Skip to main content
Report File
Date Issued
Submitting OIG
Department of Transportation OIG
Other Participating OIGs
Department of Transportation OIG
Agencies Reviewed/Investigated
Department of Transportation
Components
Office of the Secretary of Transportation
Federal Aviation Administration
Report Number
FI2019014
Report Description

What We Looked AtThe Office of Management and Budget (OMB) requires Federal agencies to implement Information Security Continuous Monitoring (ISCM), which entails the near real-time detection of cybersecurity risks, threats, and malicious activity. ISCM enables agencies to more effectively address evolving, frequent, and increasingly aggressive cybersecurity attempts to compromise Federal information systems. A large number of systems at the Department of Transportation (DOT) contain sensitive data that require protection; accordingly, we initiated this audit. Our audit objectives were to assess (1) how DOT's ISCM program conforms to OMB and National Institute of Standards and Technology requirements and (2) the status and progress of DOT's implementation of its ISCM program. This review also supports our annual audit mandated by the Federal Information Security Modernization Act.What We FoundDOT's program lacks a procedure for verifying Federal Aviation Administration (FAA) performance data reported to OMB. While DOT has met the requirement to submit quarterly reports, we identified significant errors in one submission. The Department also lacks adequate procedures for providing accurate submissions to OMB. In addition, FAA has not yet completed phase 1 of the Continuous Diagnostics and Mitigation Program, which targets the management of cybersecurity assets and activities. Finally, FAA does not have procedures for reporting on or validating its Cross Agency Priority goal data and cannot be certain those data are accurate.Our RecommendationsDOT concurred with our three recommendations to improve its ISCM program.

Report Type
Audit
Agency Wide
Yes
Number of Recommendations
0
Questioned Costs
$0
Funds for Better Use
$0

Open Recommendations

This report has 2 open recommendations.
Recommendation Number Significant Recommendation Recommended Questioned Costs Recommended Funds for Better Use Additional Details
1 Yes $0 $0

To improve the DOT's information security continuous monitoring program, DOT Chief Information Officer needs to update the department's federal information security modernization act standard operating procedures to include steps for verifying the accuracyand completeness of the Federal Aviation Administration's (FAA) CrossAgency Priority (CAP) goal metrics.

2 Yes $0 $0

To improve the accuracy and completeness of the data FAA uses to report on its CAP goal metrics, the Federal Aviation Administrator needs to implement procedures that: define the requirements for selecting the operating systems to be monitored; criteria for determining which tools should be used to collect data for the CAP goal metrics; and verify the accuracy and completeness of the CAP goal metrics.

Department of Transportation OIG

United States