Dive Brief:
-
Michael Esser, OPM's assistant inspector general for audits, blamed OPM's recent data breach on a "long history of systemic failures to properly manage its IT infrastructure" during his testimony before a joint House subcommittee hearing.
-
Esser said his team's 2014 audit found that 11 of 47 major OPM systems were operating without a valid authorization under OMB standards, but his warnings went ignored.
-
U.S. Office of Personnel Management Director Katherine Archuleta resigned Friday in the aftermath of the hack, and Beth Cobert will take over the position on an interim basis.
Dive Insight:
During the hearing, Esser said OPM needs to improve its technical security controls in areas like authentication and configuration management.
He added that while he acknowledges federal government agencies often face challenging budget environments that limit their ability to undertake major IT initiatives, an inconsistent governance framework for information security is also to blame.