Skip to main content

Veterans Affairs: Continued Action Needed to Reduce IT Equipment Losses and Correct Control Weaknesses

GAO-08-918 Published: Jul 31, 2008. Publicly Released: Jul 31, 2008.
Jump To:
Skip to Highlights

Highlights

In July 2004, GAO reported that the six Department of Veterans Affairs (VA) medical centers it audited lacked a reliable property control database and effective inventory policies and procedures. In July 2007, GAO reported that continuing internal control weaknesses over IT equipment at four case study locations at VA resulted in an increased risk of theft, loss, and misappropriation of IT equipment assets. GAO's two reports included 18 recommendations to improve internal control over IT equipment. GAO was asked to perform a follow-up audit to determine (1) whether VA has made progress in implementing GAO's prior recommendations for improving internal control over IT equipment and (2) the effectiveness of VA's current internal controls to prevent theft, loss, or misappropriation of IT equipment. GAO reviewed policies and other pertinent documentation, statistically tested IT equipment inventory controls at four geographically disparate locations, and interviewed VA officials.

Recommendations

Recommendations for Executive Action

Agency Affected Recommendation Status
Department of Veterans Affairs To improve accountability of IT equipment inventory and reduce the risk of disclosure or compromise of sensitive personal and medical information, the Secretary of Veterans Affairs should require the CIO, with the support of medical centers and VA headquarters organizations we tested and other VA organizations, as appropriate, to review property inventory records and confirm that all IT equipment, regardless of the organizational equipment inventory listing, is identified in the property system.
Closed – Implemented
In response to our recommendation, VA established new procedures to review property inventory records and confirm that all IT equipment is identified in the property system. In July 2009, VA issued VA Handbook 7002 with new inventory control procedures. At each facility, an IT Custodial Officer is to coordinate perpetual inventory activities and conduct an annual inventory of IT equipment items assigned a Catalog Stock Number (CSN) as well as expendable IT equipment items. Following an inventory of IT items, or whenever an IT equipment item is identified as "not accounted for", the IT Custodial Officer is to review, document and report any discrepancies identified during inventory activities. A VA IT Inventory Compliance Portal has been established to monitor the completeness of inventory data and the status of perpetual inventory efforts. By implementing our recommendation to review property inventory records and confirm that all IT equipment is identified in the property system, VA improved its accountability of IT equipment and helped safeguard those assets from theft, loss, and misappropriation.
Department of Veterans Affairs To improve accountability of IT equipment inventory and reduce the risk of disclosure or compromise of sensitive personal and medical information, the Secretary of Veterans Affairs should require the CIO, with the support of medical centers and VA headquarters organizations we tested and other VA organizations, as appropriate, to establish and implement a policy requiring development of standardized naming classifications for IT equipment--including item name, manufacturer, and model--for recording IT equipment into local property inventory systems.
Closed – Implemented
In response to our recommendation, in March 2010, VA issued an SOP to standardize the naming classification for IT equipment. The SOP required that fields for item name, manufacturer, and model be completed for all IT equipment. In addition, VA established a new web portal to monitor compliance with these requirements. The website provides information on IT equipment data completeness. For example, a VA staff person can view for a given facility a list of the number and percentage of items with complete information on serial number, manufacturer, and model. By implementing our recommendation to establish and implement a policy requiring development of standardized naming classification for recording IT equipment into local property inventory systems, VA has improved its accountability of IT equipment and helped safeguard those assets from theft, loss, and misappropriation.
Department of Veterans Affairs To improve accountability of IT equipment inventory and reduce the risk of disclosure or compromise of sensitive personal and medical information, the Secretary of Veterans Affairs should require the CIO, with the support of medical centers and VA headquarters organizations we tested and other VA organizations, as appropriate, to develop a list of medical equipment with data storage capability that should be considered as IT equipment for inventory control purpose
Closed – Implemented
In response to our recommendation, in April 2010, VA published a list of medical equipment Catalog Stock Numbers (CSNs) to be used for maintaining accountability over VA medical equipment with data storage capabilities to be included in its IT equipment inventory. The list includes six new CSNs for computers, printers, and monitors, which are utilized as part of a system of medical equipment, and their life expectancies. For example, there is a new CSN for laptop computers that are always used with MRI or CT equipment. By implementing our recommendation to develop a list of medical equipment with data storage capability that should be considered as IT equipment for inventory control purposes, VA has improved its accountability of IT medical equipment and helped safeguard those assets from theft, loss, and misappropriation.
Department of Veterans Affairs To improve accountability of IT equipment inventory and reduce the risk of disclosure or compromise of sensitive personal and medical information, the Secretary of Veterans Affairs should require the CIO, with the support of medical centers and VA headquarters organizations we tested and other VA organizations, as appropriate, to develop a procedure for identifying hard drive serial numbers with both the property identification numbers and serial numbers of host computers.
Closed – Implemented
In response to our recommendation, in July 2009, VA issued VA Handbook 7002 part 4 requiring that IT Custodial Officers ensure that each hard drive is marked with the equipment entry number of the host system whenever the hard drive is removed from the host system. The equipment entry numbers are to be written on the hard drives with an indelible marker at the time the hard drives are removed from the host systems. This procedure enables tracking of the hard drive to the host computer. By implementing our recommendation to develop a procedure for identifying and linking hard drives to host computers, VA has improved its accountability of IT equipment, and reduced the risk of disclosure or compromise of sensitive personal and medical information.
Department of Veterans Affairs To improve accountability of IT equipment inventory and reduce the risk of disclosure or compromise of sensitive personal and medical information, the Secretary of Veterans Affairs should require the CIO, with the support of medical centers and VA headquarters organizations we tested and other VA organizations, as appropriate, to revise the definition of IT storage locations in VA's Handbook 0730/1, Security and Law Enforcement, to include informal IT storage locations, such as OIT work rooms, and require these locations to be included in physical security inspections.
Closed – Implemented
VA concurred with our recommendation. In March 2013, VA officials updated VA Handbook 0730/1 (currently 0730/4, the fourth version of VA Handbook 0730), Security and Law Enforcement. This update requires that temporary IT storage locations have minimum physical security requirements and that temporary IT storage locations are included in physical security inspections.

Full Report

GAO Contacts

Office of Public Affairs

Topics

AccountabilityAuditsData storageEmployeesEquipment inventoriesFederal propertyFederal property managementInformation technologyInternal controlsInventory controlIT policiesPropertyProperty and supply managementProtective equipmentRecordsStrategic planningTest equipmentPolicies and procedures