Information Security: USDA Needs to Implement Its Departmentwide Information Security Plan
Abstract:
USDA has taken positive steps to begin improving its information security by developing its August 1999 Action Plan with recommendations to strengthen department-wide information security and hiring a new Associate Chief Information Officer CIO for Cyber-Security who is working to address specific vulnerabilities and other potential threats. However, since the plan was issued in August 1999, little process has been made to implement other recommendations in the plan for strengthening the departments information security. Moreover, USDA has not developed and documented a strategy for implementing the action plan recommendations with established priorities and the detailed steps, time frames, milestones, and total resources needed to fully carry then out.