Skip to main content
Report File
Date Issued
Submitting OIG
Department of Homeland Security OIG
Other Participating OIGs
Department of Homeland Security OIG
Agencies Reviewed/Investigated
Department of Homeland Security
Components
Management Directorate (Management)
Report Number
OIG-20-77
Report Description

DHS’ information security program was not effective for Fiscal Year 2019 because the Department earned a maturity rating of “Ad Hoc” (Level 1) in three of five functions, compared to last year’s higher overall rating of “Managed and Measurable” (Level 4). We attributed DHS’ regression in managing its information security program to its recent decision to permit the Coast Guard to submit its cybersecurity and Federal Information Security Management Act (FISMA) reports to the Department of Defense rather than to DHS. This decision adversely affects Department senior leadership’s ability to make informed and risk-based decisions on essential cybersecurity activities such as risk management, weakness remediation, system inventory, incident reporting, and continuous monitoring. We made five recommendations. The Department concurred with all five recommendations.

Report Type
Audit
Agency Wide
Yes
Number of Recommendations
5

Department of Homeland Security OIG

United States