The Federal Information Security Modernization Act (FISMA) requires annual evaluations of the information security program at each federal agency. The Department of Homeland Security and the Office of Management and Budget review the results, which are used to develop a report to Congress on agencies’ compliance with FISMA. The OIG contracted with an independent public accounting firm to assess VA’s information security program for fiscal year (FY) 2019, in accordance with FISMA. CliftonLarsonAllen LLP evaluated 49 major applications and general support systems hosted at 24 VA facilities that support the Veterans Health Administration, Veterans Benefits Administration, and National Cemetery Administration. The firm concluded that VA continues to face significant challenges meeting FISMA requirements and made 25 recommendations. It noted that all recommendations were repeated or modified from previous reports on FISMA compliance. The firm recommended that VA address security related issues that contributed to the information technology weakness reported in the FY 2019 audit of VA’s consolidated financial statements. It also recommended improving deployment of security patches, system upgrades, and system configurations that would mitigate significant security vulnerabilities and enforce a consistent process across field offices. Another recommendation was to improve performance monitoring to ensure controls are operating as intended, and to communicate identified security deficiencies to appropriate personnel. VA successfully closed three previous recommendations for FISMA compliance in FY 2019. CliftonLarsonAllen LLP will follow up on the outstanding recommendations and evaluate VA’s corrective actions during its FISMA audit for FY 2020. If VA continues to delay corrective actions, a material weakness in informational technology security controls may be reported in the FY 2020 audit of VA’s consolidated financial statements.
Report File
Date Issued
Submitting OIG
Department of Veterans Affairs OIG
Other Participating OIGs
Department of Veterans Affairs OIG
Agencies Reviewed/Investigated
Department of Veterans Affairs
Components
Office of Information and Technology
Report Number
19-06935-96
Report Description
Report Type
Audit
Agency Wide
Yes
Number of Recommendations
24