Report: FAA Cybersecurity Sucks
Raise your hand if this surprises you. SecurityFocus.com is running an article entitled U.S. Air Traffic Control Found Vulnerable. Some of the key points:
- The FAA certifies the security of computers systems as tested by their lab, not as deployed in the field.
- Vulnerability assessment is performed only on servers, leaving "tens of thousands" of vulnerable targets
- The FAA's IT security sucks
Ok, you probably guessed that I added that last item myself, but it's a pretty accurate summary of the article.
No comments:
Post a Comment