Reports & Testimonies
Recommendations Database
GAO’s recommendations database contains report recommendations that still need to be addressed. GAO’s priority recommendations are those that we believe warrant priority attention. We sent letters to the heads of key departments and agencies, urging them to continue focusing on these issues. Below you can search only priority recommendations, or search all recommendations.
Our recommendations help congressional and agency leaders prepare for appropriations and oversight activities, as well as help improve government operations. Moreover, when implemented, some of our priority recommendations can save large amounts of money, help Congress make decisions on major issues, and substantially improve or transform major government programs or agencies, among other benefits.
As of October 25, 2020, there are 4812 open recommendations, of which 473 are priority recommendations. Recommendations remain open until they are designated as Closed-implemented or Closed-not implemented.
Browse or Search Open Recommendations
Have a Question about a Recommendation?
- For questions about a specific recommendation, contact the person or office listed with the recommendation.
- For general information about recommendations, contact GAO's Audit Policy and Quality Assurance office at (202) 512-6100 or apqa@gao.gov.
Results:
Subject Term: "Physical security"
GAO-20-404, Apr 3, 2020
Phone: (202) 512-8777
Agency: Department of Homeland Security: Transportation Security Administration
Status: Open
Comments: TSA concurred with this recommendation and said it would take steps to implement it by updating the BASE Cybersecurity Security Action Item section to ensure it reflects the NIST Cybersecurity Framework Detect and Recover functions. When we confirm what actions TSA has taken in response to this recommendation, we will provide updated information.
GAO-19-649, Aug 22, 2019
Phone: (202) 512-9627
Agency: Department of Defense
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Department of the Army
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Department of the Navy
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Department of the Navy
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-19-138, Dec 20, 2018
Phone: (202) 512-2834
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: In August 2019, GAO contacted OMB to determine if any progress has been made implementing this recommendation. GAO is awaiting OMB's response.
Agency: Department of Homeland Security
Status: Open
Comments: In August 2019, GAO learned that DHS has recently completed the "Physical Access Control System (PACS) Modernization Working Group Charter." This charter was created under the direction of the Co-Chairs of the Federal Chief Information Security Officer Council, Identity, Credentialing and Access Management Subcommittee, and the Program Director of the DHS Interagency Security Committee. The purpose of the PACS Modernization Working Group is to facilitate the implementation and use of the technology and processes related to modernizing electronic-PACS within the federal government, thereby increasing security, coordination, and compliance with national-level policies and standards. GAO is following up with DHS to obtain additional information about this effort and to determine whether it addresses this recommendation.
GAO-19-146R, Dec 19, 2018
Phone: (202) 512-6244
Agency: Department of Agriculture
Status: Open
Comments: In March 2020, the Department of Agriculture asserted that it has implemented the recommendation but has not provided sufficient evidence to support its assertion.
Agency: Department of Agriculture
Status: Open
Comments: In March 2020, the Department of Agriculture asserted that it has implemented the recommendation but has not provided sufficient evidence to support its assertion.
Agency: Department of Agriculture
Status: Open
Comments: In March 2020, the Department of Agriculture asserted that it has implemented the recommendation but has not provided sufficient evidence to support its assertion.
Agency: Department of Agriculture
Status: Open
Comments: In March 2020, the Department of Agriculture asserted that it has implemented the recommendation but has not provided sufficient evidence to support its assertion.
GAO-19-118, Nov 5, 2018
Phone: (202) 512-9627
Agency: Department of Defense: Department of the Army
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Department of the Navy
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Department of the Navy
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Department of the Air Force
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Phone: (202) 512-2834
Agency: Department of Veterans Affairs
Status: Open
Comments: Shortly after the issuance of the report, VA notified GAO that it was in the process of working with the lnteragency Security Committee (ISC) to update its vulnerability assessment program, with a target completion date of January 2019. Despite multiple attempts, as of June 2020, VA has not provided any information on its progress in updating its program.
Agency: Department of Veterans Affairs
Status: Open
Comments: Shortly after the issuance of the report, VA notified GAO that it had identified OS&LE as the internal entity responsible for conducting a complete review of VA's current risk management policies and processes for VA facilities and that it was reviewing an ISC-certified risk assessment tool for possible implementation consideration. Despite multiple attempts, as of June 2020, VA had not provided an update on its efforts to implement this recommendation.
GAO-18-72, Oct 26, 2017
Phone: (202) 512-2834
Agency: Department of Homeland Security: United States Customs and Border Protection
Status: Open
Comments: The U.S. Customs and Border Protection issued an updated Physical Security Policy and Procedures Handbook in January 2020, which includes a series of internal controls and physical security performance measures. We have reviewed the handbook and requested additional information from CBP to determine whether it meets ISC's Risk Management Process for Federal Facilities.
Agency: Department of Transportation
Status: Open
Comments: The Federal Aviation Administration (FAA) has developed, initially tested, and deployed a risk assessment methodology that aligns with the Interagency Security Committee Risk Management Process for Federal Facilities. In August and September of 2019, FAA trained some staff on the new methodology, which is being integrated into the facility security reporting system. After resolving any software compatibility issues, completing all necessary testing and training, and issuing the associated security policy, FAA expects to fully implement the methodology by December 31, 2020.
Agency: Department of Transportation
Status: Open
Comments: The Federal Aviation Administration (FAA) drafted an updated facility security policy and distributed it for comment in October 2019. It received over 300 comments that are currently being addressed. Once completed, the policy is to incorporate a methodology that fully aligns with the Interagency Security Committee Risk Management Process for Federal Facilities for assessing all undesirable events, considering all three factors of risk, and documenting all deviations from the standard countermeasures. FAA plans to publish the new policy to coincide with the implementation of its risk-assessment methodology by December 31, 2020.
Agency: Department of Transportation
Status: Open
Comments: The Federal Aviation Administration's (FAA) update of its facility security policy and its associated databases should help to improve the monitoring and use of physical security information to better assist with risk assessment decision-making. In February 2020, FAA officials said that its facility security reporting system is to be improved with new metrics and executive level reporting. Such improvements are to result in increased program oversight, risk awareness, and mitigation planning. These improvements are to be completed by December 31, 2020 to coincide with full implementation of the components of the risk management framework, such as the risk assessment methodology, personnel training, and policy publication.
Agency: Department of Agriculture
Status: Open
Comments: The U.S. Department of Agriculture is drafting a revised physical-security regulation and manual that is to align with risk management processes, including a tracking and monitoring component. It expects to implement a revised process by the end of 2020.
Agency: Department of Agriculture
Status: Open
Comments: The U.S. Department of Agriculture (USDA) recognizes the need to develop and implement a database to track and monitor physical security assessment schedules across all of its components. As a result, USDA plans to request funding in the President's Budget for fiscal year 2021 to design and build such a database. If sufficient funding is secured and development efforts go as planned, the agency anticipates having the database operational by the end of 2021.
Phone: (202) 512-2834
Agency: National Gallery of Art
Status: Open
Comments: The National Gallery concurred with this recommendation and said it would take steps to implement it. In February 2019, the National Gallery approved the Office of Protection Services' 5-year strategic plan, which included goals for security. However, as of June 2020, work to establish performance measures was not yet complete. We will continue to monitor the National Gallery's progress in implementing this recommendation
Phone: (202) 512-3841
Agency: Department of Energy
Status: Open
Comments: We reported in May 2019 that DOE and NNSA continued to make progress in responding to this recommendation. The draft 2018 annual report contained, as recommended, more complete and uniform information on assessments, though in some cases different terminology was used by programs and sites. As of June 2020, we have requested final 2018, 2019, and 2020 annual reports from NNSA to ensure progress has continued. Once we have received and reviewed the reports, we will update the status of this recommendation.
Agency: Department of Energy
Status: Open
Comments: As of June 2020, DOE has not implemented this recommendation. While DOE program offices (Environmental Management, Science, and Nuclear Energy) are individually considering long-term needs, the program offices are not required by Congress to submit the kind of physical security plan that Congress requires of NNSA. In the absence of Congressional direction, we believe it is unlikely that DOE will fully implement this recommendation.
Agency: Department of Energy
Status: Open
Comments: As of June 2020, we are continuing to monitor actions related to this recommendation. DOE has acknowledged in a classified memorandum the security risks associated with the slow pace of the material control and accountability order. DOE has also developed a plan to implement measures to address these risks in a phased approach with final implementation sometime in the 2020s. Some of the early phases will be complete between 2019 and 2022, but others will extend beyond 2022. As such, it will be important for DOE to continue to report to Congress on residual risk until planned actions are fully completed and their implementation has been verified by the relevant DOE program offices and DOE's Office of Enterprise Assessments. We will update the status of this recommendation once we have we have received and reviewed DOE's classified 2018-2020 annual reports to ensure this action is taken.
GAO-16-435, Apr 12, 2016
Phone: (202) 512-7331
including 1 priority recommendation
Agency: Department of State
Status: Open
Priority recommendation
Comments: State agreed with this recommendation. State acknowledged challenges identifying recipients of equipment across the range of assistance activities, but noted that it would continue to update its systems and procedures to facilitate human rights vetting for recipients of equipment. In April 2017, State reported that it had provided finalized guidance on vetting Egyptian recipients of Foreign Military Financing-funded equipment to Embassy Cairo and that these procedures had been incorporated into a revised version of Embassy Cairo's guide for conducting human rights vetting. At the time, State noted that Embassy Cairo had begun to implement these procedures. However, State subsequently reported that implementation of these procedures lapsed in 2018 due to staff turnover at Embassy Cairo. As of January 2020, State said that it intends to have new standard operating procedures in place for equipment vetting in Egypt later in 2020. In addition, State has not adopted procedures, similar to those in development for Egypt, to be used more broadly in other countries that also receive equipment through the Foreign Military Financing account or through other U.S. assistance programs. As of June 2017, State had added new features to INVEST, its human rights vetting system, to help facilitate vetting of equipment recipients, and published new vetting guidance requiring screening of equipment transfers. However, State has not established global requirements for posts to use the new equipment vetting system features to screen equipment transfers. As of February 2020, State reported that it had developed draft standard operating procedures for conducting equipment vetting globally; however, these procedures are being reviewed internally within the Department and are expected to be finalized later in 2020. We will continue to monitor agency efforts to implement this recommendation.