Skip to main content
Report File
Date Issued
Submitting OIG
U.S. AbilityOne Commission OIG
Other Participating OIGs
U.S. AbilityOne Commission OIG
Agencies Reviewed/Investigated
Committee for Purchase From People Who Are Blind or Severely Disabled (AbilityOne Program)
Report Number
2020-11-25
Report Description

The objective of the evaluation was to assess the effectiveness of the Commission’s security program and practices across key functional areas as of September 30, 2020. The Commission made progress through implementation of security policies, procedures, and strategies, but lacked quantitative and qualitative measures to assess them. During FY20, there were six findings and nine corresponding recommendations regarding the Commission’s information security program including: 1. Vulnerabilities not being remediated in a timely manner; 2. Security assessment plan and security assessment report not documented during annual assessment exercises; 3. Back-up data not stored with encryption; 4. Inactive accounts not automatically disabled after 90 days of inactivity; 5. Mobile device usage policy in draft and not finalized, approved or distributed as of year-end and 6. Enterprise Architecture Policy is currently in draft and not finalized, approved or disseminated. The overall assessment of the Commission’s FY2020 information security program was deemed effective because the tested, calculated and assessed maturity levels across the functional and domain areas received an overall rating of effective. The Commission implemented the three open prior year recommendations and the report provides nine new recommendations corresponding to six new findings.

Report Type
Audit
Agency Wide
Yes
Number of Recommendations
9
Report updated under NDAA 5274
No

Open Recommendations

This report has 2 open recommendations.
Recommendation Number Significant Recommendation Recommended Questioned Costs Recommended Funds for Better Use Additional Details
01 No $0 $0 CIO-2020-01

The Commission should follow their vulnerability remediation policies.

02 No $0 $0 CIO-2020-02

Scanning should be run on a monthly basis, however if there are medium, high and/or critical vulnerabilities, then they should be remediated, and the scan should be repeated and run again.

U.S. AbilityOne Commission OIG

United States