Lack of Basic Security Practices Hindered BIS’ Continuous Monitoring Program and Placed Critical Systems at Risk
For our final report on the Bureau of Industry and Security's (BIS') continuous monitoring program, our objective -- in accordance with the Federal Information SecurityManagement Act of 2002 -- was to determine whether BIS' continuous monitoring strategy and practices, including ongoing security...