark Reading,  6/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-12936
PUBLISHED: 2019-06-23
BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions.
CVE-2019-12937
PUBLISHED: 2019-06-23
apps/gsudo.c in gsudo in ToaruOS through 1.10.9 has a buffer overflow allowing local privilege escalation to the root user via the DISPLAY environment variable.
CVE-2019-12935
PUBLISHED: 2019-06-23
Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
CVE-2019-12933
PUBLISHED: 2019-06-22
An XSS issue on the PIX-Link Repeater/Router LV-WR09 with firmware v28K.MiniRouter.20180616 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID.
CVE-2019-10028
PUBLISHED: 2019-06-21
Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019.