Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »
Webcast: In the Google Apps Cloud: How to Achieve Your Business Objectives
Dec 3rd, '09, 1 - 2 pm US/Eastern (GMT-5)
Join Council member Brent Hoag, Director, Global IT, at JohnsonDiversey, as he discusses the adoption of Google Apps which has helped meet four corporate goals; sustainability, simplification, increased employee productivity and global collaboration.
Webcast: Collaboration Initiatives: Benchmarks & Best Practices
Dec 15th, '09, 4 - 5 pm US/Eastern (GMT-5)
Join Council members Ruth Thorpe, VP & CIO at the U.S. Pharmaceutical Operations of Sanofi-Aventis, and Gary Kuyper, CIO at Bethany Christian Services, as they speak about their collaboration initiatives and experiences in how and why they chose the social networking and collaboration tools they are using and their business goals for collaboration, and facing culture change challenges.
Data Overview: Collaboration Initiatives Field Guide: Benchmarks & Best Practices
This appendix to the Council Field Guide provides an analysis which discusses benchmarks for collaboration IT implementation costs, adoption rates and payoffs. The overview identifies top IT and business goals and satisfaction rates for collaboration initiatives as well as best practices and lessons learned for implementing collaboration IT.
Learn more about the CIO Executive Council »December 16, 2008 — IDG News Service —
The U.S. Internal Revenue Service's IT staff hasn't routinely checked its cybersecurity audit logs, according to a report released this week by the agency's inspector general's office.
The IRS has effectively deployed intrusion detection systems at its Internet gateways, and it has used access controls for firewalls and routers, said the report, completed in July but released Monday. But the agency's IT staff weren't always saving or reviewing system audit logs, and clock settings on some firewalls and routers did not comply with IRS rules, the report said.
"These weaknesses increase the likelihood that intruders from the Internet could gain access to sensitive taxpayer data residing on the IRS network without being detected," the report said.
One IRS employee, the database administrator for routers, had access to router audit logs, even though IRS rules require that a worker outside the immediate IT staff responsible for routers have access for independent review, the report said. In addition, IRS IT staff did not save audit logs on two separate servers, as recommended in IRS guidelines.
The report, with large chunks redacted, recommends the IRS allow independent review of audit logs and establish procedures to save audit logs. It also recommended that the IRS regularly test its Internet gateways for compliance with standard security configurations. The IRS agreed with the recommendations, saying it planned to do bi-weekly compliance testing.
The report also said the IRS had unnecessary services enabled on routers, although the public version of the report does not tell what those services were.
"We have corrected many of the findings outlined in your report and are aggressively implementing additional changes to further protect our Internet gateways," Arthur Gonzalez, the IRS CIO, wrote in response to the report. "Your suggested recommendations are in adherence with standards that will further improve our security posture."
The IRS' parent agency, the Department of Treasury, received a failing grade for its 2007 cybersecurity efforts, according to a report card released in May. The annual report, released by the U.S. Congress, grades federal agencies' compliance with the Federal Information Security Management Act, or FISMA.
The IRS review was performed at the IRS Computer Security Incident Response Center and covered the period from February 2007 to March of this year.