<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cyber.harvard.edu/cybersecurity/history/Information_Security?feed=atom</id>
	<title>Information Security - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://cyber.harvard.edu/cybersecurity/history/Information_Security?feed=atom"/>
	<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/history/Information_Security"/>
	<updated>2026-08-10T09:11:17Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Information_Security&amp;diff=1324&amp;oldid=prev</id>
		<title>Jacob: New page: ==Full Title of Reference==  Information Security - Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies   ==Full Citation==  GAO, &#039;&#039;Information Secur...</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Information_Security&amp;diff=1324&amp;oldid=prev"/>
		<updated>2010-06-17T15:18:19Z</updated>

		<summary type="html">&lt;p&gt;New page: ==Full Title of Reference==  Information Security - Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies   ==Full Citation==  GAO, &amp;#039;&amp;#039;Information Secur...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==Full Title of Reference==&lt;br /&gt;
&lt;br /&gt;
Information Security - Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies &lt;br /&gt;
&lt;br /&gt;
==Full Citation==&lt;br /&gt;
&lt;br /&gt;
GAO, &amp;#039;&amp;#039;Information Security - Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies&amp;#039;&amp;#039; (2010). Report to Congressional Requesters and prepared by the Government Accountability Office. [http://www.hsdl.org/?view&amp;amp;doc=120785&amp;amp;coll=public&amp;#039;&amp;#039;web&amp;#039;&amp;#039;]&lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/?title=Special:Bibliography&amp;amp;action=viewsource&amp;amp;startkey=GAO:2010&amp;amp;f=wikibiblio.bib &amp;#039;&amp;#039;BibTeX&amp;#039;&amp;#039;]&lt;br /&gt;
&lt;br /&gt;
==Categorization==&lt;br /&gt;
&lt;br /&gt;
Overview: [[Government Reports]]&lt;br /&gt;
&lt;br /&gt;
Issues: [[Government Networks (.gov)]]; [[Information Sharing/Disclosure]]; [[Government Organization]]&lt;br /&gt;
&lt;br /&gt;
==Key Words== &lt;br /&gt;
&lt;br /&gt;
[http://cyber.law.harvard.edu/cybersecurity/Glossary_of_Core_Ideas#Einstein Einstein], [http://cyber.law.harvard.edu/cybersecurity/Glossary_of_Core_Ideas#Department_of_Homeland_Security Department of Homeland Security], [http://cyber.law.harvard.edu/cybersecurity/Glossary_of_Core_Ideas#Computer_Network_Attack Computer Network Attack], &lt;br /&gt;
&lt;br /&gt;
==Synopsis==&lt;br /&gt;
&lt;br /&gt;
The goals of TIC are to secure federal agencies’ external network connections, &lt;br /&gt;
including Internet connections, and improve the government’s incident &lt;br /&gt;
response capability by reducing the number of agencies’ external network &lt;br /&gt;
connections and implementing security controls over the connections that &lt;br /&gt;
remain. In implementing TIC, agencies could either provide their own access &lt;br /&gt;
points by becoming an access provider or seek service from these providers &lt;br /&gt;
or an approved vendor. To achieve the initiative’s goals, agencies were &lt;br /&gt;
required to  &lt;br /&gt;
 &lt;br /&gt;
• inventory external connections,  &lt;br /&gt;
• establish a target number of TIC access points, &lt;br /&gt;
• develop and implement plans to reduce their connections,  &lt;br /&gt;
• implement security capabilities (if they chose to be an access provider) &lt;br /&gt;
addressing such issues as encryption and physical security, and  &lt;br /&gt;
• demonstrate to DHS the consolidation of connections and compliance &lt;br /&gt;
with the security capabilities (if they chose to be an access provider).  &lt;br /&gt;
 &lt;br /&gt;
As of September 2009, none of the 23 agencies had met all of the requirements &lt;br /&gt;
of the TIC initiative. Although most agencies reported that they have made &lt;br /&gt;
progress toward reducing their external connections and implementing &lt;br /&gt;
critical security capabilities, most agencies have also experienced delays in &lt;br /&gt;
their implementation efforts. For example, the 16 agencies that chose to &lt;br /&gt;
become access providers reported that they had reduced their number of &lt;br /&gt;
external connections from 3,286 to approximately 1,753. Further, agencies &lt;br /&gt;
have not demonstrated that they have fully implemented the required security &lt;br /&gt;
capabilities. Throughout their reduction efforts, agencies have experienced &lt;br /&gt;
benefits, such as improved security and network management. However, they &lt;br /&gt;
have been challenged in implementing TIC because OMB did not promptly &lt;br /&gt;
communicate the number of access points for which they had been approved &lt;br /&gt;
and DHS did not always respond to agency queries on security capabilities in &lt;br /&gt;
a timely manner. Agencies’ experiences with implementing TIC offered OMB &lt;br /&gt;
and DHS lessons learned, such as the need to define program requirements &lt;br /&gt;
before establishing deadlines and the usefulness of sponsoring collaborative &lt;br /&gt;
meetings for agencies’ implementation efforts. &lt;br /&gt;
 &lt;br /&gt;
Einstein is intended to provide DHS with an increased awareness of activity, &lt;br /&gt;
including possible security incidents, on federal networks by providing &lt;br /&gt;
intrusion detection capabilities that allow DHS to monitor and analyze &lt;br /&gt;
agencies’ incoming and outgoing Internet traffic. As of September 2009, fewer &lt;br /&gt;
than half of the 23 agencies had executed the required agreements with DHS, &lt;br /&gt;
and Einstein 2 had been deployed to 6 agencies. Agencies that participated in &lt;br /&gt;
Einstein 1 improved identification of incidents and mitigation of attacks, but &lt;br /&gt;
DHS will continue to be challenged in understanding whether the initiative is &lt;br /&gt;
meeting all of its objectives because it lacks performance measures that &lt;br /&gt;
address how agencies respond to alerts. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Additional Notes and Highlights==&lt;br /&gt;
&lt;br /&gt;
Contact: Gregory C. Wilshusen  (202) 512-6244 or wilshuseng@gao.gov&lt;/div&gt;</summary>
		<author><name>Jacob</name></author>
	</entry>
</feed>