Reports & Testimonies
Recommendations Database
GAO’s recommendations database contains report recommendations that still need to be addressed. GAO’s priority recommendations are those that we believe warrant priority attention. We sent letters to the heads of key departments and agencies, urging them to continue focusing on these issues. Below you can search only priority recommendations, or search all recommendations.
Our recommendations help congressional and agency leaders prepare for appropriations and oversight activities, as well as help improve government operations. Moreover, when implemented, some of our priority recommendations can save large amounts of money, help Congress make decisions on major issues, and substantially improve or transform major government programs or agencies, among other benefits.
As of October 25, 2020, there are 4812 open recommendations, of which 473 are priority recommendations. Recommendations remain open until they are designated as Closed-implemented or Closed-not implemented.
Browse or Search Open Recommendations
Have a Question about a Recommendation?
- For questions about a specific recommendation, contact the person or office listed with the recommendation.
- For general information about recommendations, contact GAO's Audit Policy and Quality Assurance office at (202) 512-6100 or apqa@gao.gov.
Results:
Subject Term: Cybersecurity
GAO-21-86, Oct 9, 2020
Phone: (202)512-9342
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-629, Sep 22, 2020
Phone: (202) 512-9342
an assessment of cyber-related risk, based on an analysis of the threats to, and vulnerabilities of, critical assets and operations;
measures of performance and formal mechanism to track progress of the execution of activities; and
an analysis of the cost and resources needed to implement the National Cyber Strategy. (Recommendation 1)
Agency: Executive Office of the President: National Security Council
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Congress
Status: Open
Comments: When we determine what steps the Congress has taken, we will provide updated information.
GAO-20-431, Sep 21, 2020
Phone: (202) 512-4456
Agency: Department of Housing and Urban Development
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Housing and Urban Development
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Housing and Urban Development
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Housing and Urban Development
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Housing and Urban Development
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-701, Sep 21, 2020
Phone: (202) 512-7114
Agency: Department of Health and Human Services
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Homeland Security: Directorate of Emergency Preparedness and Response: Federal Emergency Management Agency
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services: Public Health Service: Centers for Disease Control and Prevention
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services: Public Health Service: Centers for Disease Control and Prevention
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services: Public Health Service: Centers for Disease Control and Prevention
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of the Treasury
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of the Treasury
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services: Public Health Service: Centers for Disease Control and Prevention
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Homeland Security
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-631, Sep 17, 2020
Phone: (202) 512-9342
Agency: Department of the Treasury
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of the Treasury
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-598, Aug 18, 2020
Phone: (202) 512-6240
Agency: Department of Homeland Security
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Homeland Security
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Homeland Security
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Homeland Security
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Homeland Security
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Homeland Security
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Transportation: Federal Aviation Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services: Public Health Service: Indian Health Service
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services: Public Health Service: Indian Health Service
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services: Public Health Service: Indian Health Service
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Small Business Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Small Business Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Small Business Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-432, Jul 23, 2020
Phone: (202) 512-4841
Agency: Department of Defense: Office of the Secretary of Defense: Missile Defense Agency
Status: Open
Comments: DOD concurred with the recommendation stating that MDA will conduct an independent assessment as recommended.
Phone: (202) 512-6240
Agency: Department of Defense
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-123, May 27, 2020
Phone: (202) 512-6240
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services: Centers for Medicare and Medicaid Services
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Health and Human Services: Centers for Medicare and Medicaid Services
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Justice: Federal Bureau of Investigation
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Justice: Federal Bureau of Investigation
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Justice: Federal Bureau of Investigation
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of the Treasury: Internal Revenue Service
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of the Treasury: Internal Revenue Service
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Social Security Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Social Security Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Social Security Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-453, May 14, 2020
Phone: (206)287-4804
Agency: Department of Homeland Security: Cybersecurity and Infrastructure Security Agency
Status: Open
Comments: DHS concurred with this recommendation and stated that CISA's Infrastructure Security Division (ISD) will work to develop a documented process for reviewing CFATS cybersecurity guidance at regularly defined intervals. DHS stated in its comments that once the process is documented and implemented, ISD will revise or supplement existing guidance, as appropriate. We will continue to monitor DHS's actions to address the recommendation.
Agency: Department of Homeland Security: Cybersecurity and Infrastructure Security Agency
Status: Open
Comments: DHS concurred with this recommendation stated that CISA agrees that it is important to ensure training supports program goals, whether relating to inspector-specific or program-specific performance maintenance or improvement goals. Regarding inspector performance maintenance or improvement, DHS stated that, among other things, management will ensure that each inspector's individual performance plan fully captures their expected performance goals in the area of cybersecurity. We will continue to monitor DHS's actions to address this recommendation.
Agency: Department of Homeland Security: Cybersecurity and Infrastructure Security Agency
Status: Open
Comments: DHS concurred with this recommendation and stated that CISA agrees that process improvements to better document and evaluate the effectiveness of the training provided to CFATS staff are worthwhile. DHS stated in its comments that CISA will establish policies and procedures intended to ensure that all cybersecurity training provided to chemical security personnel is accounted for in a centralized mechanism. We will continue to monitor DHS's actions taken to address this recommendation.
Agency: Department of Homeland Security: Cybersecurity and Infrastructure Security Agency
Status: Open
Comments: DHS concurred with this recommendation and stated that evaluating the effectiveness of training is beneficial and CISA will work to ensure that all cybersecurity courses provided to CISA chemical security staff are evaluated for effectiveness. DHS also stated that, among other things, CISA will require course evaluation forms from each attendee of any cybersecurity training provided by CISA to its chemical facility staff. We will continue to monitor DHS's actions to address this recommendation.
Agency: Department of Homeland Security: Cybersecurity and Infrastructure Security Agency
Status: Open
Comments: DHS concurred with this recommendation and stated that CISA will develop a concept of operations, which will include goals and requirements for a workforce review and planning effort to ensure the organization addresses the new program's capacity and capability to perform its regulatory, voluntary, and programmatic goals, to include its cybersecurity related functions. We will continue to monitor DHS's actions to address this recommendation.
Agency: Department of Homeland Security: Cybersecurity and Infrastructure Security Agency
Status: Open
Comments: DHS concurred with this recommendation and stated that CISA retains information on cyber integration levels for regulated facilities but that it is not in a readily accessible format. DHS stated in its comments that ISD will execute a contract for new information technology development support for the CSAT system which, once executed, will work with the new support contractor to build a tool to automate the locating and reporting of a facility's cyber integration level data in a more accessible format. We will continue to monitor the status of DHS's actions to address this recommendation.
GAO-20-322, Apr 23, 2020
Phone: (202) 512-6806
Agency: Executive Office of the President: Office of Management and Budget: Office of the Director
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Executive Office of the President: Office of Management and Budget: Office of the Director
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Executive Office of the President: Office of Management and Budget: Office of the Director
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Executive Office of the President: Office of Management and Budget: Office of the Director
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Executive Office of the President: Office of Management and Budget: Office of the Director
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Executive Office of the President: Office of Management and Budget: Office of the Director
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Executive Office of the President: Office of Management and Budget: Office of the Director
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Phone: (202) 512-9971
including 5 priority recommendations
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Priority recommendation
Comments: The Department of Defense partially concurred with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Priority recommendation
Comments: The Department of Defense partially concurred with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Priority recommendation
Comments: The Department of Defense did not concur with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Comments: The Department of Defense partially concurred with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Comments: The Department of Defense concurred with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Priority recommendation
Comments: The Department of Defense did not concur with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Priority recommendation
Comments: The Department of Defense partially concurred with this recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-404, Apr 3, 2020
Phone: (202) 512-8777
Agency: Department of Homeland Security: Transportation Security Administration
Status: Open
Comments: TSA concurred with this recommendation and said it would take steps to implement it by updating the BASE Cybersecurity Security Action Item section to ensure it reflects the NIST Cybersecurity Framework Detect and Recover functions. When we confirm what actions TSA has taken in response to this recommendation, we will provide updated information.
GAO-20-279, Mar 5, 2020
Phone: (202) 512-4456
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: The Office of Management and Budget (OMB) has not yet taken action to address this recommendation. We will continue to monitor the agency's efforts to implement this recommendation.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: The Office of Management and Budget (OMB) has not yet taken action to address this recommendation. We will continue to monitor the agency's efforts to implement this recommendation.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: The Office of Management and Budget (OMB) has not yet taken action to address this recommendation. We will continue to monitor the agency's efforts to implement this recommendation.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: The Office of Management and Budget (OMB) has not yet taken action to address this recommendation. We will continue to monitor the agency's efforts to implement this recommendation.
Agency: Department of Agriculture
Status: Open
Comments: In comments on our report, the Department of Agriculture (Agriculture) agreed with our recommendation and stated that it planned to meet the cost savings target in 2020. We will continue to monitor Agriculture's efforts to implement this recommendation.
Agency: Department of Commerce: Office of the Secretary
Status: Open
Comments: In comments on our report, the Department of Commerce (Commerce) agreed with our recommendation and described actions that they planned to take in order to address the recommendation. We will continue to monitor Commerce's efforts to implement this recommendation.
Agency: Department of Commerce: Office of the Secretary
Status: Open
Comments: In comments on our report, the Department of Commerce (Commerce) agreed with our recommendation and described actions that they planned to take in order to address the recommendation. We will continue to monitor Commerce's efforts to implement this recommendation.
Agency: National Aeronautics and Space Administration
Status: Open
Comments: In comments on our report, the National Aeronautics and Space Administration (NASA) agreed with our recommendation and described actions that the agency planned to take to address the recommendation. NASA stated that it expected to complete these actions by March 31, 2020. Once we have obtained and assessed evidence of the agency's actions taken, we will update the status of this recommendation.
GAO-20-299, Feb 25, 2020
Phone: (202) 512-6240
Agency: Department of Commerce: National Institute of Standards and Technology: Office of the Director
Status: Open
Comments: In written comments provided in July 2020, the Department of Commerce (Commerce) stated that it agreed with our recommendation. It noted that to further establish its Cybersecurity Measurement program, the National Institute of Standards and Technology (NIST) will document its Cybersecurity Measurement program's scope, objectives, and approach, including an inventory of existing measurement resources. Additionally, to further amplify small business awareness of cybersecurity, and of the Cybersecurity Framework, it noted that NIST will develop and publish two Cybersecurity Framework starter profiles tailored toward risk management of business processes important to small business owners. The expected completion date is September 2020.
Agency: Department of Agriculture
Status: Open
Comments: In written comments provided in April 2020, the United States Department of Agriculture (USDA) stated that it concurred with our recommendation. The department stated that it routinely shared framework guidance provided by the Department of Homeland Security and discussed the framework as part of its monthly Sector conference calls and biannual Sector Meetings. It also added that the department will continue to strengthen its coordination efforts.
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Comments: In written comments provided in July 2020, the Department of Defense concurred with our recommendation. The department noted that it had developed processes and resources to help determine the type of framework adoption across the Defense Industrial Base. These include conducting assessments on the implementation of NIST Special Publication (SP) 800-171 , "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations;" and releasing the Defense Industrial Base Implementation Guide for the NIST Cybersecurity Framework. However, the department has yet to report on sector-wide improvements using these processes and resources. Until it does so, its critical infrastructure sector may not fully understand the value of the framework to better protect its critical infrastructure from cyber threats. The expected completion dates are in September and November 2020.
Agency: Department of Energy: Office of the Secretary
Status: Open
Comments: In written comments provided in February 2020, the Department of Energy (DOE) stated that it partially agreed with our recommendation. It noted that DOE will coordinate with the Energy Sector to develop an understanding of sector-wide improvements from use of the framework. The expected completion date is December 2021.
Agency: Environmental Protection Agency
Status: Open
Comments: In written comments provided in July 2020, the Environmental Protection Agency (EPA) stated that it agreed with our recommendation. It noted that it will consult with the Water Sector Coordinating Council, the Department of Homeland Security, and the National Institute of Standards and Technology, as appropriate, to investigate options to collect and report sector-wide improvements, consistent with statutory requirements and the Sector's willingness to participate. However, the department did not provide a timeframe for completing these actions.
Agency: General Services Administration: Office of the Administrator
Status: Open
Comments: In April 2020, the General Services Administration (GSA), in coordination with its co-SSA, the Department of Homeland Security (DHS), provided documentation demonstrating that it had initiated steps to collect and report on sector-wide improvements from use of the NIST Cybersecurity Framework across its critical infrastructure sector. Specifically, the agencies from the government sector had submitted their risk management reports to DHS and OMB that described agencies' action plans to implement the framework, as required under Executive Order 13800 and evaluated the agencies against the five functions of the NIST Cybersecurity Framework: Identify, Detect, Protect, Respond, and Recover. The risk management reports are included as part of OMB's FISMA Annual Report to Congress. According to OMB's FISMA Annual Report to Congress, OMB and DHS determined that 71 of 96 agencies (74 percent) have cybersecurity programs that are either at risk or high risk. As a result, improvements were identified in the form of four core actions in the Federal Cybersecurity Risk Determination Report and Action Plan, which include: (1) Implementing the Cyber Threat Framework to increase cybersecurity threat awareness among Federal agencies, (2) Standardize IT and cybersecurity capabilities, (3) Consolidate agency SOCs to improve incident detection and response capabilities, and (4) Drive accountability across agencies through improved governance processes, recurring risk assessments, and OMB's engagements with agency leadership. We are waiting for additional information from GSA and DHS on the status of the four core actions.
Agency: Department of Health and Human Services: Office of the Secretary
Status: Open
Comments: In written comments provided in January 2020, the Department of Health and Human Services (HHS) stated that it concurred with our recommendation. The department noted that it would work with the appropriate entities to refine and communicate best practices to the sector.
Agency: Department of Homeland Security: Office of the Secretary
Status: Open
Comments: In written comments provided in February 2020, the Department of Homeland Security (DHS) stated that it agreed with our recommendation. It noted that in coordination with the IT Sector Coordinating Council, the department recently issued a survey to small and mid-sized IT sector partners to better understand framework adoption and use within the IT sector. Once the results of the survey are received, DHS's Cybersecurity and Infrastructure Security Agency will determine the feasibility of issuing similar surveys to other sectors, and the potential timelines for completing sector-specific survey modifications, issuing surveys, compiling responses, and developing white papers on the status of framework adoption for each sector. The department expects completion of this work by December 31, 2021.
Agency: Department of Transportation: Office of the Secretary
Status: Open
Comments: In written comments provided in April 2020, the Department of Transportation (DOT) stated that it concurred with our recommendation. It noted that the department (through the Office of the Secretary, Office of Intelligence, Security, and Emergency Response) and the Department of Homeland Security (through the Transportation Security Administration and United States Coast Guard) will coordinate as Co-Sector-Specific Agencies for the Transportation Systems Sector to finalize the development and distribution of a survey instrument to determine the level and type of framework adoption in the Sector. The department expects completion of this work by December 31, 2021.
Agency: Department of the Treasury: Office of the Secretary
Status: Open
Comments: In written comments provided in January 2020, the Department of the Treasury (Treasury) stated that it agreed with our recommendation. The department noted that it will assess using the identified initiatives and their viability for collecting and reporting sector-wide improvements from the use of the NIST Framework. The department did not provide a timeframe for completing these actions.
GAO-20-199, Feb 11, 2020
Phone: (202) 512-9342
Agency: Office of Congressional Workplace Rights
Status: Open
Comments: In January 2020, OCWR noted that it was in the process of revising its IT systems project planning to ensure the development and implementation of policies and procedure incorporating key cybersecurity activities. The agency also stated that it plans to hire an IT Security Project Manager in order to acquire the necessary cybersecurity expertise needed to implement this recommendation and to ensure that sufficient time and resources can be dedicated to the development and implementation of these policies and procedures. We will continue to monitor OCWR's progress in addressing this recommendation.
Agency: Office of Congressional Workplace Rights
Status: Open
Comments: In January 2020, OCWR noted that it was beginning to plan for developing and implementing oversight procedures for each externally-operated system. We will continue to monitor OCWR's progress in addressing this recommendation.
Agency: Office of Congressional Workplace Rights
Status: Open
Comments: In January 2020, OCWR noted that it had expanded the office's IT Director's role to formally include the functions of an IT Risk Executive and was in the process of establishing the roles and responsibilities. We will continue to monitor OCWR's progress in addressing this recommendation.
Agency: Office of Congressional Workplace Rights
Status: Open
Comments: In January 2020, OCWR noted that it was beginning to plan for developing and implementing a cybersecurity risk management strategy. We will continue to monitor OCWR's progress in addressing this recommendation.
Agency: Office of Congressional Workplace Rights
Status: Open
Comments: In January 2020, OCWR noted that, once the position of IT Security Project Manager is filled and the IT Risk Executive functions are formalized, the agency is planning to commit to a time frame for developing and implementing policies and procedures for managing cybersecurity risk. We will continue to monitor OCWR's progress in addressing this recommendation
GAO-20-267, Feb 6, 2020
Phone: (202) 512-6240
Agency: Department of Homeland Security: Cybersecurity and Infrastructure Security Agency
Status: Open
Comments: The agency agreed with the recommendation and has taken steps towards implementing it. Specifically, in March 2020 CISA finalized its operations plan for the 2020 elections. CISA's operations plan addresses one of the 13 objectives and key actions from the strategic plan -- monitor threat activity. While CISA's operations plan is to supplement the agency's strategy, the plan does not fully address any of the four lines of effort and the other 12 objectives outlined in the strategic plan. When examining the key actions for the remaining 12 objectives in the strategic plan, we were only able to confirm that 10 of the 27 key actions called for in those strategic plan objectives were fully addressed. We will continue to monitor the agency's progress in implementing our recommendation.
Agency: Department of Homeland Security: Cybersecurity and Infrastructure Security Agency
Status: Open
Comments: The agency agreed with the recommendation and has taken steps towards implementing it. We reported in February 2020 that CISA's strategic plan had only addressed three challenges from its external lessons learned review. Subsequently, CISA addressed two additional challenges in its operations plan, which was finalized in March 2020, and its election infrastructure subsector specific plan, which was updated in March 2020. CISA's plans addressed challenges regarding the agency's role in sharing and collecting intelligence across the election community and facilitating industry-wide vulnerability disclosures. However, CISA has not documented how the agency intends to address other identified challenges and how it will incorporate remedial actions into the agency's 2020 planning. We will continue to monitor the agency's progress in implementing our recommendation.
GAO-20-133, Feb 4, 2020
Phone: (202) 512-6240
Agency: Department of Homeland Security: Office of the Secretary
Status: Open
Comments: DHS has drafted a preliminary strategy to independently validate agencies' actions, using a risk-based approach. However, this strategy has not yet been finalized and needs to more clearly align to the existing directive development process, to which it serves as an addendum. The strategy should include when and how primary and secondary sources of information for independent validation are selected within the directive development process.
Agency: Department of Homeland Security: Office of the Secretary
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-80, Dec 19, 2019
Phone: (202) 512-4841
Agency: Department of Defense: Office of the Secretary of Defense
Status: Open
Comments: DOD concurred with our recommendation, but as of July 2020 is still working to implement its corrective action plan.
GAO-20-170SP, Dec 19, 2019
Phone: (202) 512-4841
Agency: Department of Homeland Security: Office of the Secretary
Status: Open
Comments: In providing comments on this report, DHS concurred with our recommendation and stated that the Management Directorate's Office of Program Accountability and Risk Management (PARM) developed a checklist based on GAO's Schedule Assessment Guide, among other things, to evaluate programs' IMSs. PARM also plans to develop guidance on schedules which is intended to assist the Component Acquisition Executives (CAE) and acquisition program staff responsible for building IMSs and APBs. In July 2020, PARM officials reported that the schedule checklist was already being used to evaluate and ensure program IMSs adhered to GAO's Schedule Assessment Guide. In addition, PARM officials are updating and drafting guidance on schedules to assist CAEs and program staff when building IMSs and APBs. As of July 2020, PARM was still in the process of executing these efforts.
Agency: Department of Homeland Security: Office of the Secretary
Status: Open
Comments: DHS concurred with our recommendation and stated that Management Directorate's Office of Program Accountability and Risk Management (PARM) was in the process of revising the Systems Engineering Life Cycle Guidebook and would clarify the language relating to IMSs to ensure guidance is consistent. As of July 2020, PARM was still in the process of revising the Systems Engineering Life Cycle Guidebook.
GAO-20-129, Oct 30, 2019
Phone: (202)512-4456
including 1 priority recommendation
Agency: Department of Agriculture
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Education
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Energy
Status: Open
Comments: In July 2020, the department reported actions it had taken to fully implement the activities associated with assessing competencies and needs regularly; assessing gaps in competencies and staffing; monitoring the agency's progress in addressing competency and staffing gaps; and reporting to agency leadership on progress in addressing competency and staffing gaps. The department also reported actions it had taken to address the remaining four activities and provided estimated time frames for fully implementing them. As of August 2020, we were following up with the department to obtain supporting documentation for the activities it claimed it had fully implemented and status updates for the remaining activities.
Agency: Department of Homeland Security
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Housing and Urban Development
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of the Interior
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Justice
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Labor
Status: Open
Comments: In December 2019, Labor officials provided additional documentation on actions taken to address the recommendation. We plan to review the documentation, and when we confirm what actions the agency has taken, we will provide updated information.
Agency: Department of State
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Veterans Affairs
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Environmental Protection Agency
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: General Services Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: National Science Foundation
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Nuclear Regulatory Commission
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Office of Personnel Management
Status: Open
Priority recommendation
Comments: In December 2019, OPM stated that it had partnered with the General Services Administration's IT Modernization Center of Excellence to assess the current state of its IT workforce planning activities, but had not yet implemented any of the eight key planning activities we recommended. We will continue to monitor OPM's efforts to implement the recommendation.
Agency: Small Business Administration
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Social Security Administration
Status: Open
Comments: In November 2019, Social Security Administration officials provided the agency's recently issued IT workforce strategy for fiscal year 2019 to fiscal year 2022. We plan to review the strategy, and when we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: United States Agency for International Development
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-20-146, Oct 30, 2019
Phone: (202) 512-4841
- acquisition and contracting approach;
- program management structure, including authorities and oversight responsibilities;
- plans for platform and infrastructure development;
- requirements management and development approach, and plans for prioritization;
- risk management plans, including how the program will identify and mitigate risks;
- metrics for measuring quality of software, and how those results will be shared with external stakeholders;
- manpower assessment identifying program workforce needs and state of expertise in Agile methods;
- requirements for reporting program progress to decision makers; and
- yearly funding levels. (Recommendation 1)
Agency: Department of Defense
Status: Open
Comments: DOD concurred with the recommendation and stated that the Under Secretary of Defense for Acquisition and Sustainment directed the Air Force (this work has now been moved to the Space Force) to provide an Acquisition Strategy for approval in November 2019. DOD noted that a strategy template provided to the Air Force included the elements identified by GAO. As of July 2020, the Acquisition Strategy had been submitted to the office of the Under Secretary of Defense for Acquisition and Sustainment, but officials stated that the strategy is still in review and has not yet been finalized.
Agency: Department of Defense
Status: Open
Comments: DOD concurred with this recommendation and stated that the Under Secretary of Defense for Acquisition and Sustainment will assess the need for future periodic and independent reviews of the program. As of July 2020, the Office of the Under Secretary of Defense for Acquisition and Sustainment stated that it had planned to direct an independent review of the program to be conducted by a Federally Funded Research and Development Center and to be completed by September 2020. However, lack of funding and restrictions related to COVID-19 impacted planning. The office still plans to direct this review, but details are pending.
GAO-20-20, Oct 24, 2019
Phone: (202) 512-4841
Agency: Department of Homeland Security
Status: Open
Comments: In providing comments on this report DHS concurred with our recommendation and stated that it planned to update its T&E policy to specify that acquisition programs demonstrate that components and subsystems work together before finalizing a system's design. In July 2020, DHS Test and Evaluation Division (TED) officials said they were in the process of updating the policy and that it was undergoing management review with an anticipated completion in fall 2020. Once finalized, GAO will evaluate the revised policy to determine whether DHS has met the intent of this recommendation.
Agency: Department of Homeland Security
Status: Open
Comments: In providing comments on this report, DHS concurred with our recommendation and stated that it planned to assess the knowledge and skill requirements for the T&E workforce and establish performance goals for the training. DHS Test and Evaluation Division (TED), in coordination with OCPO, also plan to develop strategies to address any deficiencies with the current training that do not meet the identified requirements. In April 2020, TED officials said that they developed a new survey process to obtain recurring feedback from participants on the training's impact on their ability to perform T&E duties as assigned over time to inform the annual review of the T&E curriculum. However, this effort is still in a piloting stage so the extent to which this information is used to assess the training is still unknown at this time. As of July 2020, TED was still in the process of executing these efforts.
Agency: Department of Homeland Security
Status: Open
Comments: In providing comments on this report DHS concurred with our recommendation and stated that it planned to update its T&E policy to specify when in the acquisition lifecycle acquisition program managers should designate a qualified T&E manager. In July 2020, DHS Test and Evaluation Division (TED) officials said they were in the process of revising the policy to include this specification and that it was undergoing management review with an anticipated completion in fall 2020. Once finalized, GAO will evaluate the revised policy to determine whether DHS has met the intent of this recommendation.
Agency: Department of Homeland Security
Status: Open
Comments: In providing comments on this report, DHS concurred with our recommendation and stated that it planned to establish an internal control process to reliably collect and maintain data on acquisition programs' assigned test and evaluation managers. In April 2020, DHS Test and Evaluation Division (TED) reported taking steps to ensure the validity of this data including establishing points of contacts within each component to cross-check collected information for accuracy and having the Director review collected data on a quarterly basis beginning in third quarter fiscal year 2020. As of July 2020, TED was still in the process of improving its internal collection process, but had not completed these efforts.
Agency: Department of Homeland Security
Status: Open
Comments: In providing comments on this report, DHS concurred with our recommendation and stated that it planned to assess the Test and Evaluation Division's (TED) workforce by reviewing current staffing levels and vacancies against the division's roles and responsibilities. The Senior Official Performing the Duties of the Under Secretary for Science and Technology plans to use the results of this review to inform strategic hiring in future years, if needed. In February 2020, DHS released its fiscal year 2020 strategic guidance memorandum for the Science and Technology (S&T) Directorate which included a statement pertaining to resourcing S&T's test and evaluation capabilities. However, as of July 2020, S&T had not yet conducted its review of TED's workforce.
GAO-19-457, Sep 10, 2019
Phone: (202) 512-4456
Agency: Department of Defense
Status: Open
Comments: The Department of Defense did not concur with this recommendation and as of July 2020 has not yet implemented it. According to a December 2019 department letter provided to GAO, the 20 percent software release target is unlikely achievable due to the nature of code that is custom developed by the department. However, the department is mandated by law to implement the open source software pilot program established by the Office of Management and Budget's memorandum M-16-21. Releasing at least 20 percent of newly custom-developed code is a requirement of this program. GAO will continue to follow-up on the status of the pilot program.
Agency: Department of Defense
Status: Open
Comments: The Department of Defense partially agreed with this recommendation and as of July 2020 has not yet implemented it. According to a December 2019 department letter sent to GAO, the department intends to release updated guidance on the release of custom-developed code as open-source software and will include metrics. The department estimated that the updated policy will be completed in the 3rd quarter of fiscal year 2020. GAO will follow-up with the agency to obtain the status of the updated guidance.
GAO-19-332, Aug 26, 2019
Phone: (202) 512-3841
including 1 priority recommendation
Agency: Department of Energy
Status: Open
Priority recommendation
Comments: DOE agreed with our recommendation. In its response to our report, DOE stated that it was working through an interagency process to develop a National Cyber Strategy Implementation Plan that will consider DOE's Multiyear Plan for Energy Sector Cybersecurity. To fully address our recommendation, DOE should coordinate with DHS and other relevant stakeholders to develop a plan for implementing the federal cybersecurity strategy for the electric grid and ensure that the plan addresses the key characteristics of a national strategy.
Agency: Federal Energy Regulatory Commission
Status: Open
Comments: In August 2020, FERC officials told GAO that the Commission assembled a team to conduct a technical analysis to develop a plan with appropriate next steps to address GAO's recommendations. As part of this effort, FERC issued two documents. In June 2020, FERC issued a Notice of Inquiry seeking comments on (1) whether NERC's cybersecurity standards adequately address certain NIST Cybersecurity Framework categories, and (2) whether modifications to the cybersecurity standards would be appropriate to address the potential risk of a coordinated cyberattack on geographically distributed targets. Additionally, in June 2020, FERC issued a white paper exploring a new framework for providing incentives to transmission facilities for cybersecurity investments that exceed the requirements of NERC's cybersecurity standards. The incentives are designed, in part, to incentivize cybersecurity investments by facilities that are not covered by NERC's cybersecurity standards, according to FERC officials. As of October 2020, this recommendation remains open.
Agency: Federal Energy Regulatory Commission
Status: Open
Comments: In August 2020, FERC officials told GAO that the Commission assembled a team to conduct a technical analysis to develop a plan with appropriate next steps to address GAO's recommendations. As part of this effort, FERC issued two documents. In June 2020, FERC issued a Notice of Inquiry seeking comments on (1) whether NERC's cybersecurity standards adequately address certain NIST Cybersecurity Framework categories, and (2) whether modifications to the cybersecurity standards would be appropriate to address the potential risk of a coordinated cyberattack on geographically distributed targets. Additionally, in June 2020, FERC issued a white paper exploring a new framework for providing incentives to transmission facilities for cybersecurity investments that exceed the requirements of NERC's cybersecurity standards. The incentives are designed, in part, to incentivize cybersecurity investments by facilities that are not covered by NERC's cybersecurity standards, according to FERC officials. As of October 2020, this recommendation remains open.
GAO-19-545, Jul 26, 2019
Phone: (202) 512-6244
including 1 priority recommendation
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Priority recommendation
Comments: In January 2020, OMB officials stated that they have incorporated agency feedback for enhancing the CyberStat program into an updated concept of operations document that is currently in draft. To consider this recommendation fully implemented, OMB needs to provide us with an updated concept of operations document for the CyberStat program, and demonstrate the expansion of CyberStat review meetings to agencies that require additional assistance due to persistent information security deficiencies. As of September 2020, OMB has not provided sufficient evidence to close this recommendation.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: As of September 2020, we were still waiting to receive OMB's 180-day letter detailing the actions it plans to take to address the recommendation.
GAO-19-384, Jul 25, 2019
Phone: (202) 512-9342
including 25 priority recommendations
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: The Office of Management and Budget did not say whether or not it concurred with this recommendation. As of January 2020, we had not received information pertaining to this recommendation. Once OMB has provided information, we plan to verify whether implementation has occurred.
Agency: Department of Agriculture
Status: Open
Priority recommendation
Comments: The Department of Agriculture did not state whether or not it concurred with this recommendation. As of February 2020, the department stated that it is developing a Risk Management Framework implementation plan, which is to include a comprehensive Cybersecurity Strategy. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Agriculture
Status: Open
Comments: The Department of Agriculture did not state whether or not it concurred with this recommendation. As of February 2020, the department stated that it is developing a Risk Management Framework implementation plan which will include updates to USDA's process guide to ensure informed security control tailoring and updates to USDA's Plan of Actions and Milestones (POA&M) Standard Operation Procedure to inform prioritized POA&M mitigation strategies, through a consistent and repeatable security risk assessment process. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Agriculture
Status: Open
Priority recommendation
Comments: The Department of Agriculture did not state whether or not it concurred with this recommendation. As of February 2020, the department stated that it plans to establish a governance framework for USDA Enterprise Risk Management (ERM), which will provide a platform to increase coordination between stakeholders within the cybersecurity and enterprise risk management functions. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Commerce
Status: Open
Comments: The Department of Commerce did not state whether or not it concurred with this recommendation. As of January 2020, we had not received information pertaining to planned actions for this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Agency: Department of Commerce
Status: Open
Priority recommendation
Comments: The Department of Commerce did not state whether or not it concurred with this recommendation. As of February 2020, the department stated that its intends to evaluate whether there are any gaps in its cybersecurity policy pertaining to the establishment of an organization-wide cybersecurity risk assessment and will establish a plan to fill in gaps as necessary. The department added that it is making strides in the implementation of a tool that can aggregate data into a dashboard for a unified visibility across the department. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Energy
Status: Open
Priority recommendation
Comments: The Department of Energy concurred with this recommendation. As of January 2020, the department stated that it was developing a department-wide risk management plan, to include a risk management strategy, and this would be completed by May 31, 2020. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Health and Human Services
Status: Open
Priority recommendation
Comments: The Department of Health and Human Services concurred with this recommendation. As of January 2020, HHS stated that it is drafting a cybersecurity risk management memo that will detail its risk management strategy, including how the department will assess, respond to, and monitor risk. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Health and Human Services
Status: Open
Comments: The Department of Health and Human Services partially concurred with this recommendation. As of January 2020, HHS stated that it is in the process of updating its policies to address the missing elements and plans to finalize the revisions by March 2021. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Health and Human Services
Status: Open
Priority recommendation
Comments: The Department of Health and Human Services concurred with this recommendation. As of January 2020, HHS stated that it is drafting a cybersecurity risk management memo and capability model that will include a process for an organization-wide assessment of cybersecurity risk. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Homeland Security
Status: Open
Priority recommendation
Comments: The Department of Homeland Security concurred with this recommendation. As of January 2020, the department stated that it was in the process of developing an enterprise-wide Cybersecurity Risk Management Strategy that will define cybersecurity risk tolerance thresholds and promote inclusion of cybersecurity risk management into the Department's overall risk management capabilities. The estimated completion date for this effort is July 31, 2020. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Agency: Department of Homeland Security
Status: Open
Priority recommendation
Comments: The Department of Homeland Security concurred with this recommendation. As of January 2020, the department stated that, once developed, its Cybersecurity Risk Management Strategy will incorporate clarifications of the cybersecurity risk executive's role and will be coordinated with the DHS Office of the Chief Financial Officer, other offices within the DHS Management Directorate, and Department Components, as appropriate. The department estimated completing this effort by July 31, 2020. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Housing and Urban Development
Status: Open
Priority recommendation
Comments: The Department of Housing and Urban Development concurred with this recommendation. As of January 2020, the department said it planned to develop a cybersecurity risk management strategy that will determine how cybersecurity risks will be identified, framed, assessed, respond to, and monitored. The Department estimated completing this effort by August 2020. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of the Interior
Status: Open
Priority recommendation
Comments: The Department of the Interior concurred with this recommendation. As of January 2020, the department stated that it cybersecurity and enterprise risk management teams would establish a process for bi-directional communication and status reporting. The Department estimated completing this effort by July 31, 2020. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Justice
Status: Open
Priority recommendation
Comments: In its comments on our draft report, the Department of Justice did not state whether it concurred with this recommendation. As of January 2020, . the department reported that it had an integrated strategy for identifying, prioritizing, assessing, responding to, monitoring, and reporting on cybersecurity risks. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Agency: Department of Justice
Status: Open
Priority recommendation
Comments: In its comments on our draft report, the Department of Justice did not state whether or not it concurred with this recommendation. As of January 2020, the department stated that it is developing an ongoing mechanism to institutionalize coordination between its cybersecurity and ERM functions in fiscal year 2020. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Agency: Department of Labor
Status: Open
Comments: The Department of Labor concurred with this recommendation. As of January 2020, we had not received information pertaining to this recommendation. Once the department states that it has taken action, we plan to verify whether implementation has occurred.
Agency: Department of State
Status: Open
Comments: The Department of State concurred with this recommendation. As of January 2020, the department stated that it is actively working to update the applicable policies and procedures. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of State
Status: Open
Priority recommendation
Comments: The Department of State concurred with this recommendation. As of January 2020, the department stated that it is actively working to update the applicable policies and procedures. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Transportation
Status: Open
Priority recommendation
Comments: The Department of Transportation concurred with this recommendation. As of January 2020, the department stated that it would update its cybersecurity risk management strategy to include the identified missing elements. The Department estimated completing this effort by October 1, 2020. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Transportation
Status: Open
Comments: The Department of Transportation concurred with this recommendation. As of January 2020, the department stated that it would update it policies and procedures to require an organization-wide cybersecurity risk assessment. The Department estimated completing this effort by July 1, 2020. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of the Treasury
Status: Open
Priority recommendation
Comments: The Department of the Treasury did not state whether or not it concurred with this recommendation. As of January 2020, we had not received information pertaining to this recommendation. Once the department has provided information, we plan to verify whether implementation has occurred.
Agency: Department of the Treasury
Status: Open
Priority recommendation
Comments: The Department of the Treasury did not state whether or not it concurred with this recommendation. As of January 2020, we had not received information pertaining to this recommendation. Once the department has provided information, we plan to verify whether implementation has occurred.
Agency: Department of the Treasury
Status: Open
Comments: The Department of the Treasury did not state whether or not it concurred with this recommendation. As of January 2020, we had not received information pertaining to this recommendation. Once the department has provided information, we plan to verify whether implementation has occurred.
Agency: Department of Veterans Affairs
Status: Open
Priority recommendation
Comments: The Department of Veterans Affairs concurred with this recommendation. As of January 2020, the department stated that it plans to develop a comprehensive risk management strategy in accordance with its updated cybersecurity program directive and plans to finalize the strategy by June 30, 2020. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Veterans Affairs
Status: Open
Comments: The Department of Veterans Affairs concurred with this recommendation. As of January 2020, VA stated that it plans to incorporate this requirement into its updated policies by June 30, 2020. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Veterans Affairs
Status: Open
Priority recommendation
Comments: The Department of Veterans Affairs concurred with this recommendation. As of January 2020, VA stated that it plans to fully document its process for an organization-wide cybersecurity risk assessment by June 30, 2020. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Department of Veterans Affairs
Status: Open
Comments: The Department of Veterans Affairs concurred with this recommendation. As of January 2020, VA described efforts under way to institutionalize coordination between cybersecurity and enterprise risk management functions and stated that this coordination will be documented in detail by June 30, 2020. Once the department has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Environmental Protection Agency
Status: Open
Priority recommendation
Comments: The Environmental Protection Agency did not state whether or not it concurred with this recommendation. As of January 2020, EPA stated that its strategic plans are under review beginning in the fourth quarter of fiscal year 2020. Once the agency has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Environmental Protection Agency
Status: Open
Comments: The Environmental Protection Agency did not state whether or not it concurred with this recommendation. As of January 2020, EPA stated that it is establishing a process to review, update, and reissue its policies. Once the agency has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Environmental Protection Agency
Status: Open
Priority recommendation
Comments: The Environmental Protection Agency did not state whether or not it concurred with this recommendation. As of January 2020, we had not received information pertaining to this recommendation. Once the agency has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Environmental Protection Agency
Status: Open
Comments: The Environmental Protection Agency did not state whether or not it concurred with this recommendation. As of January 2020, we had not received information pertaining to this recommendation. Once the agency has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: General Services Administration
Status: Open
Priority recommendation
Comments: The General Services Administration concurred with this recommendation. As of January 2020, the agency stated that it would establish a process for conducting an organization-wide cybersecurity risk assessment. The administration estimated completing this effort by June 30, 2020. Once the administration has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: National Aeronautics and Space Administration
Status: Open
Comments: NASA concurred with this recommendation. As of January 2020, the agency stated that it is working to address gaps in its cybersecurity policy. Once NASA has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: National Aeronautics and Space Administration
Status: Open
Priority recommendation
Comments: NASA concurred with this recommendation. As of January 2020, NASA stated that the agency is in the process of documenting its process for conducting an organization-wide cybersecurity risk assessment. NASA's planned completion date for this effort is September 30, 2020. Once NASA has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Nuclear Regulatory Commission
Status: Open
Comments: NRC concurred with this recommendation. As of January 2020, we had not received information pertaining to this recommendation. Once the commission has provided information, we plan to verify whether implementation has occurred.
Agency: Nuclear Regulatory Commission
Status: Open
Comments: NRC concurred with this recommendation. As of January 2020, we had not received information pertaining to this recommendation. Once the commission has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Office of Personnel Management
Status: Open
Comments: OPM concurred with this recommendation. As of January 2020, OPM stated that it planned to update its policies to address the missing elements. Once OPM has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Office of Personnel Management
Status: Open
Priority recommendation
Comments: OPM concurred with this recommendation. As of January 2020, the office stated that it planned to formalize its process for an organization-wide cybersecurity assessment. Once OPM has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Small Business Administration
Status: Open
Priority recommendation
Comments: SBA concurred with this recommendation. As of January 2020, SBA stated that it intends to finalize its process for an agency-wide cybersecurity risk assessment by March 31, 2020. Once SBA has provided evidence of these actions, we plan to verify whether implementation has occurred.
Agency: Social Security Administration
Status: Open
Priority recommendation
Comments: SSA concurred with this recommendation. As of January 2020, SSA stated that it has initiated a formal process for coordination between its cybersecurity risk management and enterprise risk management teams and that this process should be fully established by the third quarter of FY 2020. Once SSA has provided evidence of these actions, we plan to verify whether implementation has occurred.
GAO-19-426, Jun 5, 2019
Phone: (202) 512-8777
Agency: Department of Homeland Security: Transportation Security Administration
Status: Open
Comments: DHS concurred with this recommendation and stated that TSA will periodically review, and as appropriate, update the 2010 Pipeline Security and Incident Recovery Protocol Plan to ensure the plan reflects relevant changes in pipeline security threats, technology, federal law and policy, and any other factors relevant to the security of the nation's pipeline systems. In October 2019, TSA officials reported that they were in the process of reviewing the 2010 Pipeline Security and Incident Recovery Protocol Plan and anticipated completing the review by December 2019. However, this review was delayed and we will continue to monitor TSA's efforts to implement this recommendation.
Phone: (202)512-2757
including 1 priority recommendation
Agency: Department of Commerce
Status: Open
Priority recommendation
Comments: As of May 2020, the Bureau's program risk registers included a clear indication of the status of mitigation plans; however, the Bureau's portfolio risk register did not, without which there was not a clear indication of which portfolio risk mitigation plans had been approved by management. As of August 2020, the Bureau's portfolio risk register also included a clear indication of mitigation plan status. At that time, we reviewed the Bureau's program and portfolio risk registers to determine whether the Bureau had developed and obtained management approval of mitigation and contingency plans for all risks that required them. We found six risks that met the Bureau's requirements for a contingency plan but did not have an approved contingency plan in place. We notified the Bureau and asked them to ensure that approved mitigation and contingency plans were in place for all risks that required them. We will continue to monitor the Bureau's actions to implement this recommendation.
Agency: Department of Commerce
Status: Open
Comments: In July 2020, the Bureau updated its decennial risk management plan and, in doing so, implemented this recommendation for six of the seven key attributes we identified. The missing attribute was monitoring plans: a description in each mitigation and contingency plan of how the agency will monitor the risk response-with performance measures and milestones, where appropriate-to help track whether the plan is working as intended. According to Bureau officials, rather than requiring this attribute, they instead noted it as a lesson learned for the 2030 Census and documented it in their knowledge management tool. In August 2020, we requested documentation of these actions. Once received, we will assess whether these actions suffice to close the recommendation.
GAO-19-340, May 9, 2019
Phone: (202) 512-9110
including 1 priority recommendation
Agency: Congress
Status: Open
Comments: No action has been taken on this matter as of December 2019.
Agency: Department of the Treasury: Internal Revenue Service
Status: Open
Priority recommendation
Comments: In its initial response to our draft report, IRS disagreed with this recommendation. In November 2019, IRS said that it agreed with the intent of the recommendation, but did not agree to implement it, citing the need for additional explicit authority to establish security requirements for the information systems of paid preparers and others who electronically file. IRS reported that to effectively establish data safeguarding policies and implement strategies enforcing compliance with those policies, a centralized leadership structure requires the statutory authority that clearly communicates the authority of the IRS to do so. Without such authority, implementing the recommendation would be an inefficient, ineffective, and costly use of resources, according to IRS. We disagree that convening a governance structure or other centralized form of leadership would require additional statutory authority or be inefficient, ineffective, and costly. As discussed in the report, IRS has seven different offices across the agency working on information security-related activities that could benefit from centralized oversight and coordination, such as updating existing standards, monitoring Authorized e-file Provider program compliance, and tracking security incident reports.
Agency: Department of the Treasury: Internal Revenue Service
Status: Open
Comments: In its initial response to our draft report, IRS disagreed with this recommendation. In November 2019, IRS said it agreed with this recommendation and would update IRS Publication 1345, Handbook for Authorized IRS e-File Providers of Individual Income Tax Returns, to include security elements that are consistent with the FTC Safeguards Rule. IRS plans to update the publication by November 2020.
Agency: Department of the Treasury: Internal Revenue Service
Status: Open
Comments: In its initial response to our draft report, IRS disagreed with this recommendation. In November 2019, IRS stated it was in agreement with the intent of this recommendation; however, IRS does not plan to implement it without additional statutory authority to require Authorized e-file Provider Program participants to comply with the NIST Special Publication 800-53. We continue to believe that under IRS's existing authority, IRS has already established some information security requirements for a portion of tax software providers, those that are online providers. IRS has the opportunity to further establish standards for all tax software providers by incorporating the subset of NIST controls into its Authorized e-file Provider program, which would capitalize on the work it has completed with the Security Summit members.
Agency: Department of the Treasury: Internal Revenue Service
Status: Open
Comments: IRS agreed with this recommendation and in November 2019 said that it will update IRS Publication 1345, Handbook for Authorized IRS e-File Providers of Individual Income Tax Returns, with a formal memorandum to all internal stakeholders during the annual review process. IRS plans to take this action by November 2020.
Agency: Department of the Treasury: Internal Revenue Service
Status: Open
Comments: In its initial response to our draft report, IRS disagreed with this recommendation. In November 2019, IRS stated it was in agreement with the intent of this recommendation; however, it does not plan to implement it. IRS reported it does not have the statutory authority to establish policy on information security and cybersecurity issues, nor to enforce compliance if noncompliance is observed. Additionally, IRS said that the specialized technical skills required to monitor compliance with information and cybersecurity standards, should statutory authority be granted, would require additional funding to meet those monitoring needs. However, as we reported, IRS already monitors physical aspects of information security, which goes beyond existing Authorized e-file Provider program requirements. Since most individuals now file tax returns electronically, having checks for physical security without comparable checks for cybersecurity does not address current risks, as cyber criminals and fraudsters are increasingly attacking third-party providers, as IRS has noted. We believe that incorporating some basic cybersecurity monitoring into the visits would provide IRS the opportunity to help inform the most vulnerable third-party providers of additional guidance and resources.
Agency: Department of the Treasury: Internal Revenue Service
Status: Open
Comments: In its initial response to our draft report, IRS disagreed with this recommendation. In November 2019, IRS said it agreed with the intent of this recommendation; however it does not plan to implement it. IRS stated that absent statutory authority and funding, an assessment of the different monitoring approaches is moot. We disagree with this conclusion. As discussed in the report, IRS does not systematically monitor the existing security requirements for online providers, nor does it conduct information security or cybersecurity monitoring for all types of Authorized e-file Providers. We believe that IRS could conduct a risk assessment of its current monitoring program within existing statutory authority and make necessary changes that would provide better assurance that all types of providers are receiving some level of oversight and that IRS is addressing the greatest risk areas appropriately.
Agency: Department of the Treasury: Internal Revenue Service
Status: Open
Comments: IRS agreed with this recommendation and in November 2019 said that it would develop a standardized process for all Authorized e-file Providers to report security incidents to IRS. IRS said it plans to update IRS Publication 1345, Handbook for Authorized IRS e-File Providers of Individual Income Tax Returns, to include this standardized process by November 2020.
Agency: Department of the Treasury: Internal Revenue Service
Status: Open
Comments: In its initial response to our draft report, IRS agreed with this recommendation. In November 2019, IRS said it agreed with this recommendation with respect to the formal process for tax professionals to report data breaches to the IRS through the Stakeholder Liaison function within the Communications and Liaison organization. According to IRS, procedures are documented in the Data Breach Incident Reporting Instructions that are followed during the intake process. IRS said that upon completion, the breach information is disseminated to other offices within the IRS, depending on the nature of the breach incident reported. According to IRS, all 2018 and 2019 Tax Pro Data Breach incidents remain stored in the Data Breach module of the Return Preparer Database. We will follow up to confirm the information IRS described and determine if these procedures cover all of the IRS offices included in our report.
GAO-19-431T, Apr 30, 2019
Phone: (202) 512-2757
including 2 priority recommendations
Agency: Department of Commerce
Status: Open
Priority recommendation
Comments: Commerce agreed with our recommendation. It provided an action plan in August 2019. We will review the Bureau's progress in addressing this recommendation as part of our ongoing work on the 2020 Census.
Agency: Department of Commerce
Status: Open
Priority recommendation
Comments: Commerce agreed with our recommendation. In August 2019, the Bureau stated that it is developing a process for tracking and executing corrective actions identified by governing bodies and external entities. We will review the Bureau's progress in addressing this recommendation as part of our ongoing work on the 2020 Census.
GAO-19-164, Apr 9, 2019
Phone: (202) 512-4456
Agency: Department of Homeland Security: Directorate of Emergency Preparedness and Response: Federal Emergency Management Agency
Status: Open
Comments: DHS concurred with this recommendation. We will continue to monitor the department's efforts to implement it.
Agency: Department of Homeland Security: Directorate of Emergency Preparedness and Response: Federal Emergency Management Agency
Status: Open
Comments: DHS concurred with this recommendation. We will continue to monitor the department's efforts to implement it.
Agency: Department of Homeland Security: Directorate of Emergency Preparedness and Response: Federal Emergency Management Agency
Status: Open
Comments: DHS concurred with this recommendation. We will continue to monitor the department's efforts to implement it.
Agency: Department of Homeland Security: Directorate of Emergency Preparedness and Response: Federal Emergency Management Agency
Status: Open
Comments: DHS concurred with this recommendation. We will continue to monitor the department's efforts to implement it.
Agency: Department of Homeland Security: Directorate of Emergency Preparedness and Response: Federal Emergency Management Agency
Status: Open
Comments: DHS concurred with this recommendation. We will continue to monitor the department's efforts to implement it.
Agency: Department of Homeland Security: Directorate of Emergency Preparedness and Response: Federal Emergency Management Agency
Status: Open
Comments: DHS concurred with this recommendation. We will continue to monitor the department's efforts to implement it.
GAO-19-144, Mar 12, 2019
Phone: (202) 512-6244
including 10 priority recommendations
Agency: Department of Agriculture
Status: Open
Priority recommendation
Comments: The Department of Agriculture concurred with our recommendation and stated that it was identifying an internal team of subject-matter experts to collaborate with organizations across the department to review the assignment of the "000" code to positions and assist in determining the appropriate work role codes. As of April 2020, USDA expected to complete this activity by fall 2020. To fully implement this recommendation, USDA will need to provide evidence that it has assigned appropriate NICE framework work role codes to its positions in the 2210 IT management occupational series.
Agency: Department of Commerce
Status: Open
Priority recommendation
Comments: The Department of Commerce concurred with the recommendation, but as of January 2020, it had not yet provided sufficient evidence that it had implemented the recommendation. We will continue to monitor the situation.
Agency: Department of Defense
Status: Open
Comments: The Department of Defense concurred with the recommendation but as of January 2020, it had not yet provided sufficient evidence that it had implemented the recommendation. We will continue to monitor the situation.
Agency: Department of Defense
Status: Open
Priority recommendation
Comments: The Department of Defense concurred with the recommendation. As of January 2020, it had not yet provided sufficient evidence that it had implemented the recommendation. To fully implement this recommendation, DOD will need to provide evidence that it has assigned appropriate National Initiative for Cybersecurity Education framework work role codes to its positions in the 2210 Information Technology management occupational series and assessed the accuracy of position descriptions.
Agency: Department of Health and Human Services
Status: Open
Priority recommendation
Comments: The Department of Health and Human Services concurred with the recommendation and stated that it would complete a review of the assignment of the "000" code to its positions in the 2210 IT management occupational series and assign the appropriate NICE framework work role codes. As of March 2020, HHS has made significant progress toward reviewing the assignment of work role codes to its positions in the 2210 IT management occupational series and ensuring that such positions are not coded with the "000" code. To fully implement this recommendation, HHS will need to provide evidence that it has assigned the appropriate NICE framework work role codes to all or nearly all of its remaining positions in the 2210 IT management occupational series. We will continue to monitor the situation.
Agency: Department of Homeland Security
Status: Open
Priority recommendation
Comments: The Department of Homeland Security (DHS) concurred with our recommendation. DHS conducted an audit of its components' cybersecurity coding efforts in fiscal year 2018 and identified actions that components needed to take to complete the assignment of appropriate NICE framework work role codes and assess the accuracy of position descriptions; a second audit for fiscal year 2019 is underway, and the department expects to complete its coding efforts by December 2020. As of January 2020, DHS has not yet provided sufficient evidence to demonstrate that it has implemented this recommendation. To fully implement this recommendation, DHS will need to provide evidence that it has assigned appropriate NICE framework work role codes to its positions in the 2210 IT management occupational series and assessed the accuracy of position descriptions.
Agency: Department of Housing and Urban Development
Status: Open
Priority recommendation
Comments: The Department of Housing and Urban Development (HUD) agreed with this recommendation. In January 2020, HUD stated that it was in the process of reviewing its positions in the 2210 IT management occupational series and assigning appropriate work role codes. To fully implement this recommendation, HUD will need to correctly categorize the work roles and functions performed by IT and cyber-related personnel in order to be able to identify critical cybersecurity staffing needs.
Agency: Department of State
Status: Open
Priority recommendation
Comments: The Department of State concurred with the recommendation. In January 2020, we confirmed that State had assigned National Initiative for Cybersecurity Education (NICE) framework work role codes to its positions in the 2210 IT management occupational series. However, the department has not yet provided sufficient evidence to demonstrate that it has completed its efforts to assess the accuracy of position descriptions. To fully implement this recommendation, State will need to provide evidence that it has assessed the accuracy of position descriptions.
Agency: Department of the Treasury
Status: Open
Priority recommendation
Comments: Treasury partially concurred with the recommendation and stated that some positions may not align to work roles in the National Initiative for Cybersecurity Education's (NICE) cybersecurity workforce framework. Treasury stated that it planned to review and validate the work role codes of its IT, cybersecurity, or cyber-related positions by March 2019. However, as of February 2020 Treasury had not provided evidence that it has implemented our recommendation. Until it assigns work role codes that are consistent with the IT, cybersecurity, and cyber-related functions performed by these positions, Treasury will continue to have unreliable information about its cybersecurity workforce that the department will need to identify its workforce roles of critical need.
Agency: Environmental Protection Agency
Status: Open
Comments: The Environmental Protection Agency concurred with the recommendation but as of January 2020, it had not yet provided sufficient evidence that it had implemented the recommendation. We will continue to monitor the situation.
Agency: Environmental Protection Agency
Status: Open
Priority recommendation
Comments: The Environmental Protection Agency concurred with the recommendation and stated that it would complete a review of the assignment of the "000" code to its positions in the 2210 IT management occupational series, assign the appropriate NICE framework work role codes, and assess the accuracy of position descriptions. As of January 2020, EPA has not yet provided sufficient evidence to demonstrate that it has implemented this recommendation. To fully implement this recommendation, EPA will need to provide evidence that it has assigned appropriate NICE framework work role codes to its positions in the 2210 IT management occupational series and assessed the accuracy of position descriptions.
Agency: National Aeronautics and Space Administration
Status: Open
Comments: The National Aeronautics and Space Administration did not concur with the recommendation. As of January 2020, it had not yet provided sufficient evidence that it had implemented the recommendation. We will continue to monitor the situation.
Agency: National Aeronautics and Space Administration
Status: Open
Priority recommendation
Comments: The National Aeronautics and Space Administration (NASA) concurred with our recommendation and stated that it would complete a review of the assignment of the "000" code to its positions in the 2210 IT management occupational series, assign the appropriate NICE framework work role codes, and assess the accuracy of position descriptions. In March 2020, NASA indicated that it expected to implement the recommendation by September 30, 2020. To fully implement this recommendation, NASA will need to provide evidence that it has assigned appropriate NICE framework work role codes to its positions in the 2210 IT management occupational series and assessed the accuracy of position descriptions.
GAO-19-362, Mar 6, 2019
Phone: (202) 512-9971
including 4 priority recommendations
Agency: Department of Defense
Status: Open
Comments: DOD agreed with the recommendation. According to a DOD status report on implementing the recommendations for GAO-19-362 that was provided to us in February 2020, the Army is performing a validation pilot for its Cyberspace Operations Planners Course. After that validation pilot is complete, the Army will establish a time frame for validating its other courses.
Agency: Department of Defense
Status: Open
Comments: DOD agreed with the recommendation. According to a DOD status report on implementing the recommendations for GAO-19-362 that was provided to us in February 2020, the Air Force is coordinating with U.S. Cyber Command to obtain a final determination on the validated knowledge, skills, and abilities; proficiency standards, and skills for the various work roles supported by this training. The Air Force is responsible for developing curriculum for seven of the Cyber Mission Force workroles. DOD estimates that it will take 2 to 4 years to complete validation for all of the courses supporting these workroles.
Agency: Department of Defense
Status: Open
Priority recommendation
Comments: 3. DOD agreed with the recommendation. According to a DOD status report on implementing the recommendations for GAO-19-362 that was provided to us in February 2020, the Army's implementation of this recommendation is dependent upon U.S. Cyber Command establishing master training task lists for phases 2 and 3 of the training. The Army estimates it will complete all required actions to validate phase 2 of its Cyber Mission Force training requirements by June 2020, phase 3 by October 2020, and phase 4 by January 2021.
Agency: Department of Defense
Status: Open
Priority recommendation
Comments: DOD agreed with the recommendation. According to a DOD status report on implementing the recommendations for GAO-19-362 that was provided to us in February 2020, the Navy plans to identify the specific training requirements for phase 3 Cyber Mission Force training by October 31, 2020. Additionally, the Navy reported that it published a policy memorandum establishing a 24-month continuous training and certification cycle for its Cyber Mission Force Teams to address its phase 4 training requirements.
Agency: Department of Defense
Status: Open
Priority recommendation
Comments: DOD agreed with our recommendation. According to a DOD status report on implementing the recommendations for GAO-19-362 that was provided to us in February 2020, the Air Force's phase 2 training plan is contingent upon the completion of U.S. Cyber Command validating the tasks, knowledge, skills, abilities, and proficiency levels that establish the training baseline. Those products are still in coordination and are not finalized. The Air Force did not provide timeframes by which it would be able to develop training plans for its phase 2, 3, and 4 training requirements.
Agency: Department of Defense
Status: Open
Priority recommendation
Comments: DOD agreed with our recommendation. According to a DOD status report on implementing the recommendations for GAO-19-362 that was provided to us in February 2020, the Marine Corps is still developing its response to comprehensively assess and identify Cyber Mission Force training requirements for phases two , three, and four.
Agency: Department of Defense
Status: Open
Comments: DOD agreed with our recommendation. According to a DOD status report on implementing the recommendations for GAO-19-362 that was provided to us in February 2020, U.S. Cyber Command established procedures for assessing teams participating in Joint Exercise Program collective training events. These procedures include the use of highly skilled and independent assessors from deployable training teams and other units to conduct standard assessments using U.S. Cyber Command criteria. DOD reports that the command has captured lessons learned from these procedures and will promulgate a command-wide instruction to further standardize assessments across the force and guide the development of automated assessments conducted with the Persistent Cyber Training Environment. DOD further reports that the procedures described above were first used in the CYBERFLAG 19-1 exercise in June 2019. We are in the process of obtaining documentation from that exercise to verify these procedures.
Agency: Department of Defense
Status: Open
Comments: DOD agreed with our recommendation. According to a DOD status report on implementing the recommendations for GAO-19-362 that was provided to us in February 2020, U.S. Cyber Command will complete this task in September 2020. DOD reports that U.S. Cyber Command has established and made individual training standards available through the Joint Cyber Training and Certification Standards to all services prior to the training transition in October 2018. In October 2019, DOD approved a new organizational structure and new Mission Essential Tasks for Cyber Protection Teams. The training standards were updated and provided to the services, who are using them to validate and develop Joint Curriculum. DOD is currently reviewing a U.S. Cyber Command proposal for the organization and mission essential tasks for Cyber Mission Teams and Cyber Support Teams. Pending DOD approval, U.S. Cyber Command will update and publish revisions to the individual training standards.
GAO-19-105, Dec 18, 2018
Phone: (202) 512-6244
Agency: Department of Homeland Security
Status: Open
Comments: DHS provided evidence in December 2019 but it was insufficient to close this recommendation. We will continue to follow-up with DHS.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: As of January 2020, the Office of Management and Budget has not provided sufficient evidence to close this recommendation. We will continue to follow-up with OMB.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: As of January 2020, the Office of Management and Budget has not provided sufficient evidence to close this recommendation. We will continue to follow-up with OMB.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: As of January 2020, the Office of Management and Budget has not provided sufficient evidence to close this recommendation. We will continue to follow-up with OMB.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: As of January 2020, the Office of Management and Budget has not provided sufficient evidence to close this recommendation. We will continue to follow-up with OMB.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: As of January 2020, the Office of Management and Budget has not provided sufficient evidence to close this recommendation. We will continue to follow-up with OMB.
GAO-19-48, Dec 18, 2018
Phone: (404) 679-1875
including 1 priority recommendation
Agency: Department of Homeland Security: Transportation Security Administration
Status: Open
Comments: As of June 2020, TSA reported that it completed a review of the Pipeline Security Guideline criteria for determining critical facilities. TSA sought and received pipeline stakeholder comments following their review of the criteria. According to TSA officials, TSA is sharing draft criteria with federal stakeholders and anticipates completion of the review by December 31, 2020. We will continue to monitor the status of TSA's activities to determine whether our recommendation is fully implemented.
Agency: Department of Homeland Security: Transportation Security Administration
Status: Open
Priority recommendation
Comments: As of June 2020, TSA reported that officials, including TSA's Office of Human Capital Strategic Planning, began collaborating to draft a strategic workforce plan for the pipeline security section of TSA. According to the officials, while this effort was delayed as TSA's Office of Human Capital needed focus on protecting TSA's workforce in response to the COVID-19 public health emergency, progress has been made. Phase one of a four-phase process began the week of 6/8/2020, with a Manpower Study to be completed by October 2020. The second phase will be a job skills/competency analysis and the third and fourth phases are position management and classification, and plan development and approval, respectively. TSA estimated completion of the workforce plan by June 30, 2021. We will continue to monitor the status of these efforts to develop a strategic workforce plan in response to this recommendation.
Agency: Department of Homeland Security: Transportation Security Administration
Status: Open
Comments: As of June 2020, TSA officials reported meeting with representatives from the Department of Homeland Security (DHS) and the Federal Emergency Management Agency (FEMA) in February and March 2019 for their input on the identification of sources relevant to threat, vulnerability, and consequence consistent with the National Infrastructure Protection Plan and DHS critical infrastructure risk mitigation priorities. TSA officials also reported meeting with RAND personnel in March 2020 to discuss possible contract options for addressing this recommendation. Further action on this recommendation has been limited due to work on the COVID-19 response. We will continue to monitor the status of TSA's activities to determine whether our recommendation is fully implemented.
Agency: Department of Homeland Security: Transportation Security Administration
Status: Open
Comments: As of June 2020, DHS officials reported that TSA will take steps to coordinate an independent, external peer review of its Pipeline Relative Risk Ranking Tool after addressing recommendations 4,5, and 6 of this report. DHS estimated that this effort would be completed by April 30, 2021.
GAO-18-518, Sep 17, 2018
Phone: (202) 512-9342
Agency: Department of Education
Status: Open
Comments: FSA concurred with this recommendation and the agency stated that loan servicers are scheduled to be enrolled in its ongoing security authorization program beginning in fiscal year 2019. In November 2019, FSA officials told us that this recommendation had been implemented; however, they did not provide documentation to demonstrate actions taken to address the recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Education
Status: Open
Comments: FSA stated that it concurred with this recommendation, but the actions it said it planned to take would not fully address it. In November 2019, FSA officials told us that this recommendation had been implemented; however, they did not provide documentation to demonstrate actions taken to address the recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Education
Status: Open
Comments: FSA concurred with this recommendation and described planned actions to address it. In November 2019, FSA officials told us that this recommendation has a pending date of 5/31/2020 for completion When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Education
Status: Open
Comments: FSA partially concurred with this recommendation and described actions it planned to take in response. However, we believe the entire recommendation is still warranted. In November 2019, FSA officials told us that this recommendation had been implemented; however, they did not provide documentation to demonstrate actions taken to address the recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Education
Status: Open
Comments: FSA stated that it partially agreed with this recommendation; however, if effectively implemented, the planned actions it described would address this recommendation. In November 2019, FSA officials told us that this recommendation had been implemented; however, they did not provide documentation to demonstrate actions taken to address the recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Education
Status: Open
Comments: FSA did not concur with this recommendation. However, we believe it is still warranted. In November 2019, FSA officials told us that this recommendation had been implemented; however, they did not provide documentation to demonstrate actions taken to address the recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-18-93, Aug 2, 2018
Phone: (202) 512-4456
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: The agency partially agreed with the recommendation, and planned to issue guidance that addressed eight of the 12 CIO responsibilities discussed in this report that were not included in existing OMB guidance. As of July 2020, the agency had not issued such guidance and asserted that its existing Circular A-130 guidance is adequate to address this recommendation. However, the Circular A-130 does not address these 12 CIO responsibilities. We will continue to monitor the steps the agency takes to address these requirements.
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: The agency agreed with the recommendation to define the authority that Chief Information Officers (CIOs) are to have when agencies report on CIO authority over information technology spending. However, as of July 2020, the agency had not updated its definition. We will continue to monitor the steps the agency takes to address this recommendation.
Agency: Department of Agriculture
Status: Open
Comments: The agency agreed with the recommendation and, in May 2019, the agency revised its departmental policies to address 21 of the 22 responsibility gaps identified in the report. The remaining responsibility is for the Chief Information Officer (CIO) to report annually to the head of the agency on progress made in improving IT personnel capabilities. In particular, while USDA's CIO is required to conduct an annual assessment on IT personnel, there is no indication that the results are reported to the agency head. We will continue to monitor the steps the agency takes to address these requirements.
Agency: Department of Commerce
Status: Open
Comments: The agency agreed with the recommendation and, in October 2018, described a a number of steps it planned to take to address the responsibility gaps identified in the report. We will continue to monitor the steps the agency takes to address these requirements.
Agency: Department of Defense
Status: Open
Comments: We will provide updated information when we confirm what actions the agency has taken in response to this recommendation.
Agency: Department of Education
Status: Open
Comments: We will provide updated information when we confirm what actions the agency has taken in response to this recommendation.
Agency: Department of Energy
Status: Open
Comments: The department planned to complete several steps by the end of 2019. When we confirm these actions, we will provide updated information.
Agency: Department of Health and Human Services
Status: Open
Comments: The agency agreed with the recommendation and revised its policies to address three of the 23 responsibility gaps identified in the report. In particular, it has addressed the responsibilities for the Chief Information Officer to: 1) report directly to the agency head or that official's deputy, 2) improve the management of the agency's IT through portfolio review (PortfolioStat), and 3) maintain an inventory of data centers. We will continue to monitor the steps the agency takes to address the remaining responsibilities.
Agency: Department of Homeland Security
Status: Open
Comments: The agency agreed with the recommendation, and revised and provided additional departmental directives and delegations to address 19 of the 21 responsibility gaps identified in the report. The remaining responsibilities are for the Chief Information Officer (CIO) to 1) review and approve IT contracts, acquisition plans, or strategies; and 2) ensure that all personnel are held accountable for complying with the agency-wide information security program. In particular, while the DHS CIO has the authority to coordinate with the Chief Acquisition Officer on acquisition strategies, coordination is not the same as reviewing and approving. Regarding holding agency personnel accountable for information security, DHS's Sensitive Systems Policy Directive gives that authority to the heads of DHS's components, rather than the DHS CIO. We will continue to monitor the steps the agency takes to address these requirements.
Agency: Department of Housing and Urban Development
Status: Open
Comments: The department indicated that it has work underway to address this recommendation, which it plans to complete in March 2020. When we confirm those actions, we will provide updated information.
Agency: Department of the Interior
Status: Open
Comments: The department planned to review its policies and take corrective actions, as necessary. When we confirm those actions, we will provide updated information.
Agency: Department of Justice
Status: Open
Comments: Justice concurred with our recommendation and started work to address it. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Labor
Status: Open
Comments: Labor has taken a number of steps in response to this recommendation. However, the agency's policies did not address the six key areas of responsibility for CIOs.
Agency: Department of State
Status: Open
Comments: The department has begun changing its policies to address this recommendation. When we review those changes, we will provide updated information.
Agency: Department of Transportation
Status: Open
Comments: DOT agreed with many of the responsibilities in our recommendation, and in September 2019, the agency planned to leverage their technical infrastructure modernization initiative to further define the CIO responsibilities identified in the 18 responsibility gaps identified in the report. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of the Treasury
Status: Open
Comments: When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Department of Veterans Affairs
Status: Open
Comments: VA agreed with our recommendation and, as of January 2020, is working to address the recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Environmental Protection Agency
Status: Open
Comments: EPA neither agreed nor disagreed with our recommendation, but agreed that CIO authorities should be adequately documented in appropriate policies. EPA officials have stated that they continue to work to address this recommendation. When we confirm what actions the agency has taken to address the 20 responsibility gaps identified in the report, we will provide updated information.
Agency: National Aeronautics and Space Administration
Status: Open
Comments: NASA concurred with our recommendation and stated that the agency was updating its policies to address the responsibilities identified in the report. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: National Science Foundation
Status: Open
Comments: NSF agreed with our recommendations, and in February 2020, the agency issued a new CIO Authorities Policy and revised other departmental policies to address 22 of the 23 responsibility gaps identified in the report. The remaining responsibility for the CIO to benchmark agency processes against private and public sector performance has not been established through the agencies' policies. When we confirm what actions the agency has taken in response to the remaining responsibility, we will provide updated information.
Agency: Nuclear Regulatory Commission
Status: Open
Comments: NRC disagreed with our recommendation but generally agreed with our findings, and the agency had departmental policies to address three of the 15 responsibilities identified in the report. In March 2020, the agency stated it was identifying the appropriate agency policy to amend to address the remaining responsibility gaps. It anticipated that it would complete those updates by the end of the second quarter of FY 2020. We will continue to monitor the steps the agency takes to address this requirement.
Agency: Office of Personnel Management
Status: Open
Comments: OPM agreed with our recommendation. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Agency: Small Business Administration
Status: Open
Comments: SBA agreed with most of our recommendations and, in September 2018, the agency said it is revising its departmental policies to address the responsibility gaps identified in the report. SBA's Data Center Optimization Initiative (DCOI) Strategic Plan's revised in 2019 addresses two of the 19 responsibility gaps identified in the report. When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
GAO-18-445, Jul 26, 2018
Phone: (202) 512-3841
Agency: Department of Commerce: National Institute of Standards and Technology
Status: Open
Comments: NIST concurred with this recommendation and, as of May 2020, had taken some steps to implement it. Specifically, NIST provided information indicating it uses multiple information sources to identify potential measurement service gaps. For example, the Associate Director for Laboratory Programs (ADLP) reviews quarterly reports from NIST's laboratory divisions that include information on measurement services. The ADLP may identify measurement service gaps as part of this review. Also, the NIST Measurement Services Council serves the ADLP in an advisory role to identify and address NIST-wide issues related to the quality, relevance, performance, operations, and resources allocated to the health and improvement of NIST measurement services. The Council produces an annual report that addresses the health of NIST's measurement services, including potential changes needed to meet future customer needs. Further, NIST employees may suggest new services through processes established in suborder 5901.01. Many of these efforts also include consideration of potential gaps in NIST's participation in standards development activities. Additionally, NIST Order 5301.00 delegates responsibility to review standards activities and participation across several levels of NIST management. Although these actions may help identify gaps in NIST's participation in standards development activities as well as identify gaps in the measurement services it provides, it is not clear how or whether they fulfill the periodic review of the effectiveness of NIST's participation in documentary standards activities that the ADLP is to conduct under NIST's standards participation policy. We will update our evaluation of NIST's implementation of this recommendation when the agency provides additional information on how the activities described above fulfill the effectiveness review called for by NIST's policy, or provides information documenting that the ADLP has conducted such a review.
GAO-18-466, Jun 14, 2018
Phone: (202) 512-6244
Agency: Department of Commerce
Status: Open
Comments: Department of Commerce (Commerce) officials concurred with our recommendation and planned to evaluate the level of preparedness for cybersecurity personnel not currently holding certifications to take certification exams, and to identify strategies for mitigating any gaps identified. As of August 2020, Commerce had not provided sufficient evidence that it had implemented the recommendation. We will continue to monitor the situation.
Agency: Department of Energy
Status: Open
Comments: Department of Energy (DOE) officials concurred with our recommendation and planned to evaluate the level of preparedness for cybersecurity personnel not currently holding certifications to take certification exams using the National Initiative for Cybersecurity Education (NICE) certification mapping that is due for release in November 2018. DOE officials plan to develop criteria to identify personnel who are prepared to take certification exams and will perform a department-wide evaluation, after which they plan to report to Congress by a target date of September 30, 2019. As of August 2020, DOE had not provided evidence that it had implemented this recommendation. We will continue to monitor the situation.
Agency: Department of the Interior
Status: Open
Comments: Department of the Interior (Interior) concurred with our recommendation. Officials from the department stated they were developing a plan to assess the workforce's preparedness to complete and maintain certifications. Interior officials stated that they were planning to leverage its learning and performance management system for assessing the level of preparedness of cybersecurity personnel to take certification exams and planned to report to Congress by March 2021. As of August 2020, HUD had not provided evidence that it had implemented this recommendation. We will continue to monitor the situation.
Agency: National Aeronautics and Space Administration
Status: Open
Comments: National Aeronautics and Space Administration (NASA) did not concur with our recommendation and has not yet provided evidence that it has implemented the recommendation as of August 2020. We will continue to monitor the situation.
Agency: Small Business Administration
Status: Open
Comments: Small Business Administration (SBA) officials concurred with our recommendation. SBA officials stated that they have made significant progress in the workforce assessment area, and have recently completed an assessment of the SBA's IT workforce and reported on existing skills gaps. SBA officials stated that they plan to execute against the IT workforce plan to include addressing requirements within the Federal Cybersecurity Workforce Assessment Act of 2015. As of August 2020, SBA had not provided evidence that it had implemented the recommendation. We will continue to monitor the situation.
Agency: Small Business Administration
Status: Open
Comments: Small Business Administration (SBA) officials concurred with our recommendation. SBA officials stated that they have made significant progress in the workforce assessment area, and have recently completed an assessment of the SBA's IT workforce and reported on existing skills gaps. SBA officials stated that they plan to execute against the IT workforce plan to include addressing requirements within the Federal Cybersecurity Workforce Assessment Act of 2015. As of August 2020, SBA had not provided evidence that it had implemented the recommendation. We will continue to monitor the situation.
GAO-18-337, May 22, 2018
Phone: (202) 512-4456
Agency: National Aeronautics and Space Administration
Status: Open
Comments: NASA did not concur with this recommendation. As of October 2019, the agency reported that the Office of the Chief Information Officer was beginning its involvement with the agency's Mission Support Architecture Program which aims at re-aligning mission support functions from a decentralized model to an enterprise model. The office's participation in the re-alignment effort has an estimated completion date in fiscal year 2023.
Agency: National Aeronautics and Space Administration
Status: Open
Comments: NASA concurred with this recommendation. In July 2018, NASA reported that the agency intended to address this recommendation by documenting its approach for governing IT investments. In February 2020, NASA reported that the agency remained committed to taking action to address this recommendation and reported that the Office of the Chief Information Officer had established a process to govern IT investment funds and had planned additional modifications for that framework. The agency now expects to complete actions to address this recommendation by November 2020.
Agency: National Aeronautics and Space Administration
Status: Open
Comments: NASA concurred with this recommendation. In July 2018, NASA reported that it had begun updating policies and procedures for developing the portfolio criteria. In April 2019, NASA provided copies of its updated guidance. Among other things, the guidance described criteria for the portfolio and defined policies and procedures for creating the portfolio. As of April 2020, the agency had not yet provided evidence that it had developed policies and procedures for evaluating the portfolio. We plan to continue following up on the status of efforts to address this recommendation.
Agency: National Aeronautics and Space Administration
Status: Open
Comments: NASA concurred with this recommendation. In July 2018, NASA reported that it had hired a Chief Cybersecurity Risk Officer in April 2018 and that it had also approved a charter for an agency-wide Cybersecurity Integration Team. As of September 2020, NASA reported that it intends to deliver a cybersecurity risk management strategy that addresses the elements outlined in this recommendation by 2021.
Agency: National Aeronautics and Space Administration
Status: Open
Comments: NASA concurred with this recommendation. As of September 2020, NASA reported that the Chief Information Officer had initiated a review of the agency's cyber policy management framework and that any related updates were expected to be completed by 2021.
GAO-18-211, Feb 15, 2018
Phone: (202) 512-9342
including 7 priority recommendations
Agency: Department of Agriculture
Status: Open
Priority recommendation
Comments: In written comments, United States Department of Agriculture (USDA) neither agreed nor disagreed with the recommendation in our report, but stated that it would attempt to develop a measurement mechanism as part of its annual data calls to the Food and Agriculture Sector. Specifically, officials stated that the diversity of the sector makes it difficult to develop a method for determining the level and type of framework adoption across the sector that would apply to all members. USDA officials added, however, that the sector coordinating council frequently invites the Department of Homeland Security to semi-annual meetings to present on both the threat to cybersecurity and resources available to support the needs of the sector. However, as of January 2020, USDA officials had yet to develop methods to determine the level and type of framework adoption. Implementing our recommendations to gain a more comprehensive understanding of the framework's use by critical infrastructure sectors is essential to the success of protection efforts.
Agency: Department of Energy
Status: Open
Priority recommendation
Comments: The Department of Energy (DOE) stated that it worked with stakeholders to better align the Cybersecurity Capability Maturity Model (C2M2) with the updated NIST Cybersecurity Framework but did not provide specific information regarding the adoption or use of the framework. To fully address the recommendation, DOE should have a more comprehensive understanding of the framework's use by sector entities if DOE, along with other entities, want to ensure that its facilitation efforts are successful and determine whether organizations are realizing positive results by adopting the framework. We will continue to monitor DOE actions in response to this recommendation.
Agency: Environmental Protection Agency
Status: Open
Priority recommendation
Comments: In written comments, EPA did not explicitly state whether it agreed or disagreed with our recommendation, but said that several factors constrain the agency from implementing the recommendation. EPA also said it agrees that a comprehensive assessment of framework adoption within the water sector would assist with evaluating and tailoring efforts to promote its use. Further, the agency stated that it will continue to work with the Water Sector Coordinating Council and sector partners to promote and facilitate adoption of the cybersecurity framework. The agency also suggested options related to developing cross-sector metrics and survey methods and stated that it will collect available data that may be characterized as cybersecurity framework "awareness," such as downloads of guidance materials and participation in classroom trainings and webinars. However, as of February 2020, EPA had yet to develop methods to determine the level and type of framework adoption. Officials identified steps the department is taking to facilitate framework use. Specifically, EPA officials told us that the agency will coordinate with its Sector Coordinating Council to identify appropriate means to collect and report information, including a survey, to determine the level and type of framework adoption. They explained that, in the past, the water sector expressed concerns with sharing sensitive cybersecurity information and in developing metrics to evaluate cybersecurity practices. . However, EPA officials stated that they have conducted training, webcasts, and outreach related to cybersecurity, including using the framework and tailoring its efforts to sector needs. According to EPA officials, the agency's goal in doing so was to ensure that sector organizations understood the importance of the framework. While the agency has some ongoing initiatives, implementing our recommendation to gain a more comprehensive understanding of the framework's use by its critical infrastructure sector is essential to the success of protection efforts.
Agency: Department of Health and Human Services
Status: Open
Priority recommendation
Comments: In written comments, the Department of Health and Human Services (HHS) concurred with the recommendation in our report and stated that it would work with appropriate entities to assist in sector adoption. HHS officials, in collaboration with NIST and a joint Cybersecurity Working Group, developed 10 best practices in May 2017 (Health Industry Cybersecurity Practices) for the Healthcare and Public Health Services sector based on the framework. These practices allowed stakeholders to identify how to use the framework with existing sector resources by raising awareness and providing vetted cybersecurity practices to enable the organizations to mitigate cybersecurity threats to the sector. In addition, officials from HHS's Assistant Secretary for Preparedness and Response (ASPR) stated that the working group discussed the challenges associated with measuring the use and impact of the NIST framework, and approved the establishment of a task group to further investigate the issue. ASPR officials added that some of the ideas discussed included the use of surveys and identification of a set of voluntary reporting indicators. In its fiscal year 2021 budget justification, HHS noted that it participated in a Health Care SCC Cybersecurity Working Group survey that was sent to group members in June 2019. However, while the survey included a question on the extent a working group member used the framework, SCC officials stated that the survey results were not statistically meaningful. While the department has ongoing initiatives, it had yet to develop methods to determine the level and type of framework adoption. Implementing our recommendations to gain a more comprehensive understanding of the framework's use by critical infrastructure sectors is essential to the success of protection efforts.
Agency: Department of Homeland Security
Status: Open
Priority recommendation
Comments: In written comments, the Department of Homeland Security (DHS) concurred with the recommendation in our report and stated that its National Protection and Programs Directorate, as the sector-specific agency for 9 of the 16 critical infrastructure sectors, will continue to work closely with its private sector partners to ensure framework adoption is a priority. Additionally, the department stated that the directorate will work closely with its private sector partners to better understand the extent of framework adoption and barriers to adoption by entities across their respective sectors. As of January 2020, the department had begun taking steps to develop methods to determine the level and type of framework adoption in the respective sectors. Specifically, in October 2019, DHS, in coordination with its Information Technology (IT) sector partner, administered a survey to all small and midsized IT sector organizations to gather information on, among other things, framework use and plans to report on the results in 2020. DHS officials stated that any small or mid-sized business across all critical infrastructure sectors could complete the survey and that the department had promoted the survey to all sectors.
Agency: Department of Transportation
Status: Open
Priority recommendation
Comments: As of January 2020, the department had begun taking steps to develop methods to determine the level and type of framework adoption in the respective sectors. Specifically, officials in the Department of Transportation's (DOT) Office of Intelligence, Security, and Emergency Response, in coordination with the Department of Homeland Security (DHS), told us that they planned to develop and distribute a survey to the Transportation Systems sector to determine the level and type of framework adoption. DOT officials stated that the draft survey was undergoing DHS legal review and that the completion of the review and subsequent Office of Management and Budget review would determine when the survey is approved for distribution.
Agency: Department of the Treasury
Status: Open
Priority recommendation
Comments: The Department of the Treasury neither agreed nor disagreed with the recommendation in our report. The department stated that it will assess using the identified initiatives and their viability for collecting and reporting sector-wide improvements from use of the framework with input from the sector coordinating council (SCC) and financial regulators. However, as of January 2020, the department had yet to develop methods to determine the level and type of framework adoption. Treasury officials stated that the department, in coordination with the Financial and Banking Information Infrastructure Committee, and in consultation with NIST, developed the Cybersecurity Lexicon in March 2018. The lexicon addressed, among other things, common terminology for cyber terms used in the framework. Additionally, the Financial Services sector, in consultation with NIST, created the Financial Service Sector Cybersecurity Profile (profile) in October 2018, which mapped the framework core to existing regulations and guidance, such as the Commodity Futures Trading Commission System Safeguards Testing Requirements. Officials stated that these efforts will facilitate the use of the framework. However, while the department has ongoing initiatives, implementing our recommendations to gain a more comprehensive understanding of the framework's use by critical infrastructure sectors is essential to the success of protection efforts.
GAO-18-177, Jan 18, 2018
Phone: (202) 512-9971
Agency: Department of Defense
Status: Open
Comments: DOD partially concurred with this recommendation. As of August 2018, DOD and the FAA signed a memorandum of agreement that that establishes a framework for DOD and FAA to jointly address the provision to allow certain aircraft not to broadcast and airspace monitoring and defense security issues related to ADS-B, and identifies a path to fully address the recommendations in our report. The memorandum of agreement was a first step to address the security issues we highlighted in the report; however, FAA still needs to publish a National Procedural Guidance for accommodation of DOD needs for mixed-equipment operations and operational security concerns (expected December 2018).
Agency: Department of Transportation
Status: Open
Comments: DOT concurred with this recommendation. As of August 2018, DOD and the FAA signed a memorandum of agreement that that establishes a framework for DOD and FAA to jointly address the provision to allow certain aircraft not to broadcast and airspace monitoring and defense security issues related to ADS-B, and identifies a path to fully address the recommendations in our report.
Agency: Department of Defense
Status: Open
Comments: DOD partially concurred with this recommendation. As of August 2018, DOD has not taken action regarding the eight tasks GAO identified in the 2007 Deputy Secretary of Defense memorandum on ADS-B implementation.
GAO-17-614, Aug 3, 2017
Phone: (202) 512-6244
including 2 priority recommendations
Agency: Office of Personnel Management
Status: Open
Priority recommendation
Comments: OPM partially concurred with the recommendation. OPM has improved its POA&M management system. Using this system, the agency provided, on 08-27-19, milestones showing timely validation of evidence for closing one US-CERT recommendation. However, OPM has not provided support showing timely validation of 16 other US-CERT recommendations that it has closed. OPM needs to provide evidence of timely validation of these 16 completed recommendations, or evidence for the two US-CERT recommendations that remain open, once these two have been closed and validated. As of March 2020, OPM has not yet provided evidence of taking such actions.
Agency: Office of Personnel Management
Status: Open
Priority recommendation
Comments: OPM concurred with the recommendation. In December 2018, OPM stated that it is working with its learning management system vendor to develop role-based training requirements for its continuous monitoring program, but had not yet targeted an expected completion date. To fully implement the recommendation, OPM needs to issue role-based training requirements for individuals who configure and maintain the deployed continuous diagnostics and mitigation tools. As of March 2020, OPM has not yet provided evidence of taking such actions.
GAO-17-668, Jul 27, 2017
Phone: (202) 512-9971
Agency: Department of Defense: Office of the Under Secretary of Defense for Intelligence
Status: Open
Comments: DOD concurred with this recommendation. We reached out to DOD in August 2018 on this recommendation and are awaiting their response.
Agency: Department of Defense: Office of the Principal Cyber Advisor to the Secretary of Defense
Status: Open
Comments: DOD concurred with this recommendation. DOD has implemented one geo-location policy in 2018 relating to operations security that addresses a portion of this recommendation.
GAO-17-39, Feb 3, 2017
Phone: (202) 512-3604
Agency: Department of Defense
Status: Open
Comments: DOD concurred with this recommendation. In its initial response, DOD noted that it will maintain its focus on the recruiting and retention pays for both the active and reserve components, and will continue to work with the Reserve Components to strengthen the collection of the remaining special and incentive pays. As of November 2019, DOD had not taken action on this recommendation.
Agency: Department of Defense
Status: Open
Comments: DOD partially concurred with this recommendation. In DOD's initial response, it stated that DOD does use key principles of effective human capital management, and although not articulated as GAO's principles, DOD's and GAO's principles share common goals and results. In addition, DOD stated that it will support the opportunity to review and improve upon the principles and methods to assess the efficiency of its S&I pay programs, and, where appropriate, will incorporate these principles in future DOD policy issuances and updates. In May 2018, DOD stated that it believed it was in compliance with this recommendation and that the action was complete. DOD stated that this assessment was based on our finding that most of the Department's S&I pay programs either met or partially met the key principles of effective human capital management. But our finding was on select pay programs. Further, DOD's response did not document what actions the Department has taken to ensure all programs fully meet the key principles. As of November 2019 DOD had not taken action on this recommendation. We continue to believe that fully implementing the key principles of effective human capital management that we identified would help DOD and the services to ensure that S&I pay programs are effectively designed and that resources are optimized for the greatest return on investment.
Agency: Department of Defense
Status: Open
Comments: DOD concurred with this recommendation. As of August 2017, DOD had submitted a proposal to conduct a study focused on aviation officers that will examine the military services' methodologies used to accomplish their retention goals to determine the primary reasons aviation officers remain or leave the service and the degree to which these reasons affect their retention decisions. According to DOD officials, a portion of the study will consider the interaction between monetary and non-monetary incentives such as duty assignments, flying opportunities, reduced administrative burdens, and quality of life. In May 2018, DOD stated that the Military Departments continue to utilize non-monetary incentives as their first approach to access and retain quality servicemembers. DOD added that these incentives consist of choice of career path, duty assignment, selective military training, educational benefits, as well as the career intermission program. DOD noted that the Army's Career Satisfaction Program is just one example of using non-monetary pay incentives to improve retention. According to DOD, this program increases the retention of Army officers at no additional cost to the Army by offering academy cadets and senior ROTC cadets the choice of occupational specialty and assignment location upon commissioning in exchange for extending their active duty service obligation for an additional 3 years. DOD also stated that the Navy currently uses both monetary and non-monetary incentives to retain its surface warfare officer (SWO) community to ensure it retains adequate numbers of officers to fill critical SWO Department Head positions in the rank of Lieutenant and Lieutenant Commander. The Department concluded that it believes the recommendation is closed, as it has offered and continues to offer non-monetary incentives as part of its S&l pay program, and continues to encourage the use of non-monetary incentives as an alternative to cash incentives. While the programs DOD mentioned in its response demonstrate progress toward fully implementing our recommendation, we believe that this recommendation should remain open until more progress is made. As of November 2019, DOD had not taken additional actions on this recommendation.
Agency: Department of Defense
Status: Open
Comments: DOD partially concurred with this recommendation. In DOD's initial response, it stated that the services are responsible for developing their personnel requirements in order to meet individual service needs and that it has provided the services with the necessary staffing tools to recruit and retain servicemembers in the cybersecurity skill sets. DOD also noted that it is crucial for the services to retain their flexibility to utilize these pays and benefits to address service-specific shortfalls within their cybersecurity workforce and noted that it will assist the services in growing and maintaining their cybersecurity workforce through existing and future DOD policies. In August 2018, DOD reiterated that the services have responsibility for developing their manpower requirements and employing the necessary manpower tools, such as bonuses and incentives, to achieve their goals, including those for the cybersecurity workforce. DOD added that the current suite of special and incentive pays already provides the services the necessary authorities and flexibilities to access and retain servicemembers in their cybersecurity communities. DOD concluded that it believed their actions to address this recommendation were complete. We recognize that the services are responsible for their specific personnel requirements and that flexibility is important. However, as noted in our report, each military service has assigned cybersecurity personnel to military occupational specialties that include other types of personnel skill sets, such as intelligence or information technology. As a result, because the services offer SRBs by military occupational specialty, the services may award SRBs to specialties that include non-cybersecurity personnel for whom the SRB is unneeded. Therefore, we continue to believe that there are benefits to developing approaches to target cybersecurity personnel in non-designated cybersecurity fields and that this recommendation should remain open. As of November 2019, DOD had not taken additional actions on this recommendation.
GAO-17-163, Feb 1, 2017
Phone: (202) 512-6244
including 2 priority recommendations
Agency: Department of Homeland Security
Status: Open
Priority recommendation
Comments: For all eleven functions, DHS has measures that evaluate compliance with five (1, 2, 5, 6, 7) of the nine principles and considered whether measures and applicability were appropriate for the other four principles. In February 2020, DHS stated that it does not measure any functions' adherence with principle #8 related to safeguarding against unauthorized access or #9 regarding compliance with policies, regulations, and laws related to privacy and civil liberties. Specifically, the agency stated these two principles are a steady state consideration across all mission areas and functions and have no associated identified measure. For the remaining two principles, DHS did not provide measures that were related to prioritizing activities based on level of risk (#3) or ensuring that appropriate consideration of coordination with subject matter experts from industry, academia, and national labs (#4). As such, DHS does not have appropriate means for assessing the eleven functions against those two principles. However, in March 2020, DHS stated that the metrics for 2020 were different than those in 2019. Officials are in the process of creating a mapping between the previously provided metrics and those for 2020. We will review this mapping and determine if the aforementioned is still applicable with the new metrics.
Agency: Department of Homeland Security
Status: Open
Priority recommendation
Comments: For all 11 functions, DHS stated they have a means of evaluating compliance with five (1, 2, 5, 6, 7) of the nine principles. Once DHS provides specific evidence of data tracked in support of the aforementioned compliance measures, we will review to determine if they have closed this recommendation.
Agency: Department of Homeland Security
Status: Open
Comments: In November 2018, DHS invited GAO to observe a vendor's demonstration of the anticipated Unified Workflow Solution (UWS) that officials stated could support closure of this recommendation, when implemented. In February 2020, DHS stated that their planning and design efforts are ongoing and are on track for deployment of a Minimal Viable Product in April 2020. Once DHS has developed and implemented the UWS, we will review their efforts to determine the extent to which the agency has integrated information related to security incidents.
Agency: Department of Homeland Security
Status: Open
Comments: In March 2019, DHS said that they will provide GAO with a list of the entry points into the NCCIC service desk as well as the standard operating procedures (SOP) and process for quality assurance and quality control. Additionally, the development of the NCCIC Unified Workflow Solution (UWS) could impact this recommendation as well. In February 2020, DHS stated that their planning and design efforts are ongoing and are on track for deployment of a Minimal Viable Product in April 2020. Once DHS has developed and implemented the UWS, we will review their efforts to determine the extent to which the agency has integrated information related to security incidents.
Agency: Department of Homeland Security
Status: Open
Comments: In November 2019, DHS stated that while no alerts or advisories are sent only to Section 9 entities, they do have various forms and mechanisms that Section 9 entities receive cybersecurity information: through HSIN Communities of Interest, the CISCP program, the applicable Sector Specific Agencies, and the applicable Section Information Sharing and Analysis Centers. Further analysis of the membership of the aforementioned forums and mechanisms is needed to determine the extent of Section 9 representation.
Agency: Department of Homeland Security
Status: Open
Comments: In November 2019 DHS stated that the legacy Help Desk and operational activity tracking tools continue to be assessed and requirements identified for configuration into the Unified Workflow Solution (UWS). In February 2020, DHS stated that their planning and design efforts are ongoing and are on track for deployment of a Minimal Viable Product in April 2020. Once DHS has developed and implemented the UWS, we will review their efforts to determine the extent to which the agency has integrated information related to security incidents.
GAO-17-8, Nov 30, 2016
Phone: (202) 512-9286
including 3 priority recommendations
Agency: Department of Commerce
Status: Open
Priority recommendation
Comments: The department agreed with the recommendation and stated that it plans to fully implement it. In October 2019 (in GAO-20-129), we reported the results of our evaluation of the department's progress in implementing the eight IT workforce planning activities. Specifically, we reported that the department had substantially implemented the activity to develop competency and staffing requirements, minimally or partially implemented four activities, and not implemented the remaining three activities. In July 2020, the department provided a summary of actions it claimed it had taken to close the recommendation. The department also provided supporting documentation. We are reviewing the documentation to determine whether it fully addresses the recommendation.
Agency: Department of Defense
Status: Open
Comments: DOD partially concurred with our recommendation. In October 2019 (in GAO-20-129), we reported the results of our evaluation of the Department of Defense's progress in implementing the eight IT workforce planning activities. Specifically, we reported that the department had fully implemented the activities to develop competency and staffing requirements and assess competency and staffing needs regularly, substantially implemented four other activities, and partially implemented the remaining two activities. We will continue to monitor the department's efforts to address our recommendation.
Agency: Department of Health and Human Services
Status: Open
Comments: The department agreed with our recommendation and identified plans for (1) collecting and analyzing additional workforce data and (2) conducting targeted recruitment, staff planning, career development, and training. In October 2019 (in GAO-20-129), we reported the results of our evaluation of the department's progress in implementing the eight IT workforce planning activities. Specifically, we reported that the department had substantially implemented the activity to develop competency and staffing requirements, partially implemented three other activities, and either minimally or not implemented the remaining four activities. We will continue to monitor the department's efforts to address our recommendation.
Agency: Department of Transportation
Status: Open
Priority recommendation
Comments: The department agreed with the recommendation and stated that it plans to fully implement it. In October 2019 (in GAO-20-129), we reported the results of our evaluation of the department's progress in implementing the eight IT workforce planning activities. Specifically, we reported that the department had fully implemented the activity to develop competency and staffing requirements, but had not yet fully implemented the remaining seven activities, including developing a workforce planning process. In January 2020, the department stated that its Office of the Chief Information Officer and Office of Human Resource Management had established a workgroup to lead and conduct workforce planning activities, and had defined the strategic goals and objectives for the department's IT workforce. The department also stated that the workgroup was planning on subsequently completing additional activities, including completing a workforce analysis with a competency gap assessment, by the end of calendar year 2020, and developing strategies to address any identified gaps by the end of 2021. We will continue to monitor the department's efforts to implement our recommendation.
Agency: Department of the Treasury
Status: Open
Priority recommendation
Comments: The department agreed with our recommendation and identified planned and ongoing efforts to address it. In October 2019 (in GAO-20-129), we reported the results of our evaluation of the department's progress in implementing the eight IT workforce planning activities. Specifically, we reported that it had fully implemented the activity to develop competency and staffing requirements, but had not yet fully implemented the remaining seven activities, including developing a workforce planning process. In January 2020, the department stated that its Office of the Chief Human Capital Officer and Office of the Chief Information Officer would be presenting a decision paper to the Human Capital Advisory Council that month to request approval and resources to complete an IT Competency Framework, conduct a competency assessment, and conduct a department-wide workforce planning study for the 2210 (IT management) occupation. We will continue to monitor the department's efforts to implement our recommendation.
GAO-16-686, Aug 26, 2016
Phone: (202) 512-6244
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: The Office of Management and Budget (OMB) partially concurred with this recommendation, but does not intend to directly issue guidance as recommended. As of June 2020, OMB has not provided sufficient evidence that it has implemented this recommendation. We will continue to monitor OMB's implementation of this recommendation.
Agency: Department of Defense
Status: Open
Comments: In response to our report, DOD partially concurred with our recommendation; however, DOD subsequently concurred with the recommendation and is taking steps to implement it. The department stated that the issuance of an updated Cyber Incident Handling guidance is on track to be completed and coordinated in the third quarter of fiscal year 2018. As of June 2020, it has not yet provided sufficient evidence that it has implemented the recommendation. When we confirm what actions DOD has taken, we will provide updated information.
Agency: Department of State
Status: Open
Comments: The Department of State (State) concurred with this recommendation. However, as of June 2020, the department has not yet provided sufficient evidence that it has implemented the recommendation. When we receive additional evidence from State, we will review it to determine whether the department has addressed the recommendation.
Agency: Department of Transportation
Status: Open
Comments: The Department of Transportation (DOT) concurred with the recommendation and is currently updating its Cybersecurity Policy. The Department plans to be complete by June 29, 2019. As of June 2020, the department has not yet provided sufficient evidence that it has implemented the recommendation. Upon receiving additional evidence from DOT, we will review it to determine whether the department has addressed the recommendation.
Agency: Department of Transportation
Status: Open
Comments: The Department of Transportation (DOT) concurred with the recommendation and is currently updating its Cybersecurity Policy. The Department plans to be complete by June 29, 2019. As of June 2020, the department has not yet provided sufficient evidence that it has implemented the recommendation. Upon receiving additional evidence from DOT, we will review it to determine whether the department has addressed the recommendation.
Agency: National Aeronautics and Space Administration
Status: Open
Comments: The National Aeronautics and Space Administration (NASA) concurred with our recommendation. As of June 2020, NASA stated that the agency is working to update the relevant policy to address this recommendation, but the update is taking longer than expected; NASA expects the policy to be updated and the review process to be completed by November 30, 2020. We will examine the evidence when NASA provides it.
GAO-16-771, Aug 26, 2016
Phone: (202) 512-6244
Agency: Department of Health and Human Services
Status: Open
Comments: The Department of Health and Human Services (HHS) concurred with the recommendation but has not yet provided sufficient evidence that it had implemented the recommendation. In particular, as of August 2020, the HHS Office for Civil Rights (OCR) has not yet reviewed the feasibility of performance measures as part of its audit program, and plans to do so only after implementing a future redesign of its audit program. We will continue to monitor HHS actions in response to this recommendation.
GAO-16-695, Jul 21, 2016
Phone: (202) 512-9110
Agency: Department of the Treasury: Internal Revenue Service
Status: Open
Comments: In its fiscal year 2017 congressional justification, IRS modified how its budget data were organized, including linking requested increases to future state themes, but did not clarify how current spending by themes relates to appropriation accounts. Information on current spending by theme and account is important to ensure transparency on the current funding levels to assist Congress in making informed budget decisions. As reported in October 2018 in GAO-19-108R, the themes under the Future State vision are now being pursued as part of IRS's strategic plan for fiscal years 2018 to 2022-issued in May 2018. IRS has been phasing out the use of the term Future State and did not include it in its fiscal year 2020 congressional justification. Including data on the themes in the strategic plan would provide additional transparency and improve the quality of the information available to Congress for budget deliberations.
Agency: Department of the Treasury
Status: Open
Comments: As of November 2017, Treasury Department officials took steps to address the need to manually correct budget data for the fiscal year 2017 budget request. However, as of October 2019, we have not received documentation that they have done so for future budget years. Improved information would help Treasury and IRS better account for information technology resources. We will continue to monitor Treasury's progress.
GAO-16-79, Nov 19, 2015
Phone: (202) 512-6244
Agency: Department of the Treasury
Status: Open
Comments: The Department of the Treasury, as the sector-specific agency for the financial services sector, continues to develop initiatives intended to enhance the sector's cybersecurity. In 2016, Treasury developed and promulgated a set of seven fundamental elements or critical building blocks for sector stakeholders' cybersecurity, disseminated a template for financial sector cyber exercises, and promoted the NIST Cybersecurity Framework throughout the sector. However, they have not provided evidence of metrics implemented, and the 2015 sector-specific plan does not include specific metrics to track and report on their effectiveness. We will continue to monitor Treasury's efforts to create specific metrics and related reports on the sector's cybersecurity progress.
Agency: Department of Agriculture
Status: Open
Comments: The Department of Agriculture (USDA), as the co-sector specific agency for the food and agriculture sector, with the Department of Health and Human Services (HHS) continues to implement cybersecurity-related activities for the sector. In particular, USDA, through the sector coordination council, routinely shares best practices and informational bulletins from the Department of Homeland Security on cybersecurity with sector stakeholders via the Homeland Security Information Network. In addition, at semi-annual council meetings, USDA has hosted roundtable discussions of cybersecurity challenges and best practices. No evidence of performance metrics to track and report on the SSAs' activities or the sector's cybersecurity progress has been provided. As USDA and HHS continue to carry out their sector-specific agency role, we will continue to monitor their efforts and associated performance metrics to be developed to demonstrate the effectiveness of these activities
Agency: Department of Health and Human Services
Status: Open
Comments: The Department of Health and Human Services (HHS), as the co-sector specific agency for the food and agriculture sector, with the Department of Agriculture (USDA) continues to implement cybersecurity-related activities for the sector. In particular, through the sector coordination council, they routinely share best practices and informational bulletins from the Department of Homeland Security on cybersecurity with sector stakeholders via the Homeland Security Information Network. In addition, at semi-annual council meetings, they have hosted roundtable discussions of cybersecurity challenges and best practices. No evidence of performance metrics to track and report on the SSAs' activities or the sector's cybersecurity progress has been provided. As HHS and USDA continue to carry out their sector-specific agency role, we will continue to monitor their efforts and associated performance metrics to be developed to demonstrate the effectiveness of these activities
Agency: Environmental Protection Agency
Status: Open
Comments: The Environmental Protection Agency (EPA) continues to develop and implement activities in support of the water and wastewater sector's cybersecurity such as a cyber-attack risk assessment tool and cybersecurity training for sector partners. The 2015 water and wastewater sector-specific plan calls for assessing performance and reporting on sector cybersecurity progress; however, the plan does not state specific measures. In 2017, agency officials stated that the development of performance metrics in collaboration with sector partners was underway; however, EPA has not provided evidence of the metrics or any tracking effort. As EPA continues to carry out its sector-specific agency role, we will continue to monitor its efforts and associated performance metrics to be developed to demonstrate the effectiveness of these activities.