ISR News: SEC Cybersecurity Incomplete

March 19, 2009 by ADMIN
Share |

Excerpts From GCN.com

The Securities and Exchange Commission has corrected some weaknesses identified in its information security controls in the past two years, but the lack of a comprehensive information security program has let weaknesses accumulate faster than they have been resolved, according to the Government Accountability Office.

“In our report on SEC’s financial statements for fiscal years 2008 and 2007, we concluded that weaknesses in information security controls constitute a significant deficiency in internal controls over the information systems and data used for financial reporting,” GAO auditors wrote in a recently released report.

SEC has corrected or mitigated 18 of 34 weaknesses reported in a 2008 audit, GAO said. But in addition to the 16 problems not yet addressed, GAO identified 23 new ones. “A key reason for these weaknesses was that SEC did not fully implement key activities of its information security program,” the report states.

These icons link to social bookmarking sites where readers can share and discover new web pages.
  • TwitThis
  • LinkedIn
  • Google Bookmarks
  • Digg
  • StumbleUpon
  • YahooBuzz
  • del.icio.us
  • Wikio
  • Propeller
  • Facebook
  • MySpace
Share |


Filed under: Breach, Class Action Lawsuit, D&O Liability, Financial, Government, ISR News, Insider Threat, Uncategorized, identity-theft, malware, national security 

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!