IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

GAO slams federal agencies for IT supply chain risk

Federal agencies don't understand where their technology comes from

Man in suit in front of holographic display showing risk assessment and supply chain

Just days after the US government learned of a widespread hack via a third-party provider's software, the US Government Accountability Office (GAO) has issued a report criticizing 23 civilian agencies for poor risk management in their information and communications technology (ICT) supply chains.

The GAO report, “Federal Agencies Need to Take Urgent Action to Manage Supply Chain Risks,” examined how federal government agencies managed risks from third-party hardware, software, and services. It examined multiple organizations, including the Departments of Agriculture, Commerce, Education, and Energy. The Office of Personnel Management, which suffered a massive data breach in 2015, was also in the review.

"Over several years, we have reported that the growing dependence on a globally distributed supply chain — and the lack of control over and visibility into how ICT products and services are developed, integrated, and deployed — presents an increasing amount of risk to federal agencies," the report warned.

It identified ICT supply chain risks, including the introduction of counterfeit products and the compromise of legitimate ones before delivery.

"Threat actors attack all tiers of the supply chain and at each phase of the system development life cycle and, thus, pose significant risk to federal agencies," it continued.

Auditors examined how agencies implemented seven foundational supply chain risk management (SCRM) practices, including executive oversight, creating an agency-wide strategy, and creating SCRM requirements for suppliers.

"None of the 23 agencies fully implemented all of the SCRM practices and 14 of the 23 agencies had not implemented any of the practices," it warned, highlighting the security risks involved.

Not a single agency had established a process to conduct agency-wide ICT supply chain risk assessments, and 19 of them had no method to document their ICT supply chains.

Agencies complained they had no federal guidance on SCRM, the report noted. A federal organization dedicated to managing supply chain risk, the Federal Acquisition Security Council, was scheduled to issue guidance this month.

However, the National Institute of Standards and Technology (NIST) already issued SCRM guidance in 2015 and updated its cyber security framework to cover supply chain risk in April 2018, the report noted. The Office of Management and Budget (OMB) required agencies to tackle SCRM since 2016.

The GAO made 145 recommendations to the agencies, including making someone responsible for leading agency-wide SCRM activities and creating a strategy to secure ICT supply chains. Seventeen agencies agreed with all the recommendations, but one unidentified organization agreed with none.

Already released privately in October, the report's public release came in the wake of a widespread government hack. Attackers compromised several government departments via the SolarWinds IT monitoring system in a hack so serious the FBI, CISA, and the ODNI coordinated a government-wide response. 

Some of the government departments compromised in the attack, including the Department of the Treasury, Department of Commerce, and Homeland Security, were among those covered in the GAO report.

Featured Resources

Meeting the future of education with confidence

How the switch to digital learning has created an opportunity to meet the needs of every student, always

Free Download

The Total Economic Impact™ of IBM Cloud Pak® for Watson AIOps with Instana

Cost savings and business benefits

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

Technology reimagined

Why PCaaS is perfect for modern schools

Free Download

Recommended

Costa Rica declares state of emergency following Conti ransomware attack
ransomware

Costa Rica declares state of emergency following Conti ransomware attack

10 May 2022
LinkedIn to pay $1.8 million to employees after settling gender discrimination charges
Careers & training

LinkedIn to pay $1.8 million to employees after settling gender discrimination charges

4 May 2022
Google claims US government is too reliant on unsecure Microsoft products
cyber security

Google claims US government is too reliant on unsecure Microsoft products

1 Apr 2022
Democrats propose privacy-focused digital dollar
digital currency

Democrats propose privacy-focused digital dollar

29 Mar 2022

Most Popular

How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

7 Jun 2022
Delivery firm Yodel disrupted by cyber attack
cyber attacks

Delivery firm Yodel disrupted by cyber attack

21 Jun 2022
Swift exit: How the world cut off Russian banks
finance

Swift exit: How the world cut off Russian banks

24 Jun 2022