New GAO Report and GAO Testimony of Interest
The GAO also issued important new testimony yesterday entitled “GAO-21-594T Cybersecurity: Federal Agencies Need to Implement Recommendations to Manage Supply Chain Risks”. The GAO stated that “the supply chain for information and communication technologies can be an access point for hackers. Compromised SolarWinds Orion network management software, for example, was sent to an estimated 18,000 customers. We testified about the government's SolarWinds response and agency efforts to reduce supply chain vulnerability. The response included a coordinated effort to help agencies find and remove the threats to their systems. In a 2020 report, we noted that none of 23 reviewed agencies had fully adopted identified practices to reduce supply chain risks. Federal information security has been on our High Risk List since 1997.”