SEC needs better controls to protect data -watchdog

WASHINGTON, April 3 Thu Apr 4, 2013 3:14am IST

Related Topics

WASHINGTON, April 3 (Reuters) - Sensitive non-public information could be compromised if the U.S. Securities and Exchange Commission fails to take additional steps to improve its internal controls, an agency watchdog has found.

In two separate audits completed late last month, the SEC's new inspector general, Carl Hoecker, found vulnerabilities in the SEC's information technology system.

The first audit, dated March 25, examined how well the SEC maintains controls to protect sensitive information that it shares with the U.S. Financial Stability Oversight Council, or FSOC, a body of regulators that guards against systemic risks.

The second audit, dated March 29, reviewed the SEC's compliance with the Federal Information Security Management Act, a federal law that lays down a framework for government agencies to protect themselves against threats and ensure data is secure.

Both audits were conducted as routine reviews to ensure compliance with federal rules and regulations, and were not investigating any wrongdoing.

The inspector general's audits come as Congress and the White House are restarting negotiations on legislation aimed at improving U.S. defenses against cyber attacks.

The White House wants critical companies to comply with minimum security standards and also wants to help protect private information turned over to the government.

Protection of private company data is particularly important for financial market regulators, who routinely use it to help police the marketplace.

Hoecker's March 25 audit found that the SEC needs to take more steps to safeguard critical information that companies such as hedge funds provide to the SEC on a confidential basis.

That information, which often includes proprietary data, is later reviewed by the FSOC.

The audit found that the SEC does not have controls to restrict or prevent employees and contractors who are accessing their e-mail remotely via the Internet from uploading or saving non-public information to a non-government computer.

"As a result, sensitive or nonpublic information could potentially be saved to a non-SEC computer," Hoecker wrote. "There is a risk that an unauthorized person could gain access to sensitive or nonpublic SEC information."

The SEC said the audit did not inquire whether any information was actually compromised.

The second audit found that generally the SEC needs to do more to continually monitor the security of its systems. It also found the SEC did not always properly disable network accounts for employees or contractors who have left the SEC.

"By not disabling these accounts, unauthorized employees/contractors can have access to the SEC's network," the report said, adding it was "putting the SEC at a higher risk for malicious acts."

SEC spokesman John Nester declined to comment beyond the agency's comments attached to the two audits.

The SEC concurred with the recommendations and said it would take steps to correct the problems.

FILED UNDER:
Comments (0)
This discussion is now closed. We welcome comments on our articles for a limited period after their publication.

  • Most Popular
  • Most Shared

REUTERS SHOWCASE

Press Event

Press Event

Modi takes tea, but no questions, in first press event as PM.  Full Article 

School Shooting

School Shooting

Two killed, four wounded in Washington state school shooting.  Full Article 

Sundar Pichai Elevated

Sundar Pichai Elevated

Google's Pichai to oversee major products and services.  Full Article 

Need For Reforms

Need For Reforms

Euro zone risks "relapse into recession" without structural reforms - Draghi.  Full Article 

Diwali Sales

Diwali Sales

Gold sales jump about 20 pct for Diwali - trade body  Full Article 

World Bank Rival

World Bank Rival

Three major nations absent as China launches W.Bank rival in Asia  Full Article 

Wal-Mart India

Wal-Mart India

Murali Lanka appointed as Wal-Mart India operations chief  Full Article 

Health Of Lenders

Health Of Lenders

25 European banks set to fail health checks - sources.  Full Article 

India Insight

India Insight

Kalki Koechlin on her role as a disabled girl in “Margarita, With a Straw”  Full Article 

Reuters India Mobile

Reuters India Mobile

Get the latest news on the go. Visit Reuters India on your mobile device.  Full Coverage