Are US Federal Cyber Workers Good Enough?

Federal agencies have made mixed progress at ensuring their cybersecurity workers are properly trained and credentialed, according to a watchdog report released Thursday.

In some cases, agencies haven’t determined exactly who counts as a cybersecurity worker and who doesn’t, according to the Government Accountability Office report. In other cases, agencies haven’t determined which certifications are appropriate or necessary for the cybersecurity employees they do have, the report found.

There’s no standard certification requirement for cybersecurity professionals, such as the bar degree for lawyers, but employers often require certifications offered by professional organizations—such as the Certified Information Systems Security Professional certification—or use those certifications to judge an applicants’ qualifications.

The Federal Cybersecurity Workforce Assessment Act, a 2015 law, required the Office of Personnel Management to develop a coding structure that defines government cyber jobs and the qualifications and certifications required for them.

The law also mandated agencies to apply those codes to their cyber workforces and to report back to Congress on whether their cyber workers were properly credentialed and, if not, what the agencies were doing about it.

After the law went into effect, however, the personnel office was late in developing the coding structure because of earlier delays at the Commerce Department’s cyber education office and that delayed agency assessments.

As of March, only 21 of the 24 major federal agencies had completed their assessments and four of those were missing important pieces of reportable information, the accountability office found.

Some of the reports that included all necessary information were likely partially inaccurate, because of incomplete cyber worker counts or inconsistent use of the codes, the office said.

“This diminishes the usefulness of the assessments in determining the certification and training needs of these agencies’ cybersecurity employees,” the report found.

Overall, 23 of the 24 agencies “had established procedures to identify their civilian cybersecurity positions and assign the appropriate employment codes,” but six of those agencies failed to address at least one of OPM’s coding or assessment requirements, the report found.

The accountability office made 30 separate recommendations to the 13 agencies that fell short in some way, most of which the agencies agreed with or, at least, didn’t disagree with.

The one exception was NASA, which disagreed with a recommendation that it should assess how ready its cyber workers who don’t hold certifications are to get those certifications.

“The agency stated that there is no federal or NASA requirement for employees in cybersecurity positions to hold and/or maintain a certification, and therefore the agency has no plans to assess the readiness of its cybersecurity personnel to take certification exams,” the report stated.

The accountability office stands firm in the recommendation, it said.

Nextgov:

You Might Also Read:

In Demand: Cybersecurity Specialists

« World First Police 3D Security Scanner
EC-Council Sets New Application Security Training Standards »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Forcepoint

Forcepoint

Forcepoint provide a unified, cloud-centric platform that safeguards users, networks and data while eliminating the inefficiencies of managing multiple point security products.

CERT-PA

CERT-PA

CERT-PA is the national Computer Emergency Response Team for Italian government institutions.

Red Canary

Red Canary

Red Canary continuously monitors and analyzes your endpoints, users, and network activity in search of threatening behaviors, patterns, and signatures.

Merlin Cyber

Merlin Cyber

Merlin is a premier cybersecurity platform that leverages security technologies, trusted relationships, and capital to develop and deliver groundbreaking security solutions.

Healthcare Fraud Shield (HCFS)

Healthcare Fraud Shield (HCFS)

The focus of Healthcare Fraud Shield is solely on healthcare fraud prevention and payment integrity with a successful approach based on many unique advantages we deliver to our clients.

ditno

ditno

ditno uses machine learning to help you build a fully governed and micro-segmented network. Dramatically mitigate risk and prevent lateral movement across your organisation – all from one centralised

Laminar

Laminar

Laminar provides the only Public Cloud Data Protection solution that provides full visibility and enforcement capabilities across your entire public cloud infrastructure.

Cloud Seguro

Cloud Seguro

Cloud Seguro are leaders in the development of cloud solutions, Ethical Hacking, Privacy and Information Security.

Moro Hub

Moro Hub

Moro Hub, a subsidiary of Digital DEWA, is a UAE-based digital data hub focused on digital transformation and operational services.

DigitalPlatforms

DigitalPlatforms

DigitalPlatforms SpA is an Italian group with the mission of providing end-to-end solutions and Internet of Things and Cyber technologies to companies that manage critical infrastructures.

Saffron Networks

Saffron Networks

Saffron Networks is an ISO-certified company. We assure our clients of reliable solutions, specifically with the Security landscape and Enterprise Networking.

B2Bcert

B2Bcert

B2BCERT one of the top companies offering ISO 9001, ISO 14001, ISO 45001, ISO 22000, ISO 27001, ISO 20000,CE Marking, HACCP, and other globally accepted standards and Management solutions.

CyberMaxx

CyberMaxx

At CyberMaxx, our approach to cybersecurity provides end-to-end coverage for our customers – we use offense to fuel defense.

PriorityZero

PriorityZero

PriorityZero is a European company focused on remote security assessments and consulting services that operates on a global scale.

Socket

Socket

Socket protects software applications and critical services from malware and security threats originating in open source code.

Secomea

Secomea

Secomea redefines manufacturing plant security by combining internationally recognized industry best practices as critical components of our robust cybersecurity strategy.