08.11.2012 Views

Evaluation of Department of State Information Security Program ...

Evaluation of Department of State Information Security Program ...

Evaluation of Department of State Information Security Program ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

UNCLASSIFIED<br />

patches within required timeframes and enabling mandatory security settings from the<br />

Bureau <strong>of</strong> Diplomatic <strong>Security</strong> (DS) Configuration Guidelines.<br />

C. <strong>Security</strong> Awareness and Role-Based Training<br />

The <strong>Department</strong> needs to improve its process and procedures for general information<br />

security awareness and role-based training. The <strong>Department</strong> is not tracking and<br />

documenting Significant <strong>Security</strong> Responsibilities (SSR) training attendance. The<br />

evaluation found that nine <strong>of</strong> 30 employees and contractors hired during FY 2011 had<br />

not taken the PS800 training (general security awareness training) within 10 days after<br />

being hired. Additionally, five <strong>of</strong> 30 <strong>Department</strong> information system users had not<br />

taken the annual PS800 training.<br />

D. Plans <strong>of</strong> Action and Milestones<br />

The <strong>Department</strong>’s Plans <strong>of</strong> Actions and Milestones (POA&M) process had not been<br />

fully and effectively implemented, and the program is not compliant with FISMA and<br />

OMB requirements. The <strong>Department</strong> had not implemented a POA&M process to<br />

address and resolve security weaknesses identified on the ClassNet GSS. In addition,<br />

the evaluation found the <strong>Department</strong> had not implemented effective corrective actions<br />

to address the POA&M control weaknesses within the OpenNet GSS identified in the<br />

FY 2010 FISMA report on the <strong>Department</strong>’s information security program.<br />

E. Account and Identity Management <strong>Program</strong><br />

The <strong>Department</strong> needs to improve account management processes in Active Directory 2<br />

(AD) for OpenNet and ClassNet. From a population <strong>of</strong> approximately 128,000<br />

OpenNet Active Directory user accounts, we identified approximately 400 guest, test,<br />

and temporary accounts; 9,000 accounts that had not been used (never logged on); 400<br />

accounts with passwords set “not to expire”; and 300 Install Accounts. 3 Then, from a<br />

population <strong>of</strong> approximately 36,000 ClassNet AD accounts, we identified<br />

approximately 200 guest, test, and temporary accounts; 4,000 accounts that had not<br />

been used (never logged on); 900 accounts with passwords set “not to expire”; and 200<br />

s<strong>of</strong>tware installation accounts (Install Accounts).<br />

F. User Provisioning Process<br />

The <strong>Department</strong>’s user provisioning process for creating, modifying, and disabling<br />

users’ accounts is not in compliance with the <strong>Department</strong>’s Foreign Affairs Manual<br />

(FAM). The <strong>Department</strong> did not require two <strong>of</strong> 25 ClassNet Domain Administrators’<br />

accounts to have individual user accounts, which may result in Domain<br />

Administrators’ accounts being used for non-administrator functions and susceptible to<br />

cyber attacks. The <strong>Department</strong> had not removed in a timely manner 294 <strong>of</strong> 894<br />

2 Active Directory is a technology created by Micros<strong>of</strong>t that provides a variety <strong>of</strong> network services such as<br />

identification and authentication, directory access, and other network services.<br />

3 Install accounts are those accounts created for <strong>Department</strong> <strong>of</strong> <strong>State</strong> personnel to install s<strong>of</strong>tware within the different<br />

domains (for the bureaus and <strong>of</strong>fices).<br />

2<br />

UNCLASSIFIED

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!