‘Information Security Weaknesses’ in 7 FDA Systems: GAO
The Government Accountability Office (GAO) says its review of security controls over seven key FDA information systems found “a significant number of security control weaknesses [that] jeopardize the confidentiality, integrity, and availability of its information and systems.” The GAO report says that FDA did not fully or consistently implement access controls, which are intended to prevent, limit, and detect unauthorized access to computing resources. Specifically, it says, the agency did not always (1) adequately protect the boundaries of its network; (2) consistently identify and authenticate system users; (3) limit users’ access to only what was required to perform their duties; (4) encrypt sensitive data; (5) consistently audit and monitor system activity; and (6) conduct physical security review of its facilities.
In response, FDA chief information officer Todd Simpson says that “information security and the protection of industry and public health information are among FDA’s highest priorities and we do not take lightly the recommendations provided by the GAO in its report. FDA has worked quickly to address the concerns outlined by the GAO, already fully implementing 80% (12 of 15) of GAO’s program recommendations and 61% (102 of 166) of GAO’s technical recommendations. We anticipate completing the remaining three program recommendations in the next few months, and the remaining technical recommendations in the next year.”
GAO says the control weaknesses existed, in part, because FDA had not fully implemented an agency-wide information security program as required under the Federal Information Security Modernization Act of 2014 and the Federal Information Security Management Act of 2012. For example, it says, the agency did not:
- ensure risk assessments for reviewed systems were comprehensive and addressed system threats;
- review or update security policies and procedures in a timely manner;
- complete system security plans for all reviewed systems or review them to ensure that the appropriate controls were selected;
- ensure that personnel with significant security responsibilities received training or that such training was effectively tracked;
- always test security controls effectively and at least annually;
- always ensure that identified security weaknesses were addressed in a timely manner; and
- fully implement procedures for responding to security incidents.
“Until FDA rectifies these weaknesses, the public health and proprietary business information it maintains in these seven systems will remain at an elevated and unnecessary risk of unauthorized access, use, disclosure, alteration, and loss,” the report concludes. GAO recommended that FDA:
- complete a risk assessment and authorization to operate for one FDA system;
- ensure that the completed risk assessments for six systems reviewed address the likelihood and impact of threats to FDA;
- develop a policy for system maintenance;
- develop procedures for eight specified security control families;
- enhance procedures for seven specified security control families;
- review and update as needed per FDA’s frequency the policies for 11 specified security control families;
- develop and document a security plan for one system supporting FDA scientific research;
- update security plans to ensure they fully and accurately document the controls selected and intended for protecting each of the six systems;
- review and approve security plans for the six systems reviewed at least annually;
- implement a process to effectively monitor and track training for personnel with significant security roles and responsibilities;
- ensure that personnel with significant security responsibilities receive role-based training;
- test controls at least annually for the two systems that support FDA’s scientific research and IT infrastructure;
- implement remedial actions in accordance with FDA’s prescribed time frames or update milestones if actions are delayed;
- update FDA’s incident response policy according to agency requirements; and
- update incident response procedures to include (1) instructions for coordinating incident response with contingency planning and (2) lessons learned from incident response tests.
GAO said it also made 166 technical recommendations in a separate report with limited distribution. Those recommendations addressed information security weaknesses related to boundary protection, identification and authentication, authorization, cryptography, physical security, configuration management, and media protection.
In his statement, Simpson said the agency continues to enhance its cybersecurity strategies and procedures to ensure FDA information security systems provide adequate protection of industry data and public health information on a continual, long-term basis. “In support of these efforts,” he said, “we acquired industry-leading expertise to assist in the development and execution of timely action plans, as well as program/project management activities to immediately address the recommendations outlined in the GAO report.”
He also stressed that FDA has not experienced any major cybersecurity-related breaches that exposed industry or public health information. “We recognizes the risks associated with operating our large global IT enterprise and have implemented processes, procedures, and tools to ensure the deterrence, prevention, detection, and correction of incidents,” he concluded. “In addition to addressing the majority of the recommendations identified in the GAO report, we have also undertaken several other key activities and initiatives to ensure our IT systems and sensitive information are appropriately protected by safeguarding against unauthorized disclosure, access, or misuse.”