Skip to main content
Report File
Date Issued
Submitting OIG
U.S. Development Finance Corporation OIG
Other Participating OIGs
U.S. Development Finance Corporation OIG
Agencies Reviewed/Investigated
U.S. International Development Finance Corporation
Report Number
A-DFC-22-003-C
Report Description

Our objective was to determine whether the U. S. International Development Finance Corporation (DFC) implemented and effective information security program for fiscal year (FY) 2021, in support of the Federal Information Security Modernization Act of 2014 (FISMA). The OIG contracted with the independent certified public accounting firm of CliftonLarsonAllen LLP (CLA) to conduct the audit. CLA evaluated the effectiveness of DFC’s implementation of CLA reviewed FISMA reporting metrics and also assessed DFC’s implementation of selected controls outlined in the National Institute of Standards and Technology’s Special Publication 800-53, Revision 4, “Security and Privacy Controls for Federal Information Systems and Organizations.” CLA reviewed three of the four internal and external systems in DFC’s inventory dated February 12, 2021.We found DFC implemented an effective information security program. For example, DFC established an effective security training program, maintained an effective information system continuous monitoring program, and implemented an effective incident handling and response program. However, we did make recommendations to address weaknesses in four of the nine FY 2021 IG FISMA metric domains.

Report Type
Audit
Number of Recommendations
3
Questioned Costs
$0
Funds for Better Use
$0

U.S. Development Finance Corporation OIG

United States