MAY 24, 2010 4:58am ET

Related Links

New Product News – May 17, 2013
May 16, 2013
8 Risks Inherent to All Organizations
May 14, 2013
Second World Risk Day Takes a Project-Minded Path
May 9, 2013

Web Seminars

Data Protection in the Cloud: What You Need to Know About Security and Compliance—Right Now
Available On Demand

GAO: Security at VA Remains Weak

Print
Reprints
Email

The Department of Veterans Affairs was deficient in each of five major categories of information security controls in 2006 and remains so today, according to the Government Accountability Office, an investigative arm of Congress.

The five categories are access control, configuration management, segregation of duties, contingency planning and security management.

"Further, in VA's fiscal year 2009 performance and accountability report, the independent auditor stated that, while VA continued to make progress, I.T. security and control weaknesses remained pervasive and continued to place VA's program and financial data at risk," according to testimony GAO officials delivered on May 19 to the oversight subcommittee of the House Committee on Veterans Affairs.

Where there has been progress on security issues there also has been backsliding, according to the GAO. The department in recent years has significantly increased its contingency plan testing, while at the same time the percentage of employees receiving security awareness training has decreased.

Until VA fully and effectively implements a comprehensive information security program and fixes known vulnerabilities, its computer systems--and sensitive information on veterans and beneficiaries--will remain at increased risk, the GAO concludes.

The testimony, "Veterans Affairs Needs to Resolve Long-Standing Weaknesses," is available at gao.gov.

This article can also be found at HealthDataManagement.com.

Joseph Goedert is news editor at Health Data Management.

Filed under:

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.

Where do young IT professionals (30 and under) obtain information to aid with daily role responsibilities and career development?

Trade publication websites 14%
Social media 23%
Vendor websites 4%
Vendor/community forums 7%
Newsletters 1%
Trade conferences/meetups 2%
RSS feeds 6%
Web search 44%

 

Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.