Advertisement
Top
image credit: Adobe Stock

GAO Report: Cyber Incident Response at U.S. Federal Agencies Lacking

December 12, 2023

More than a few federal agencies have some work to do when it comes to incident response, according to a December 4, 2023, report from the U.S. Government Accountability Office (GAO), titled “Cybersecurity: Federal Agencies Made Progress, but Need to Fully Implement Incident Response Requirements.” GAO-24-105658 assesses the progress of 23 civilian Chief Financial Officers (CFO) Act agencies in complying with Executive Order 14028’s cybersecurity incident response requirements.

Key findings in the GAO report

  • Progress made: Agencies have taken steps to standardize their incident response plans and improve their capabilities for detection, analysis, and handling of incidents. All agencies incorporated or are incorporating the Cybersecurity and Infrastructure Security Agency (CISA) playbook into their plans, and most completed the preparation phase activities.

Read More on SecureWorld