The Office of the Inspector General conducted a review to determine if TVA’s privacy program is effective and in compliance with applicable regulations, guidance, policies, and procedures. We found several areas of the privacy program to be generally effective, including (1) controls protecting privacy information on TVA-owned mobile devices, (2) privacy training taken by network users, (3) regular reviews of the privacy program by TVA management, (4) encryption controls protecting data in privacy systems, and (5) appropriate use and protection of reports in privacy systems. However, we identified several issues that should be addressed by TVA management to further increase the effectiveness of the privacy program. We also found gaps between TVA’s policies and procedures governing the privacy program and applicable federal privacy regulations and guidance. TVA management agreed with our findings and recommendations.
Wednesday, June 13, 2018
Agency Reviewed / Investigated:
Submitting OIG-Specific Report Number:
Type of Report:
Funds for Better Use:
Number of Recommendations: