BY JACK MOORE, NEXTGOV
The White House's Executive Office of the President hasn't submitted reports detailing compliance with federal cybersecurity rules for the past three years, according to a letter to President Barack Obama written by the chairmen of two Senate committees with oversight of federal technology efforts.
The apparent lack of annual reporting is even more striking considering the White House's unclassified computer networks were breached by hackers last fall, purportedly from Russia, leading to temporary outages as officials worked to suppress malicious activity.
The letter says the office, or EOP, hasn't submitted annual cybersecurity reviews of its systems to either the Office of Management and Budget or congressional committees for at least the past three years. The last time White House results showed up in OMB's annual compilation of agency reports was in fiscal 2008, according to the letter.
Annual reviews of agencies' IT security posture are mandated by the 2002 Federal Information Security Management Act, which Congress last updated in December. Independent inspectors general are also required to review agencies' FISMA compliance.