Probing Federal IT Security Programs: Gregory Wilshusen, GAO

Published: Feb. 23, 2009, 5:33 p.m.

b'Government Accountability Office auditors will have a busy spring, examining a number of federal government programs aimed at securing government information systems and data. \\n\\n

In an interview with GovInfoSecurity.com, Gregory Wilshusen discusses how the GAO is looking at how private industry and two dozen federal agencies employ metrics to measure the effectiveness of information security control activities. Other current GAO information security investigations he discusses include:\\n\\n

Federal Desktop Core Configuration intended to standardize security features on personal computers purchased by the government.
\\n
Trusted Internet Connection initiative aimed at slashing government Internet connections to fewer than 100 from more than 2,000.
\\n
Einstein automated networking monitoring program run by U.S Computer Emergency Readiness Team.
\\n\\n

Gregory Wilshusen is director of information security issues at GAO, where he leads information security-related studies and audits of the federal government. He has more than 26 years of auditing, financial management and information systems experience. Before joining GAO in 1997, Wilshusen served as a senior systems analyst at the Department of Education as well as the controller for the North Carolina Department of Environment, Health and Natural Resources.'