Skip to main content
banner image
venafi logo

Federal Agencies Miss Encryption Deadline: How Can We Improve Compliance?

Federal Agencies Miss Encryption Deadline: How Can We Improve Compliance?

Federal Agencies Miss Encryption Deadline
March 5, 2018 | Emil Hanscom

Encryption is a critical component of our digital economy. It plays a fundamental role in protecting privacy and commerce. Unfortunately: some government agencies have difficulty accepting the importance, and necessity, of encryption.

Although it’s a foundational component of every responsible organization, each day seems to bring a new threat to encryption technology from well-meaning, but ill-informed government officials. These vocal attacks may play one of many roles in how agencies adopt and maintain their security solutions. Other factors include: a dearth of funding for updating security, an aging infrastructure, a lack of skilled resources and more.

According to a recent government report, almost half of all federal agencies missed a deadline to adopt a swath of cyber security upgrades, including adding HTTPS encryption to their websites. The security updates come from the Homeland Security Department’s binding operational directive, which was initially released in October and gave agencies until February 13th to implement the improvements.

“Just 54 percent of agencies met the full set of requirements, according to a tally maintained by the General Services Administration,” writes Joseph Marks, security reporter for NextGov. “While about 70 percent met the HTTPS requirement, according to a Homeland Security official.”

Overall compliance varied by agency. “Only 20 percent of Homeland Security’s own websites met the web security deadline,” continued Marks. “NASA, by contrast, was 97 percent compliant and the Interior Department was 93 percent compliant.”

HTTPS isn’t perfect, but it is a valuable tool for website security. It remains to be seen how critical comments and a lack of funding from the federal government have hindered its own encryption usage. That’s a difficult issue to assess. But one thing remains clear, current compliance rates leave much to be desired.

Does your website meet these security standards?

Related posts

Like this blog? We think you will love this.
executive man with forward looking glasses leaning up against a wall, self assured
Featured Blog

Why Is NIST SP 1800-16 So Important? [Think Executive Buy-In]

"The executive summary is a perfect tool to reach out to your executives and gain their sponsors

Read More
Subscribe to our Weekly Blog Updates!

Join thousands of other security professionals

Get top blogs delivered to your inbox every week

See Popular Tags

You might also like

CIO Study: Certificate-Related Outages Continue to Plague Organizations
White Paper

CIO Study: Certificate-Related Outages Continue to Plague Organizations

Machine Identity Protection for Dummies
eBook

Machine Identity Protection for Dummies

About the author

Emil Hanscom
Emil Hanscom

Emil is the Public Relations Manager at Venafi. Passionate about educating the global marketplace about infosec and machine-identity issues, they have consistently grown Venafi's global news coverage year over year.

Read Posts by Author
get-started-overlay close-overlay cross icon
get-started-overlay close-overlay cross icon
Venafi Risk assessment Form Image

Sign up for Venafi Cloud


Venafi Cloud manages and protects certificates



* Please fill in this field Please enter valid email address
* Please fill in this field Password must be
At least 8 characters long
At least one digit
At last one lowercase letter
At least one uppercase letter
At least one special character
(@%+^!#$?:,(){}[]~`-_)
* Please fill in this field
* Please fill in this field
* Please fill in this field
*

End User License Agreement needs to be viewed and accepted



Already have an account? Login Here

×
get-started-overlay close-overlay cross icon

How can we help you?

Thank you!

Venafi will reach out to you within 24 hours. If you need an immediate answer please use our chat to get a live person.

In the meantime, please explore more of our solutions

Explore Solutions

learn more

Email Us a Question

learn more

Chat With Us

learn more
Chat