Skip to main content

Privacy: Dedicated Leadership Can Improve Programs and Address Challenges

GAO-22-105065 Published: Sep 22, 2022. Publicly Released: Sep 22, 2022.
Jump To:

Fast Facts

Federal agencies that collect personally identifiable information—such as birthplaces and Social Security numbers—are required to establish programs to protect it.

The 24 agencies we examined had designated a senior agency official for privacy, as required. However, these officials may have numerous other duties and may not bring a needed focus on privacy. They generally delegated many aspects of privacy programs to less-senior officials.

We recommended that Congress consider legislation to designate dedicated, senior-level privacy officials. We also made more than 60 other recommendations to strengthen agency privacy programs.

A graphic of a phone, which shows a colorful padlock on the screen, surrounded by illustrated eyes.

Skip to Highlights

Highlights

What GAO Found

The 24 Chief Financial Officer (CFO) Act of 1990 agencies varied in the extent to which they addressed key practices for implementing privacy programs:

  • Agencies generally established policies and procedures for key privacy activities. These included developing system of records notices, to identify personal data collected and how they are used; conducting privacy impact assessments; and documenting privacy program plans.
  • Agencies varied in establishing policies and procedures for coordination between privacy programs and other agency activities, such as information security, budget and acquisition, workforce planning, and incident response.
  • Many agencies did not fully incorporate privacy into their risk management strategies, provide for privacy officials' input into the authorization of systems containing personally identifiable information (PII), and develop a privacy continuous monitoring strategy.

Extent to Which 24 Chief Financial Officers Act of 1990 Agencies Addressed Key Practices for Establishing a Privacy Program

Extent to Which 24 Chief Financial Officers Act of 1990 Agencies Addressed Key Practices for Establishing a Privacy Program

Without fully establishing these elements of their privacy programs, agencies have less assurance that they are consistently implementing privacy protections.

Agencies most frequently cited the following challenges in implementing their privacy programs (see table). Additional information sharing could help agencies address selected challenges.

24 Chief Financial Officer Act of 1990 Agency Challenges in Implementing Privacy Programs

Challenge

Number of agencies reporting challenge

Having sufficient resources

21

Applying privacy requirements to new technologies

20

Hiring privacy personnel

17

Integrating privacy and security controls

16

Coordinating with other agency offices and programs

15

Ensuring agency programs are implementing privacy requirements

15

Retaining privacy personnel

15

Training privacy professionals

14

Source: GAO analysis of agency data. | GAO-22-105065

Agencies and privacy experts identified benefits of privacy impact assessments, including providing public information and managing risks. However, they also identified factors that can limit the assessments' effectiveness. These include agencies not always initiating privacy impact assessments early enough to affect program decisions; privacy programs not aware of all agency systems with PII; and privacy programs unable to hold agency staff accountable for developing privacy impact assessments.

Addressing key privacy program practices, program challenges, and privacy impact assessment effectiveness requires significant leadership commitment at agencies. In accordance with Office of Management and Budget (OMB) guidance, the 24 agencies have each designated a senior agency official for privacy. However, most of these officials do not have privacy as their primary responsibility and have numerous other duties relating to, for example, managing IT and information security. Officials with primary duties other than privacy are unlikely to spend a majority of their time focused on privacy, and agencies generally delegated operational aspects of their privacy programs to less-senior officials. This makes it less likely that the senior agency officials for privacy will focus their attention on privacy in discussions with other senior agency leaders.

The shortcomings in agency policies and challenges they reported could be better addressed by a senior-level official with privacy as a primary area of responsibility. In particular, such an official could be better positioned to ensure a consistent focus on privacy at the level of senior leadership, facilitate cross-agency coordination, and elevate the importance of privacy. OMB privacy staff stated that they believed codifying a dedicated senior privacy official in statute would strengthen agency programs and better enable them to address challenges. In addition, several agency officials and privacy experts noted that a senior agency leader dedicated to privacy could better ensure cross-agency coordination and elevate the importance of privacy. Establishing such a position in law could enhance the leadership commitment needed to give attention to privacy issues across the government.

Why GAO Did This Study

The protection of personal privacy has become a more significant issue in recent years with the advent of new technologies and the proliferation of personal information. Federal agencies collect and process large amounts of PII for various government programs. Accordingly, they must ensure that any PII they collect, store, or process is protected from unauthorized access, tampering, or loss.

Federal agencies are required to establish privacy programs for the protection of PII that they collect and process. Among other things, this includes designating a senior agency official for privacy with overall responsibility for the agency's privacy program. In addition, agencies are to conduct privacy impact assessments to analyze how personal information is collected, stored, shared, and managed in a federal system.

GAO was asked to review federal agencies' privacy programs. This report examines (1) the extent to which agencies have established programs for ensuring privacy protections; (2) challenges agencies reported experiencing in implementing their privacy programs; (3) reported benefits and limitations in agencies' use of privacy impact assessments; and (4) the extent to which agencies have senior leadership dedicated to privacy issues.

To do so, GAO compared policies and procedures at the 24 CFO Act agencies to key practices for establishing privacy programs. These practices included privacy compliance activities, coordination between privacy and other agency programs or functions, and activities to manage privacy risks.

In addition, GAO surveyed the 24 agencies on benefits and limitations of privacy impact assessments, and on challenges in implementing their privacy programs. GAO also interviewed privacy experts, relevant agency officials, and staff at OMB's privacy branch.

Recommendations

GAO is recommending one matter for congressional consideration, that Congress consider legislation to designate a dedicated, senior-level privacy official at agencies that currently lack one. GAO is also making two recommendations to OMB to facilitate information sharing to help agencies address selected challenges and better implement privacy impact assessments.

Finally, GAO is making 62 recommendations to selected agencies to fully implement key practices for their privacy programs. This includes fully establishing policies and procedures for coordination between privacy programs and other agency functions and incorporating privacy into risk management activities.

Twenty agencies, including OMB, agreed with the recommendations, and several described planned actions to implement them. One agency did not explicitly state whether it agreed with the recommendations, but generally agreed with the report. One agency disagreed with the recommendations, while another disagreed with some recommendations and partially agreed with others. Two agencies stated that they had no comments on the report. GAO continues to believe all of its recommendations are warranted.

Matter for Congressional Consideration

Matter Status Comments
Congress should consider legislation to designate a senior privacy official, such as a chief privacy officer, at agencies that currently lack such a position. This position should have privacy as its primary duty, the organizational placement necessary to coordinate with other agency functions and senior leaders, and the authority to ensure that privacy requirements are implemented and privacy concerns are elevated to the head of the agency.
Open
As of April 2023, no new legislation designating a senior privacy official at agencies that currently lack such a position has been enacted.

Recommendations for Executive Action

Agency Affected Recommendation Status
Office of Management and Budget The Director of OMB should take steps to promote, through the Federal Privacy Council or other channels, sharing of information and best practices to help agencies address challenges identified in this report, including the application of privacy requirements and risk management to new and emerging technologies and integrating security and privacy controls. (Recommendation 1)
Open
OMB's Office of Information and Regulatory Affairs stated it agreed with our recommendation and would take steps to address it. As of February 2023, OMB had not provided further updates on actions taken to address this recommendation. Once the agency states that it has taken action, we plan to verify whether implementation has occurred.
Office of Management and Budget The Director of OMB should take steps to promote, through the Federal Privacy Council or other channels, the sharing of information, best practices, and other resources related to conducting privacy impact assessments. (Recommendation 2)
Open
OMB's Office of Information and Regulatory Affairs stated it agreed with our recommendation and would take steps to address it. As of February 2023, OMB had not provided further updates on actions taken to address this recommendation. Once the agency states that it has taken action, we plan to verify whether implementation has occurred.
Department of Agriculture The Secretary of Agriculture should document program management controls and common privacy controls in place or planned for meeting applicable requirements and managing risks. (Recommendation 3)
Closed – Implemented
The Department of Agriculture stated that it generally agreed with the findings and recommendations in our report. In July 2023, USDA updated its privacy program plan, which specifies that the senior agency official for privacy designates which privacy controls the department will treat as program management, common, information system-specific, and hybrid controls. In addition, USDA's privacy controls implementation guidance designates each privacy control as program management, common, hybrid, or system specific. Accordingly, we consider this recommendation to be implemented. By taking these steps, USDA has increased assurance that privacy protections are consistently implemented across the organization and privacy risks are effectively managed.
Department of Agriculture The Secretary of Agriculture should fully define and document a process for ensuring that the senior agency official for privacy, or other designated privacy official, reviews IT capital investment plans and budgetary requests. (Recommendation 4)
Closed – Implemented
The Department of Agriculture stated that it generally agreed with the findings and recommendations in our report. In July 2023, USDA updated its privacy program plan, and the plan specifies that the senior agency official for privacy reviews IT capital investment plans and budgetary requests to ensure that privacy requirements and associated privacy controls, as well as any associated costs, are explicitly identified and included, with respect to any IT resources that will be used to create, collect, use, process, store, maintain, disseminate, disclose, or dispose of personally identifiable information. For IT acquisitions, the USDA Privacy Office has provided privacy-related questions for, and participates in departmental capital planning and investment planning, as well as agency information technology portfolio reviews. Accordingly, we consider this recommendation to be implemented. By taking these steps, USDA is better positioned to ensure privacy requirements and associated controls are identified and included for IT resources that involve PII.
Department of Agriculture The Secretary of Agriculture should fully define and document a process for ensuring that the senior agency official for privacy or other designated privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy. (Recommendation 5)
Closed – Implemented
The Department of Agriculture stated that it generally agreed with the findings and recommendations in our report. In July 2023, USDA updated its privacy program plan, and the plan specifies that the senior agency official for privacy (SAOP) assesses and addresses the hiring, training, and professional development needs of the department with respect to privacy. Additionally, the SAOP coordinates with the Chief Information Officer and Chief Human Capital Officer to maintain and enhance a current workforce planning process, maintain workforce skills, recruit and retain privacy and IT professionals, develop a set of competency requirements for staff, and ensure managers are aware of flexible hiring authorities. Accordingly, we consider this recommendation to be implemented. By taking these steps, USDA is better positioned to identify staffing needs and ensure a qualified privacy workforce.
Department of Agriculture The Secretary of Agriculture should establish a time frame for incorporating privacy into an organization-wide risk management strategy that includes a determination of risk tolerance, and develop and document this strategy. (Recommendation 6)
Open
The Department of Agriculture stated that it generally agreed with the findings and recommendations in our report. As of February 2023, the department stated that its Office of Budget and Program Analysis will incorporate privacy and a process for developing risk tolerance into the USDA Enterprise Risk Management strategy through departmental guidance. It estimated completing these efforts by the end of December 2023. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Agriculture
Priority Rec.
The Secretary of Agriculture should fully define and document the role of the senior agency official for privacy or other designated privacy official in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages, and document these roles. (Recommendation 7)
Closed – Implemented
The Department of Agriculture stated that it generally agreed with the findings and recommendations in our report. In July 2023, USDA provided updated procedures for its risk management process that specify the role of the senior agency official for privacy and other officials in key risk management steps. Specifically, the procedures define the role of the SAOP in approving security categorizations for systems that contain personally identifiable information (PII), overseeing privacy control assessments, and reviewing system authorization packages. Accordingly, we consider this recommendation to be implemented. By taking these steps, USDA is better able to ensure privacy protections are adequately incorporated into systems with PII.
Department of Agriculture The Secretary of Agriculture should establish a time frame for fully developing a privacy continuous monitoring strategy, and develop and document this strategy. (Recommendation 8)
Closed – Implemented
The Department of Agriculture stated that it generally agreed with the findings and recommendations in our report. In May 2023, USDA developed a privacy continuous monitoring strategy that outlines its approach to ensuring that privacy controls are in place and operating as intended. Among other things, the strategy outlines the roles and responsibilities of the department's senior agency official for privacy and chief privacy officer and specifies the frequency at which privacy controls will be assessed on an ongoing basis. Accordingly, we consider this recommendation to be implemented. By taking these steps, USDA increases its ongoing awareness of the state of its privacy controls, which is necessary to support decisions for adequately protecting personally identifiable information.
Department of Commerce
Priority Rec.
The Secretary of Commerce should ensure that its organization-wide risk management strategy includes key elements, including a determination of privacy risk tolerance. (Recommendation 9)
Open
The Department of Commerce agreed with our recommendation and stated that it planned to develop a formal action plan. As of February 2023, Commerce had not provided additional updates on any further actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Defense
Priority Rec.
The Secretary of Defense should establish a time frame for fully defining a process to ensure that the senior agency official for privacy or other designated senior privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy, and document this process. (Recommendation 10)
Open
The Department of Defense concurred with our recommendation and stated that it would take steps to address it by the end of April 2024. Once the department states that it has taken action, we plan to verify if implementation has occurred.
Department of Defense The Secretary of Defense should establish a time frame for incorporating privacy into an organization-wide risk management strategy that includes a determination of risk tolerance, and develop and document this strategy. (Recommendation 11)
Open
The Department of Defense concurred with our recommendation and stated that it would take steps to address it by the end of April 2024. Once the department states that it has taken action, we plan to verify if implementation has occurred.
Department of Defense The Secretary of Defense should establish a time frame for fully developing a privacy continuous monitoring strategy, and develop and document this strategy. (Recommendation 12)
Open
The Department of Defense concurred with our recommendation and stated that it would take steps to address it by the end of April 2024. Once the department states that it has taken action, we plan to verify if implementation has occurred.
Department of Education
Priority Rec.
The Secretary of Education should establish a time frame for updating the department's policies for creating, reviewing, and publishing system of records notices, and make these updates. (Recommendation 13)
Open
The Department of Education concurred with our recommendation and described plans under way to address it. As of February 2023, the department had not provided additional updates on further actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Energy The Secretary of Energy should establish a time frame for fully defining a process for ensuring that the senior agency official for privacy or other designated privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy, and document this process. (Recommendation 14)
Open
The Department of Energy concurred with our recommendation and described planned actions to implement it. As of February 2023, the department stated that it will update its policies to clarify the roles of the senior agency official for privacy and other privacy officials in addressing hiring, training and professional development. The department estimated that it would complete these efforts by the end of June 2023. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Energy The Secretary of Energy should incorporate privacy into an organization-wide risk management strategy that includes a determination of risk tolerance. (Recommendation 15)
Open
The Department of Energy concurred with our recommendation and described planned actions to implement it. As of February 2023, the department stated that it will work to incorporate privacy into the department-wide risk process and estimated completing these efforts by the end of October 2023. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Energy
Priority Rec.
The Secretary of Energy should establish a time frame for fully defining the role of the senior agency official for privacy or other designated privacy official in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages, and document these roles. (Recommendation 16)
Open
The Department of Energy concurred with our recommendation and described planned actions to implement it. As of February 2023, the department stated that its Office of the Chief Information Officer is in the process of updating the department's privacy program order, which will include documenting and defining the role of the SAOP in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages. The program will also review whether additional delegations are needed to empower the SAOP to perform the relevant functions. DOE estimated completing this effort by the end of June 2023. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Health and Human Services
Priority Rec.
The Secretary of Health and Human Services should fully define and document a process for ensuring that the senior agency official for privacy or other designated privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy. (Recommendation 17)
Open
The Department of Health and Human Services concurred with our recommendation and described actions planned to address it. Specifically, the department stated that it planned to more fully define and document the responsibility and process of the senior agency official for privacy in the next iteration of its Policy for Information Security and Privacy Protection. As of February 2024, the department had not provided updates on any further efforts taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Homeland Security The Secretary of Homeland Security should incorporate privacy into an organization-wide risk management strategy that includes a determination of risk tolerance. (Recommendation 18)
Open
The Department of Homeland Security concurred with our recommendation and described plans to implement it. As of February 2023, the department had not provided any updates of further actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Homeland Security
Priority Rec.
The Secretary of Homeland Security should fully define and document the role of the senior agency official for privacy or other designated privacy official in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages. (Recommendation 19)
Open
The Department of Homeland Security concurred with our recommendation and described plans to implement it. As of February 2023, the department had not provided any updates of further actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Homeland Security The Secretary of Homeland Security should fully develop and document a privacy continuous monitoring strategy. (Recommendation 20)
Open
The Department of Homeland Security concurred with our recommendation and described plans to implement it. As of February 2023, the department had not provided any updates of further actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Housing and Urban Development The Secretary of Housing and Urban Development should fully define and document a process for ensuring that the senior agency official for privacy, or other designated privacy official, reviews IT capital investment plans and budgetary requests. (Recommendation 21)
Open
The Department of Housing and Urban Development did not concur with this recommendation, stating that the HUD privacy office participates in the Office of the Chief Information Officer's Configuration Change Management Board and Technical Review Subcommittee. However, based on documentation provided by HUD, it was not clear that this role involved reviewing IT capital investment plans and budgetary requests. We intend to follow up with the department, and once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Housing and Urban Development
Priority Rec.
The Secretary of Housing and Urban Development should incorporate privacy into an organization-wide risk management strategy that includes a determination of risk tolerance. (Recommendation 22)
Open
The Department of Housing and Urban Development did not concur with this recommendation, stating that privacy risks at the enterprise level are addressed through the department's Risk Management Council. However, while a dedicated risk management council can be an important tool for managing agency risks, it does not replace the need for a documented risk management strategy in which the agency explicitly frames its approach to privacy risk. We intend to follow up with HUD, and once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Housing and Urban Development The Secretary of Housing and Urban Development should establish a time frame for fully developing a privacy continuous monitoring strategy, and develop and document this strategy. (Recommendation 23)
Open
The Department of Housing and Urban Development did not concur with this recommendation, stating that it had established a continuous monitoring strategy. However, while the documentation provided by HUD assigns responsibilities for implementing and maintaining privacy controls, it does not establish the frequency at which these controls are to be assessed. We intend to follow up wiht HUD, and once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of the Interior
Priority Rec.
The Secretary of the Interior should establish a time frame for incorporating privacy into an organization-wide risk management strategy that includes a determination of risk tolerance, and develop and document this strategy. (Recommendation 24)
Open
The Department of the Interior concurred with our recommendation. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Justice
Priority Rec.
The Attorney General should incorporate privacy into an organizationwide risk management strategy that includes a determination of risk tolerance. (Recommendation 25)
Open
The Department of Justice did not concur with this recommendation, stating that its existing strategy documents address how it manages privacy risk, including a determination of risk tolerance. However, documentation provided by DOJ did not explicitly discuss the department's approach to determining privacy risk tolerance, including, for example, factors to be considered and acceptable amounts of risk. Accordingly, we continue to believe our recommendation is warranted. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Justice The Attorney General should establish a time frame and fully develop and document a privacy continuous monitoring strategy. (Recommendation 26)
Open
The Department of Justice did not concur with this recommendation, stating that DOJ components must assess all security and privacy controls employed by an information system during initial authorization and assess a subset of controls during continuous monitoring on an ongoing basis. However, documentation provided by DOJ did not specify the frequency with which the department plans to assess each privacy control at the various risk management tiers. Accordingly, we continue to believe our recommendation is warranted. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Labor The Secretary of Labor should fully define and document a process for ensuring that the senior agency official for privacy, or other designated privacy official, reviews IT capital investment plans and budgetary requests. (Recommendation 27)
Open
The Department of Labor stated that it concurred with our recommendation and would take steps to address it. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Labor The Secretary of Labor should fully define and document a process for ensuring that the senior agency official for privacy or other designated privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy. (Recommendation 28)
Open
The Department of Labor stated that it concurred with our recommendation and would take steps to address it. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Labor
Priority Rec.
The Secretary of Labor should fully define and document the role of the senior agency official for privacy or other designated privacy official in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages. (Recommendation 29)
Open
The Department of Labor stated that it concurred with our recommendation and would take steps to address it. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of State The Secretary of State should establish a time frame for incorporating privacy into an organization-wide risk management strategy that includes a determination of risk tolerance, and develop and document this strategy. (Recommendation 30)
Open
The Department of State concurred with our recommendation and described plans under way to address it. As of February 2023, the department stated it planned to establish a time frame for incorporating privacy into an organization-wide risk management strategy that includes a determination of risk tolerance by April 30, 2024. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of State
Priority Rec.
The Secretary of State should establish a time frames for fully defining and the role of the senior agency official for privacy or other designated privacy official in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages, and document these roles. (Recommendation 31)
Open
The Department of State concurred with our recommendation and described plans under way to address it. As of February 2023, the department stated that it planned to fully define and document these roles by April 30, 2024. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of State The Secretary of State should establish a time frame for fully developing a privacy continuous monitoring strategy, and develop and document this strategy. (Recommendation 32)
Open
The Department of State concurred with our recommendation and described plans under way to address it. As of February 2023, the department stated that it planned to fully develop and document a privacy continuous monitoring strategy by April 30, 2024. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Transportation
Priority Rec.
The Secretary of Transportation should fully define and document a process for ensuring that the senior agency official for privacy or other designated privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy. (Recommendation 33)
Open
The Department of Transportation concurred with our recommendation. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Transportation The Secretary of Transportation should incorporate privacy into an organization-wide risk management strategy that includes a determination of risk tolerance. (Recommendation 34)
Open
The Department of Transportation concurred with our recommendation. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of the Treasury The Secretary of the Treasury should fully define and document a process for ensuring that the senior agency official for privacy, or other designated privacy official, reviews IT capital investment plans and budgetary requests. (Recommendation 35)
Open
The Department of the Treasury did not state whether it concurred with our recommendation. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of the Treasury The Secretary of the Treasury should fully define and document a process for ensuring that the senior agency official for privacy or other designated privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy. (Recommendation 36)
Open
The Department of the Treasury did not state whether it concurred with our recommendation. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of the Treasury The Secretary of the Treasury should incorporate privacy into an organization-wide risk management strategy that includes a determination of risk tolerance. (Recommendation 37)
Open
The Department of the Treasury did not state whether it concurred with our recommendation. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of the Treasury
Priority Rec.
The Secretary of the Treasury should establish a time frame for fully defining the role of the senior agency official for privacy or other designated privacy official in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages, and document these roles. (Recommendation 38)
Open
The Department of the Treasury did not state whether it concurred with our recommendation. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of the Treasury The Secretary of the Treasury should fully develop and document a privacy continuous monitoring strategy. (Recommendation 39)
Open
The Department of the Treasury did not state whether it concurred with our recommendation. As of February 2023, the department had not provided further updates on actions taken to address this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Veterans Affairs The Secretary of Veterans Affairs should establish a time frame for defining a process for ensuring that the senior agency official for privacy, or other designated privacy official, reviews IT capital investment plans and budgetary requests, and document this process. (Recommendation 40)
Open
The Department of Veterans Affairs concurred with this recommendation. As of February 2023, the department stated that it planned to complete actions to address this recommendation by the end of March 2023. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Veterans Affairs The Secretary of Veterans Affairs should fully define and document a process for ensuring that the senior agency official for privacy or other designated privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy. (Recommendation 41)
Open
The Department of Veterans Affairs concurred with this recommendation. As of February 2023, the department stated that it planned to complete actions to address this recommendation by the end of September 2023. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Veterans Affairs
Priority Rec.
The Secretary of Veterans Affairs should fully define and document the role of the senior agency official for privacy or other designated privacy official in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages, and document these roles. (Recommendation 42)
Open
The Department of Veterans Affairs concurred with this recommendation. As of February 2023, VA stated that it was updating its relevant policies to address this recommendation and anticipates completion by September 30, 2023. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Department of Veterans Affairs The Secretary of Veterans Affairs should ensure that its privacy continuous monitoring strategy includes a catalog of privacy controls and defines the frequency at which they are to be assessed. (Recommendation 43)
Closed – Implemented
In October 2022, we verified that VA, in response to our recommendation, updated its Privacy Continuous Monitoring Strategy and Privacy Controls Catalog, which outline the department's approach to managing the VA privacy continuous monitoring program, including available privacy controls and the frequency at which they are to be addressed. By taking these steps, VA should have improved awareness of the state of its privacy controls, which is necessary to support decisions for adequately protecting personally identifiable information. Accordingly, we consider this recommendation to be implemented.
Environmental Protection Agency The Administrator of EPA should fully develop and document a privacy continuous monitoring strategy. (Recommendation 44)
Open
The Environmental Protection Agency concurred with our recommendation and described planned actions to address it. As of February 2023, the agency had not provided updates on further actions taken to address this recommendation. Once the agency states that it has taken action, we plan to verify whether implementation has occurred.
General Services Administration The Administrator of GSA should fully define and document a process for ensuring that the senior agency official for privacy, or other designated privacy official, reviews IT capital investment plans and budgetary requests. (Recommendation 45)
Closed – Implemented
The General Services Administration stated that it agreed with our recommendation and was developing plans to address it. GSA agreed with this recommendation and in December 2022 provided evidence showing that it had established such a process. Specifically, GSA's IT Capital Planning and Investment Control process requires, among other things, the Senior Agency Official for Privacy to review and approval of budget submissions. Accordingly, we consider this recommendation to be implemented. By defining and documenting this process, GSA is better positioned to ensure privacy requirements and associated controls are explicitly identified and included with respect to any IT resources that will involve personally identifiable information.
General Services Administration The Administrator of GSA should establish a time frame for fully defining a process for ensuring that the senior agency official for privacy or other designated privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy, and document that process. (Recommendation 46)
Closed – Implemented
The General Services Administration stated that it agreed with our recommendation and was developing plans to address it. As of February 2024, GSA had defined and documented the role of its senior agency official for privacy and chief privacy officer in assessing and addressing privacy workforce needs. Specifically, the SAOP and CPO assess the agency's privacy workforce needs and advise GSA's Office of Human Resources Management on hiring personnel, in accordance with GSA's Privacy Continuous Monitoring Strategy and the Federal Privacy Council and Office of Personnel Management's "Toolkit for Recruiting, Hiring, and Retaining Privacy Professionals in the Federal Government." Accordingly, we consider this recommendation to be implemented. By taking these steps, GSA is better positioned to identify staffing needs and ensure a well qualified privacy workforce.
General Services Administration
Priority Rec.
The Administrator of GSA should fully define and document the role of the senior agency official for privacy or other designated privacy official in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages. (Recommendation 47)
Closed – Implemented
The General Services Administration stated that it agreed with our recommendation. In June 2023, GSA updated its IT Security Procedural Guide: Managing Enterprise Cybersecurity Risk, which defines the GSA cybersecurity risk management process. Among other things, the guide defines and documents the role of the senior agency official for privacy and other privacy officials in key authorization steps, including system categorization, control assessments, and authorization decisions. Accordingly, we consider this recommendation to be implemented. By taking these steps, GSA is better positioned to ensure that privacy protections are consistently applied to systems with personally identifiable information.
National Aeronautics and Space Administration The Administrator of NASA should incorporate privacy into an organization-wide risk management strategy that includes a determination of risk tolerance. (Recommendation 48)
Open
NASA stated that it agreed with our recommendation and was developing plans to address it. As of February 2023, NASA had provided documentation of efforts taken to address this recommendation. We are following up with NASA to collect additional information and verify whether implementation has occurred.
National Aeronautics and Space Administration
Priority Rec.
The Administrator of NASA should fully define and document the role of the senior agency official for privacy or other designated privacy official in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages. (Recommendation 49)
Open
NASA stated that it agreed with our recommendation and was developing plans to address it. As of February 2023, NASA had provided evidence to demonstrate actions taken to implement this recommendation. We are following up with NASA to collect additional information and verify whether implementation has occurred.
Nuclear Regulatory Commission The Chairman of NRC should fully define and document a process for ensuring that the senior agency official for privacy or other designated privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy. (Recommendation 50)
Closed – Implemented
The Nuclear Regulatory Commission stated that it agreed with our recommendation and was developing plans to address it. In May 2023, NRC updated its Privacy Program Plan, which, among other things, specifies the responsibilities of the Senior Agency Official for Privacy (SAOP) with respect to workforce management. Specifically, the SAOP is responsible for ensuring that NRC employees have the appropriate training and education concerning privacy laws, regulations, policies, and procedures and working with NRC stakeholders to ensure that vendors/contractors, with access to PII, who engage in business with NRC, abide by federal privacy requirements. In addition, the SAOP is a voting member of the agency's Human Capital Council and collaborates with members of NRC's Executive Leadership to maintain and enhance the workforce planning process, maintain workforce skills, recruit and retain privacy professionals, and develop a set of competency requirements for staff in the NRC's privacy program. Accordingly, we consider this recommendation to be implemented. By taking these steps, NRC is better positioned to identify staffing needs and ensure a well qualified privacy workforce.
Nuclear Regulatory Commission
Priority Rec.
The Chairman of NRC should fully define and document the role of the senior agency official for privacy or other designated privacy official in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages. (Recommendation 51)
Closed – Implemented
The Nuclear Regulatory Commission stated that it agreed with our recommendation and was developing plans to address it. In September 2023, NRC provided updated privacy policies and procedures which specify the role of the Senior Agency Official for Privacy (SAOP) in key risk management steps for systems with personally identifiable information (PII). Specifically, according to NRC policy, the SAOP and Privacy Officer are consulted regarding system categorizations; the SAOP oversees privacy metrics and control evaluations for systems with PII; and the SAOP reviews authorization packages for systems with PII. Accordingly, we consider this recommendation to be implementation. By taking these steps, NRC has increased assurance that privacy protections are adequately incorporated into systems with PII.
Office of Personnel Management The Director of OPM should establish a time frame for updating the agency's policy for creating, reviewing, and publishing system of records notices, and make these updates. (Recommendation 52)
Open
The Office of Personnel Management partially concurred with this recommendation, noting that it has a process for system of records notices (SORN) while adding it plans to review and update any outdated SORN guidance. In January 2024, OPM officials stated that while the agency may benefit from an updated policy regarding the System of Records Notices (SORN) process at OPM, they adhere to the requirements of the Privacy Act of 1974 and the Office of Management and Budget Circular A-108 in publishing new or updated SORNs. OPM added that it plans to review the current SORN process and policy documentation by the end of Q2 of FY 24, as operational priorities and resources permit. Once the agency states that it has taken action, we will verify whether implementation has occurred.
Office of Personnel Management The Director of OPM should define and document procedures for coordination between privacy and information security functions. (Recommendation 53)
Open
The Office of Personnel Management partially concurred with this recommendation, noting that it has processes in place for such coordination, while stating that it will evaluate the need for increased documentation of coordination between its privacy and security functions. In January 2024, OPM officials stated that OPM has continued to hold a weekly executive meeting with the Senior Agency Official for Privacy (SAOP) and the Chief Information Security Officer (CISO) and their respective deputies to ensure coordination on projects and issues of mutual interest. Additionally, the agency stated that it continues to work on implementing the privacy and security controls in NIST 800-53 revision 5, and any policies and procedures related to that implementation will reflect the necessary coordination. Further, the agency noted that a draft agency-level Cybersecurity and Privacy policy is currently proceeding through OPM's internal review and clearance process, which is planned to clear in fiscal year 2024. Once the agency states that it has taken action to further document this coordination, we plan to verify whether implementation has occurred.
Office of Personnel Management The Director of OPM should fully define and document a policy and process for ensuring that the senior agency official for privacy or other designated privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy. (Recommendation 54)
Open
The Office of Personnel Management did not concur with this recommendation, noting that it has processes in place for the senior agency official for privacy's involvement in workforce planning. In particular, the agency described steps it has taken in this area, including developing a memo in 2020 outlining strategic workforce needs for the Office of Privacy and Information Management. However, OPM has not formalized the role of the SAOP in addressing hiring, training, and professional development needs with respect to privacy, helping to insure the privacy program's ability to advocate for the skilled and qualified staff it needs on an ongoing basis. Accordingly, we believe our recommendation continues to be warranted. In January 2024, OPM stated that it will consider formally documenting the SAOP's role in hiring, training, and professional development by the end of fiscal year 2024 as priorities and resources allow. Once the agency states that it has taken action, we plan to verify whether implementation has occurred.
Office of Personnel Management The Director of OPM should incorporate privacy into an organizationwide risk management strategy that includes a determination of risk tolerance. (Recommendation 55)
Open
The Office of Personnel Management did not concur with this recommendation, stating that its senior agency official for privacy is a member of the OPM Risk Management Council, which identifies, evaluates, and works to mitigate enterprise-wide risk. However, the agency did not develop a documented risk management strategy in which the agency explicitly frames its approach to privacy risk. Accordingly, we continue to believe our recommendation is warranted. In January 2024, OPM stated that it has incorporated privacy risk and mitigation considerations into its enterprise risk management process, which does include determination of risk tolerance on identified privacy risks. OPM further stated that it plans to continue examining its approach to privacy risk management in fiscal years 2024 and 2025 and will look to expand activities consistent with this recommendation, including continuing to work on implementing the privacy and security controls in NIST 800-53 revision 5. Once the agency states that it has taken action to further document its approach to privacy risk management, we plan to verify whether implementation has occurred.
Office of Personnel Management
Priority Rec.
The Director of OPM should establish a time frame for fully defining the role of the senior agency official for privacy or other designated privacy official in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages, and document these roles. (Recommendation 56)
Open
The Office of Personnel Management partially concurred with this recommendation, stating that its privacy team is involved in various activities related to this process and its privacy and security teams are currently examining roles and responsibilities with respect to the controls and their selection and evaluation. As of January 2024, OPM stated that in fiscal years 2024 and 2025, OPM will continue to look for opportunities to document the role of the SAOP more fully in these activities and that this should be satisfied by the draft agency-level Cybersecurity and Privacy policy that is currently undergoing internal review. Once the agency states that it has taken action, we plan to verify whether implementation has occurred.
Office of Personnel Management The Director of OPM should fully develop and document a privacy continuous monitoring strategy. (Recommendation 57)
Open
The Office of Personnel Management partially concurred with this recommendation, stating that it will further evaluate its approach to privacy continuous monitoring and review the need for more comprehensive documentation. As of January 2024, OPM stated that its privacy and security programs work collaboratively to implement revision 5 of the National Institute of Standards and Technology's Special Publication 800-53, revision 5. OPM added that it plans to further evaluate the agency's approach to continuous monitoring and documentation by Q4 of fiscal year 2024 or Q1 of fiscal year 2025. Once the agency states that it has taken action, we plan to verify whether implementation has occurred.
Small Business Administration
Priority Rec.
The Administrator of SBA should fully define and document a process for ensuring that the senior agency official for privacy or other designated privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy. (Recommendation 58)
Open
SBA stated that it agreed with our recommendation and was developing plans to address it. In March 2023, SBA described actions it was taking to address this recommendation and enhance its privacy program, including updating its Privacy Program Plan. The agency stated that it planned to complete these efforts by the second quarter of fiscal year 2024. We continue to follow up with SBA on its efforts.
Social Security Administration The Commissioner of SSA should define and document procedures for coordination between privacy and information security functions. (Recommendation 59)
Closed – Implemented
In January 2024, SSA provided its Cybersecurity Senior Advisory Committee charter which defines and documents procedures for coordination between the agency's privacy and information security function. Specifically, the committee will provide expertise and enable coordination to address the cybersecurity and privacy risks that directly impact SSA's mission and strategic objectives. The committee includes core members from SSA's Office of Information Security, Office of Privacy and Disclosure, and the Office of Systems Operations and Hardware Engineering. Accordingly, we consider this recommendation to be implemented. By taking these steps, SSA is better positioned to consistently consider and incorporate key privacy considerations in security activities.
Social Security Administration The Commissioner of SSA should fully define and document a process for ensuring that the senior agency official for privacy, or other designated privacy official, reviews IT capital investment plans and budgetary requests to ensure privacy requirements and associated controls are explicitly identified and included with respect to any IT resources that will involve PII. (Recommendation 60)
Open
SSA stated that it agreed with our recommendation. In January 2024, SSA officials provided evidence that the integration of the "investment characteristics" selection in their Information Technology (IT) Investments Process Intake Form, which notifies designated privacy staff about proposed IT resources that will process personally identifiable information (PII). However, SSA did not provide a standard operating procedure or of other documentation of its process. We are continuing to follow up with SSA to verify whether implementation has occurred.
Social Security Administration The Commissioner of SSA should fully define and document a process for ensuring that the senior agency official for privacy or other designated privacy official is involved in assessing and addressing the hiring, training, and professional development needs of the agency with respect to privacy. (Recommendation 61)
Open
SSA stated that it agreed with our recommendation. In October 2023, SSA stated that it plans to develop formal agency policy during fiscal year 2024 to more fully address the role of the senior agency official for privacy in training and workforce development. Once the agency states that it has taken action, we plan to verify whether implementation has occurred.
Social Security Administration
Priority Rec.
The Commissioner of SSA should establish a time frame for fully defining the role of the senior agency official for privacy or other designated privacy official in reviewing and approving system categorizations, overseeing privacy control assessments, and reviewing authorization packages, and document these roles. (Recommendation 62)
Open
SSA stated that it agreed with our recommendation. In October 2023, SSA stated that it is evaluating how best to integrate its Privacy Implementation Division into the review and approval process for system categorizations. Once the agency states that it has taken action, we plan to verify whether implementation has occurred.
U.S. Agency for International Development The Administrator of USAID should fully define and document a process for ensuring that the senior agency official for privacy, or other designated privacy official, reviews IT capital investment plans and budgetary requests. (Recommendation 63)
Closed – Implemented
USAID stated that it agreed with our recommendation and described plans to address it. In February 2023, USAID provided evidence showing that it had taken action to address the recommendation. Specifically, USAID took steps to ensure that its Senior Agency Official for Privacy (SAOP) is included as a permanent voting member of the agency's Information Technology Steering Subcommittee (ITSS). The ITSS is an Agency-wide executive IT investment governance body made up of executive representatives from across the agency participate on the ITSS to provide input on business and program needs and make recommendations on investment priorities. The responsibilities of the SAOP include evaluating the privacy impact of all new technology, including its impact on personally identifiable information (PII). Accordingly, we considered this recommendation to be implemented. By establishing this process, USAID is better equipped to ensure privacy requirements and associated controls are explicitly identified and included with respect to any IT resources that will involve PII.
U.S. Agency for International Development The Administrator of USAID should incorporate privacy into an organization-wide risk management strategy that includes a determination of risk tolerance. (Recommendation 64)
Closed – Implemented
USAID stated that it agreed with our recommendation and described plans to address it. In February 2023, USAID provided evidence that it had incorporated privacy, including a determination of risk tolerance, into its risk management strategy. Specifically, the agency updated its risk appetite statement to acknowledge the overlap between privacy and cybersecurity risks as well as other privacy-related risks to better inform decision-making. This includes incorporating privacy considerations into its risk appetite related to various aspects of the IT risk facing the agency. Accordingly, we consider this recommendation to be implemented. By taking these steps, USAID is better positioned to manage privacy risks within acceptable thresholds.

Full Report

Office of Public Affairs

Topics

Chief financial officersContinuous monitoringCybersecurityFederal agenciesInformation securityInformation systemsPersonally identifiable informationPersonnel managementPrivacyPrivacy protectionRisk management