Skip to main content

Department of Transportation

Jump To:

Open Recommendations (87 total)

Cybersecurity: Agencies Need to Fully Establish Risk Management Programs and Address Challenges

Show
1 Open Recommendations
Agency Affected Recommendation Status Sort descending
Department of Transportation The Secretary of Transportation should update the department's policies to require an organization-wide risk assessment. (Recommendation 27)
Open
The Department of Transportation concurred with this recommendation. The department stated that it would update its policies and procedures to require an organization-wide cybersecurity risk assessment, but as of March 2024, it had not provided these updated policies and procedures or an estimated completion date. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.

Automated Technologies: DOT Should Take Steps to Ensure Its Workforce Has Skills Needed to Oversee Safety

Show
1 Open Recommendations
Agency Affected Recommendation Status Sort descending
Department of Transportation The Director of DOT's Department of Human Resources should regularly measure the progress of strategies implemented to close skill gaps—such as on an annual basis—and ensure modal administrations offer training to close those gaps. (Recommendation 3)
Open
DOT partially agreed with this recommendation. In March 2024, DOT noted that it was continuing to design efforts to monitor and measure mitigation of competency skill gaps by pairing assessed skill gaps with learning content and courses. DOT estimated that it would finish building a "competency model" by June 30, 2024 that will allow individual managers to monitor and track skill gap closure by tracking course completion. We will review the competency model when it is available. GAO will continue to monitor DOT's efforts to implement this recommendation.

Artificial Intelligence: Agencies Have Begun Implementation but Need to Complete Key Requirements

Show
1 Open Recommendations
Agency Affected Recommendation Status Sort descending
Department of Transportation The Secretary of Transportation should ensure that the department updates its AI use case inventory to include all the required information, at minimum, and takes steps to ensure that the data in the inventory aligns with provided instructions. (Recommendation 25)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.

Federal Software Licenses: Better Management Needed to Achieve Significant Savings Government-Wide

Show
1 Open Recommendations
Agency Affected Recommendation Status Sort descending
Department of Transportation To ensure the effective management of software licenses, the Secretary of Transportation should develop an agency-wide comprehensive policy for the management of software licenses that addresses the weaknesses we identified.
Open
As of January 2024, the department had not provided a documented policy for the management of software licenses that address the weaknesses we identified. According to department officials, they have onboarded an enterprise software license manager and expects to have an enterprise software license program plan and governance documentation published to its IT community by September 30, 2024. In July 2016, the MEGABYTE Act of 2016 was enacted, which codified this recommendation for all executive agencies (Pub. L. No. 114-210, 130 Stat. 824). We will follow up with the department to obtain evidence of the department-wide implementation of this recommendation.

Critical Infrastructure: Actions Needed to Better Secure Internet-Connected Devices

Show
1 Open Recommendations
Agency Affected Recommendation Status Sort descending
Department of Transportation The Secretary of Transportation should direct the Director, Office of Intelligence, Security and Emergency Response to jointly work with the Administrator of DHS's Transportation Security Administration and the Commandant of the U.S. Coast Guard, as co-SRMAs for the transportation systems sector, to use the National Plan to develop a sector-specific plan that includes metrics for measuring the effectiveness of their efforts to enhance the cybersecurity of their sector's IoT and OT environments. (Recommendation 7)
Open
In April 2023, DOT stated that, in coordination with co-SRMA partners at the Department of Homeland Security (DHS), it is developing an update to the 2015 transportation systems sector-specific plan (SSP). DOT noted that it plans to include metrics for measuring the effectiveness of efforts to enhance the cybersecurity of the sector's IoT and OT environments. In addition, DOT stated that the update is dependent on DHS finalizing the National Plan to ensure that the SSP aligns with any substantive changes in the new National Plan. According to DHS, the National Plan is estimated to be completed by September 2025.

Federal Motor Carrier Safety: Modifying the Compliance, Safety, Accountability Program Would Improve the Ability to Identify High Risk Carriers

Show
1 Open Recommendations
Agency Affected Recommendation Status Sort descending
Department of Transportation To improve the CSA program, the Secretary of Transportation should direct the FMCSA Administrator to revise the SMS methodology to better account for limitations in drawing comparisons of safety performance information across carriers; in doing so, the Secretary of Transportation should direct the FMCSA Administrator to conduct a formal analysis that specifically identifies: (1) limitations in the data used to calculate SMS scores including variability in the carrier population and the quality and quantity of data available for carrier safety performance assessments, and (2) limitations in the resulting SMS scores including their precision, confidence, and reliability for the purposes for which they are used.
Open
FMCSA did not agree with this recommendation and has requested that we close the recommendation as not implemented. However, in response to a similar 2017 review by the National Academy of Sciences, FMCSA developed and tested a new methodology to compare safety performance across motor carriers. We believe the changes made could account for the data and other limitations we identified in our report. In February 2023, FMCSA published proposed changes to the SMS methodology for comment in the Federal Register. As of March 2024, FMCSA is still in the process of reviewing comments and has not made a final decision on whether proposed changes would be implemented. To fully implement this recommendation, FMCSA should ensure that the methodology used to compare safety performance across motor carriers addresses the limitations we identified. Without a new methodology, FMCSA's ability to target unsafe motor carriers is hindered by insufficient information not accounted for in the current SMS methodology, such as variability in the motor carrier population. We will continue to monitor FMCSA's efforts to address this recommendation.

Highway Infrastructure: Better Alignment with Leading Practices Would Improve DOT's Reconnecting Communities Pilot Program

Show
1 Open Recommendations
Agency Affected Recommendation Status Sort descending
Department of Transportation The Secretary of Transportation should identify a means to assess lessons learned from the Reconnecting Communities Pilot program to inform decisions on whether or how to scale or integrate the pilot with other DOT efforts. (Recommendation 3)
Open
As of March 2024, DOT officials told us that the PCR program staff have collected lessons learned from the first two rounds of the program and plans to discuss them at a strategic planning session in May 2024. According to the officials, they plan to discuss how the program may adjust the Notice of Funding Opportunity, the application merit review process, and outreach activities to attract high-quality applications that benefit disadvantaged communities. In addition, the officials stated in May 2024, they plan to reach out to governmental and non-governmental stakeholders with an interest in reconnecting communities to gain additional feedback on program implementation and outcomes. The officials also said that additional lessons learned will be gathered through the evaluation of grant recipient outcomes that will be used to inform the required report to Congress by January 1, 2026. We will continue to monitor DOT's efforts to implement this recommendation.

Cloud Computing: Agencies Have Increased Usage and Realized Benefits, but Cost and Savings Data Need to Be Better Tracked

Show
1 Open Recommendations
Agency Affected Recommendation Status Sort descending
Department of Transportation The Secretary of Transportation should ensure that the CIO of Transportation establishes a consistent and repeatable mechanism to track savings and cost avoidances from the migration and deployment of cloud services. (Recommendation 28)
Open
Although DOT agreed with GAO's April 2019 recommendation, as of February 2024, it had not yet implemented the recommendation. An official from DOT's Office of the Chief Information Officer reported in February 2022 that the department had implemented a mechanism for tracking cost savings and avoidance from cloud services as part of its annual IT spending plan process. Subsequently, in February 2024, a DOT official reported that the department was working to finalize its departmental cloud strategy and a standard operating procedure related to this recommendation, which would be finalized by June 1, 2024. Successfully implementing a mechanism to track savings and cost avoidances from the use of cloud services should help DOT to ensure that it has sufficient information on the results of cloud acquisitions to date and the data necessary to make decisions regarding future cloud acquisitions.

Automated Technologies: DOT Should Take Steps to Ensure Its Workforce Has Skills Needed to Oversee Safety

Show
1 Open Recommendations
Agency Affected Recommendation Status Sort descending
Department of Transportation The Director of DOT's Department of Human Resources should collect and analyze information on the effectiveness of recruiting strategies, such as special payment authorities, in attracting staff to occupations that oversee the safety of automated technologies, and share effective strategies with modal administrations. (Recommendation 4)
Open
DOT agreed with this recommendation. In April 2024, DOT noted that it needed more time to provide an update to us on this recommendation. We will review DOT's recruitment report or any information the Department provides when it is available.

Discretionary Transportation Grants: DOT Should Improve Transparency in the Infrastructure for Rebuilding America Program

Show
1 Open Recommendations
Agency Affected Recommendation Status Sort descending
Department of Transportation The Secretary of Transportation should ensure that Office of the Secretary officials establish quality control procedures to verify that the conflict-of-interest screening and eligibility determination documentation is complete for Multimodal Project Discretionary Grant program applications. (Recommendation 1)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.