Reports & Testimonies
Recommendations Database
GAO’s recommendations database contains report recommendations that still need to be addressed. GAO’s priority recommendations are those that we believe warrant priority attention. We sent letters to the heads of key departments and agencies, urging them to continue focusing on these issues. Below you can search only priority recommendations, or search all recommendations.
Our recommendations help congressional and agency leaders prepare for appropriations and oversight activities, as well as help improve government operations. Moreover, when implemented, some of our priority recommendations can save large amounts of money, help Congress make decisions on major issues, and substantially improve or transform major government programs or agencies, among other benefits.
As of October 25, 2020, there are 4812 open recommendations, of which 473 are priority recommendations. Recommendations remain open until they are designated as Closed-implemented or Closed-not implemented.
Browse or Search Open Recommendations
Have a Question about a Recommendation?
- For questions about a specific recommendation, contact the person or office listed with the recommendation.
- For general information about recommendations, contact GAO's Audit Policy and Quality Assurance office at (202) 512-6100 or apqa@gao.gov.
Results:
Subject Term: "Critical infrastructure vulnerabilities"
GAO-21-86, Oct 9, 2020
Phone: (202)512-9342
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-629, Sep 22, 2020
Phone: (202) 512-9342
an assessment of cyber-related risk, based on an analysis of the threats to, and vulnerabilities of, critical assets and operations;
measures of performance and formal mechanism to track progress of the execution of activities; and
an analysis of the cost and resources needed to implement the National Cyber Strategy. (Recommendation 1)
Agency: Executive Office of the President: National Security Council
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Congress
Status: Open
Comments: When we determine what steps the Congress has taken, we will provide updated information.
GAO-20-631, Sep 17, 2020
Phone: (202) 512-9342
Agency: Department of the Treasury
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of the Treasury
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Phone: (202) 512-9971
including 5 priority recommendations
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Priority recommendation
Comments: The Department of Defense partially concurred with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Priority recommendation
Comments: The Department of Defense partially concurred with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Priority recommendation
Comments: The Department of Defense did not concur with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Comments: The Department of Defense partially concurred with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Comments: The Department of Defense concurred with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Priority recommendation
Comments: The Department of Defense did not concur with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Priority recommendation
Comments: The Department of Defense partially concurred with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-404, Apr 3, 2020
Phone: (202) 512-8777
Agency: Department of Homeland Security: Transportation Security Administration
Status: Open
Comments: TSA concurred with this recommendation and said it would take steps to implement it by updating the BASE Cybersecurity Security Action Item section to ensure it reflects the NIST Cybersecurity Framework Detect and Recover functions. When we confirm what actions TSA has taken in response to this recommendation, we will provide updated information.
GAO-20-267, Feb 6, 2020
Phone: (202) 512-6240
Agency: Department of Homeland Security: Cybersecurity and Infrastructure Security Agency
Status: Open
Comments: The agency agreed with the recommendation and has taken steps towards implementing it. Specifically, in March 2020 CISA finalized its operations plan for the 2020 elections. CISA's operations plan addresses one of the 13 objectives and key actions from the strategic plan -- monitor threat activity. While CISA's operations plan is to supplement the agency's strategy, the plan does not fully address any of the four lines of effort and the other 12 objectives outlined in the strategic plan. When examining the key actions for the remaining 12 objectives in the strategic plan, we were only able to confirm that 10 of the 27 key actions called for in those strategic plan objectives were fully addressed. We will continue to monitor the agency's progress in implementing our recommendation.
Agency: Department of Homeland Security: Cybersecurity and Infrastructure Security Agency
Status: Open
Comments: The agency agreed with the recommendation and has taken steps towards implementing it. We reported in February 2020 that CISA's strategic plan had only addressed three challenges from its external lessons learned review. Subsequently, CISA addressed two additional challenges in its operations plan, which was finalized in March 2020, and its election infrastructure subsector specific plan, which was updated in March 2020. CISA's plans addressed challenges regarding the agency's role in sharing and collecting intelligence across the election community and facilitating industry-wide vulnerability disclosures. However, CISA has not documented how the agency intends to address other identified challenges and how it will incorporate remedial actions into the agency's 2020 planning. We will continue to monitor the agency's progress in implementing our recommendation.
GAO-20-133, Feb 4, 2020
Phone: (202) 512-6240
Agency: Department of Homeland Security: Office of the Secretary
Status: Open
Comments: DHS has drafted a preliminary strategy to independently validate agencies' actions, using a risk-based approach. However, this strategy has not yet been finalized and needs to more clearly align to the existing directive development process, to which it serves as an addendum. The strategy should include when and how primary and secondary sources of information for independent validation are selected within the directive development process.
Agency: Department of Homeland Security: Office of the Secretary
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-20, Oct 24, 2019
Phone: (202) 512-4841
Agency: Department of Homeland Security
Status: Open
Comments: In providing comments on this report DHS concurred with our recommendation and stated that it planned to update its T&E policy to specify that acquisition programs demonstrate that components and subsystems work together before finalizing a system's design. In July 2020, DHS Test and Evaluation Division (TED) officials said they were in the process of updating the policy and that it was undergoing management review with an anticipated completion in fall 2020. Once finalized, GAO will evaluate the revised policy to determine whether DHS has met the intent of this recommendation.
Agency: Department of Homeland Security
Status: Open
Comments: In providing comments on this report, DHS concurred with our recommendation and stated that it planned to assess the knowledge and skill requirements for the T&E workforce and establish performance goals for the training. DHS Test and Evaluation Division (TED), in coordination with OCPO, also plan to develop strategies to address any deficiencies with the current training that do not meet the identified requirements. In April 2020, TED officials said that they developed a new survey process to obtain recurring feedback from participants on the training's impact on their ability to perform T&E duties as assigned over time to inform the annual review of the T&E curriculum. However, this effort is still in a piloting stage so the extent to which this information is used to assess the training is still unknown at this time. As of July 2020, TED was still in the process of executing these efforts.
Agency: Department of Homeland Security
Status: Open
Comments: In providing comments on this report DHS concurred with our recommendation and stated that it planned to update its T&E policy to specify when in the acquisition lifecycle acquisition program managers should designate a qualified T&E manager. In July 2020, DHS Test and Evaluation Division (TED) officials said they were in the process of revising the policy to include this specification and that it was undergoing management review with an anticipated completion in fall 2020. Once finalized, GAO will evaluate the revised policy to determine whether DHS has met the intent of this recommendation.
Agency: Department of Homeland Security
Status: Open
Comments: In providing comments on this report, DHS concurred with our recommendation and stated that it planned to establish an internal control process to reliably collect and maintain data on acquisition programs' assigned test and evaluation managers. In April 2020, DHS Test and Evaluation Division (TED) reported taking steps to ensure the validity of this data including establishing points of contacts within each component to cross-check collected information for accuracy and having the Director review collected data on a quarterly basis beginning in third quarter fiscal year 2020. As of July 2020, TED was still in the process of improving its internal collection process, but had not completed these efforts.
Agency: Department of Homeland Security
Status: Open
Comments: In providing comments on this report, DHS concurred with our recommendation and stated that it planned to assess the Test and Evaluation Division's (TED) workforce by reviewing current staffing levels and vacancies against the division's roles and responsibilities. The Senior Official Performing the Duties of the Under Secretary for Science and Technology plans to use the results of this review to inform strategic hiring in future years, if needed. In February 2020, DHS released its fiscal year 2020 strategic guidance memorandum for the Science and Technology (S&T) Directorate which included a statement pertaining to resourcing S&T's test and evaluation capabilities. However, as of July 2020, S&T had not yet conducted its review of TED's workforce.
GAO-19-332, Aug 26, 2019
Phone: (202) 512-3841
including 1 priority recommendation
Agency: Department of Energy
Status: Open
Priority recommendation
Comments: DOE agreed with our recommendation. In its response to our report, DOE stated that it was working through an interagency process to develop a National Cyber Strategy Implementation Plan that will consider DOE's Multiyear Plan for Energy Sector Cybersecurity. To fully address our recommendation, DOE should coordinate with DHS and other relevant stakeholders to develop a plan for implementing the federal cybersecurity strategy for the electric grid and ensure that the plan addresses the key characteristics of a national strategy.
Agency: Federal Energy Regulatory Commission
Status: Open
Comments: In August 2020, FERC officials told GAO that the Commission assembled a team to conduct a technical analysis to develop a plan with appropriate next steps to address GAO's recommendations. As part of this effort, FERC issued two documents. In June 2020, FERC issued a Notice of Inquiry seeking comments on (1) whether NERC's cybersecurity standards adequately address certain NIST Cybersecurity Framework categories, and (2) whether modifications to the cybersecurity standards would be appropriate to address the potential risk of a coordinated cyberattack on geographically distributed targets. Additionally, in June 2020, FERC issued a white paper exploring a new framework for providing incentives to transmission facilities for cybersecurity investments that exceed the requirements of NERC's cybersecurity standards. The incentives are designed, in part, to incentivize cybersecurity investments by facilities that are not covered by NERC's cybersecurity standards, according to FERC officials. As of October 2020, this recommendation remains open.
Agency: Federal Energy Regulatory Commission
Status: Open
Comments: In August 2020, FERC officials told GAO that the Commission assembled a team to conduct a technical analysis to develop a plan with appropriate next steps to address GAO's recommendations. As part of this effort, FERC issued two documents. In June 2020, FERC issued a Notice of Inquiry seeking comments on (1) whether NERC's cybersecurity standards adequately address certain NIST Cybersecurity Framework categories, and (2) whether modifications to the cybersecurity standards would be appropriate to address the potential risk of a coordinated cyberattack on geographically distributed targets. Additionally, in June 2020, FERC issued a white paper exploring a new framework for providing incentives to transmission facilities for cybersecurity investments that exceed the requirements of NERC's cybersecurity standards. The incentives are designed, in part, to incentivize cybersecurity investments by facilities that are not covered by NERC's cybersecurity standards, according to FERC officials. As of October 2020, this recommendation remains open.
GAO-19-105, Dec 18, 2018
Phone: (202) 512-6244
Agency: Department of Homeland Security
Status: Open
Comments: DHS provided evidence in December 2019 but it was insufficient to close this recommendation. We will continue to follow-up with DHS.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: As of January 2020, the Office of Management and Budget has not provided sufficient evidence to close this recommendation. We will continue to follow-up with OMB.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: As of January 2020, the Office of Management and Budget has not provided sufficient evidence to close this recommendation. We will continue to follow-up with OMB.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: As of January 2020, the Office of Management and Budget has not provided sufficient evidence to close this recommendation. We will continue to follow-up with OMB.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: As of January 2020, the Office of Management and Budget has not provided sufficient evidence to close this recommendation. We will continue to follow-up with OMB.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: As of January 2020, the Office of Management and Budget has not provided sufficient evidence to close this recommendation. We will continue to follow-up with OMB.
GAO-19-48, Dec 18, 2018
Phone: (404) 679-1875
including 1 priority recommendation
Agency: Department of Homeland Security: Transportation Security Administration
Status: Open
Comments: As of June 2020, TSA reported that it completed a review of the Pipeline Security Guideline criteria for determining critical facilities. TSA sought and received pipeline stakeholder comments following their review of the criteria. According to TSA officials, TSA is sharing draft criteria with federal stakeholders and anticipates completion of the review by December 31, 2020. We will continue to monitor the status of TSA's activities to determine whether our recommendation is fully implemented.
Agency: Department of Homeland Security: Transportation Security Administration
Status: Open
Priority recommendation
Comments: As of June 2020, TSA reported that officials, including TSA's Office of Human Capital Strategic Planning, began collaborating to draft a strategic workforce plan for the pipeline security section of TSA. According to the officials, while this effort was delayed as TSA's Office of Human Capital needed focus on protecting TSA's workforce in response to the COVID-19 public health emergency, progress has been made. Phase one of a four-phase process began the week of 6/8/2020, with a Manpower Study to be completed by October 2020. The second phase will be a job skills/competency analysis and the third and fourth phases are position management and classification, and plan development and approval, respectively. TSA estimated completion of the workforce plan by June 30, 2021. We will continue to monitor the status of these efforts to develop a strategic workforce plan in response to this recommendation.
Agency: Department of Homeland Security: Transportation Security Administration
Status: Open
Comments: As of June 2020, TSA officials reported meeting with representatives from the Department of Homeland Security (DHS) and the Federal Emergency Management Agency (FEMA) in February and March 2019 for their input on the identification of sources relevant to threat, vulnerability, and consequence consistent with the National Infrastructure Protection Plan and DHS critical infrastructure risk mitigation priorities. TSA officials also reported meeting with RAND personnel in March 2020 to discuss possible contract options for addressing this recommendation. Further action on this recommendation has been limited due to work on the COVID-19 response. We will continue to monitor the status of TSA's activities to determine whether our recommendation is fully implemented.
Agency: Department of Homeland Security: Transportation Security Administration
Status: Open
Comments: As of June 2020, DHS officials reported that TSA will take steps to coordinate an independent, external peer review of its Pipeline Relative Risk Ranking Tool after addressing recommendations 4,5, and 6 of this report. DHS estimated that this effort would be completed by April 30, 2021.
GAO-18-407, May 14, 2018
Phone: (202) 512-4841
Agency: Department of Defense: Defense Security Service
Status: Open
Comments: DOD agreed with this recommendation and as of February 2019, stated that it continues to pilot DSS in Transition at cleared facilities and use information gathered from stakeholders, including key government and industry stakeholder organizations to refine the process. On August 12, 2020, DOD stated that DSS was in the process of drafting a Corrective Action Plan. At that time, DOD officials explained that this plan would be completed in the fourth quarter of fiscal year 2019. As of September 2020, this plan has not been completed.
GAO-17-614, Aug 3, 2017
Phone: (202) 512-6244
including 2 priority recommendations
Agency: Office of Personnel Management
Status: Open
Priority recommendation
Comments: OPM partially concurred with the recommendation. OPM has improved its POA&M management system. Using this system, the agency provided, on 08-27-19, milestones showing timely validation of evidence for closing one US-CERT recommendation. However, OPM has not provided support showing timely validation of 16 other US-CERT recommendations that it has closed. OPM needs to provide evidence of timely validation of these 16 completed recommendations, or evidence for the two US-CERT recommendations that remain open, once these two have been closed and validated. As of March 2020, OPM has not yet provided evidence of taking such actions.
Agency: Office of Personnel Management
Status: Open
Priority recommendation
Comments: OPM concurred with the recommendation. In December 2018, OPM stated that it is working with its learning management system vendor to develop role-based training requirements for its continuous monitoring program, but had not yet targeted an expected completion date. To fully implement the recommendation, OPM needs to issue role-based training requirements for individuals who configure and maintain the deployed continuous diagnostics and mitigation tools. As of March 2020, OPM has not yet provided evidence of taking such actions.
GAO-17-668, Jul 27, 2017
Phone: (202) 512-9971
Agency: Department of Defense: Office of the Under Secretary of Defense for Intelligence
Status: Open
Comments: DOD concurred with this recommendation. We reached out to DOD in August 2018 on this recommendation and are awaiting their response.
Agency: Department of Defense: Office of the Principal Cyber Advisor to the Secretary of Defense
Status: Open
Comments: DOD concurred with this recommendation. DOD has implemented one geo-location policy in 2018 relating to operations security that addresses a portion of this recommendation.
Phone: (202) 512-3841
Agency: Department of Energy
Status: Open
Comments: We reported in May 2019 that DOE and NNSA continued to make progress in responding to this recommendation. The draft 2018 annual report contained, as recommended, more complete and uniform information on assessments, though in some cases different terminology was used by programs and sites. As of June 2020, we have requested final 2018, 2019, and 2020 annual reports from NNSA to ensure progress has continued. Once we have received and reviewed the reports, we will update the status of this recommendation.
Agency: Department of Energy
Status: Open
Comments: As of June 2020, DOE has not implemented this recommendation. While DOE program offices (Environmental Management, Science, and Nuclear Energy) are individually considering long-term needs, the program offices are not required by Congress to submit the kind of physical security plan that Congress requires of NNSA. In the absence of Congressional direction, we believe it is unlikely that DOE will fully implement this recommendation.
Agency: Department of Energy
Status: Open
Comments: As of June 2020, we are continuing to monitor actions related to this recommendation. DOE has acknowledged in a classified memorandum the security risks associated with the slow pace of the material control and accountability order. DOE has also developed a plan to implement measures to address these risks in a phased approach with final implementation sometime in the 2020s. Some of the early phases will be complete between 2019 and 2022, but others will extend beyond 2022. As such, it will be important for DOE to continue to report to Congress on residual risk until planned actions are fully completed and their implementation has been verified by the relevant DOE program offices and DOE's Office of Enterprise Assessments. We will update the status of this recommendation once we have we have received and reviewed DOE's classified 2018-2020 annual reports to ensure this action is taken.
GAO-17-163, Feb 1, 2017
Phone: (202) 512-6244
including 2 priority recommendations
Agency: Department of Homeland Security
Status: Open
Priority recommendation
Comments: For all eleven functions, DHS has measures that evaluate compliance with five (1, 2, 5, 6, 7) of the nine principles and considered whether measures and applicability were appropriate for the other four principles. In February 2020, DHS stated that it does not measure any functions' adherence with principle #8 related to safeguarding against unauthorized access or #9 regarding compliance with policies, regulations, and laws related to privacy and civil liberties. Specifically, the agency stated these two principles are a steady state consideration across all mission areas and functions and have no associated identified measure. For the remaining two principles, DHS did not provide measures that were related to prioritizing activities based on level of risk (#3) or ensuring that appropriate consideration of coordination with subject matter experts from industry, academia, and national labs (#4). As such, DHS does not have appropriate means for assessing the eleven functions against those two principles. However, in March 2020, DHS stated that the metrics for 2020 were different than those in 2019. Officials are in the process of creating a mapping between the previously provided metrics and those for 2020. We will review this mapping and determine if the aforementioned is still applicable with the new metrics.
Agency: Department of Homeland Security
Status: Open
Priority recommendation
Comments: For all 11 functions, DHS stated they have a means of evaluating compliance with five (1, 2, 5, 6, 7) of the nine principles. Once DHS provides specific evidence of data tracked in support of the aforementioned compliance measures, we will review to determine if they have closed this recommendation.
Agency: Department of Homeland Security
Status: Open
Comments: In November 2018, DHS invited GAO to observe a vendor's demonstration of the anticipated Unified Workflow Solution (UWS) that officials stated could support closure of this recommendation, when implemented. In February 2020, DHS stated that their planning and design efforts are ongoing and are on track for deployment of a Minimal Viable Product in April 2020. Once DHS has developed and implemented the UWS, we will review their efforts to determine the extent to which the agency has integrated information related to security incidents.
Agency: Department of Homeland Security
Status: Open
Comments: In March 2019, DHS said that they will provide GAO with a list of the entry points into the NCCIC service desk as well as the standard operating procedures (SOP) and process for quality assurance and quality control. Additionally, the development of the NCCIC Unified Workflow Solution (UWS) could impact this recommendation as well. In February 2020, DHS stated that their planning and design efforts are ongoing and are on track for deployment of a Minimal Viable Product in April 2020. Once DHS has developed and implemented the UWS, we will review their efforts to determine the extent to which the agency has integrated information related to security incidents.
Agency: Department of Homeland Security
Status: Open
Comments: In November 2019, DHS stated that while no alerts or advisories are sent only to Section 9 entities, they do have various forms and mechanisms that Section 9 entities receive cybersecurity information: through HSIN Communities of Interest, the CISCP program, the applicable Sector Specific Agencies, and the applicable Section Information Sharing and Analysis Centers. Further analysis of the membership of the aforementioned forums and mechanisms is needed to determine the extent of Section 9 representation.
Agency: Department of Homeland Security
Status: Open
Comments: In November 2019 DHS stated that the legacy Help Desk and operational activity tracking tools continue to be assessed and requirements identified for configuration into the Unified Workflow Solution (UWS). In February 2020, DHS stated that their planning and design efforts are ongoing and are on track for deployment of a Minimal Viable Product in April 2020. Once DHS has developed and implemented the UWS, we will review their efforts to determine the extent to which the agency has integrated information related to security incidents.