TOPICS
TOPICS
GAO hacks Army Corps computer system
The U.S. Army Corps of Engineers' core financial computer system is full of computer security holes, making sensitive financial data vulnerable to hackers, a new General Accounting Office study says.
The Corps' key financial system processes military engineering, construction, civil works and real estate projects. According to GAO, users with valid access, as well as hackers, could change or alter information and disclose or destroy sensitive financial data, including social security numbers and other personal information stored in the system.
GAO hired a contractor, PricewaterhouseCoopers, to test the system's vulnerabilities. The firm successfully hacked into the Corps' computer system and found serious weaknesses, according to the report, "Financial Management: Significant Weaknesses in Corps of Engineers' Computer Controls,"(GAO-01-89).
Problem areas included: remote access to the Corps' system; users with access to unauthorized areas; infrequent logging and monitoring of individuals' access to stored data; and the absence of audit logs to detect and monitor security violations.
But Russell Fuhrman, acting commander of the Corps, disagreed with GAO's findings, and said he did not believe his agency had "pervasive weaknesses" as the report asserted.
"The Corps of Engineers' automated systems are continually being modernized and security strengthened," Fuhrman said. "We are working hard to provide the government and our customers with a safe and secure information system and financial management operating system."
Fuhrman said the release of the report is premature since his agency has already taken steps to fix many of the problems GAO identified and because PricewaterhouseCoopers has not yet completed follow-up work that might show that many of the problems are resolved.
Still, GAO stuck with its original assessment, saying that the Corps' efforts to correct weaknesses need to be institutionalized as a continuous program of risk management.
RELATED STORIES:
Federal cybersecurity efforts outpace private sector
(June 14)
Senator: No laws can fix careless computer security
(March 3)
Feds say private sector must take lead in computer security
(March 1)
Senators call for computer security crackdown
(Feb. 24)
Cyber security experts ask feds to step back
(Feb. 24)
EPA shuts Web sites amid charges of lax security
(Feb. 18)
White House assuages Internet security fears
(Feb. 16)
Senators call for larger DoD role in cyber security
(Feb. 2)
RELATED LINK:
General Accounting Office










Post a Comment
To post a comment, you must provide a name and a valid e-mail address. Messages must be limited to 400 words. By using this Service you agree not to post material that is obscene, harassing, defamatory, or otherwise objectionable. Although Government Executive does not monitor comments posted to this site (and has no obligation to), it reserves the right to delete, edit, or move any material that it deems to be in violation of this rule.