Sorry, you need to enable JavaScript to visit this website.
Skip to main content
Report File
Date Issued
Submitting OIG
U.S. Development Finance Corporation OIG
Agencies Reviewed/Investigated
U.S. International Development Finance Corporation
Report Number
DFC-25-005-C
Report Description

What Was Reviewed
The U.S. International Development Finance Corporation Office of Inspector General contracted with the independent public accounting firm RMA Associates, LLC (RMA) to conduct the Federal Information Security Modernization Act of 2014 (FISMA) Performance Audit of the United States International Development Finance Corporation (DFC) for Fiscal Year (FY) 2025 to evaluate the effectiveness of the DFC’s information security program and practices, and determine what maturity level DFC achieved for each of the core metrics and supplemental metrics outlined in the FY 2025 Inspectors General (IG) FISMA Reporting Metrics v2.0 (April 2025).

Our objective was to evaluate the effectiveness of the DFC’s information security program and practices and determine the maturity level DFC achieved for each of the core metrics and supplemental metrics outlined in the FY 2025 IG FISMA Reporting Metrics v2.0 (April 2025).

What Was Found
In this Performance Audit of DFC, RMA determined that DFC’s information security program and practices were effective for FY 2025, as DFC’s information security program met the criteria required to be assessed at a maturity level of Managed and Measurable (Effective). RMA’s tests of the information security program identified two findings that fell within the data protection and privacy and information security continuous monitoring domains.

Report Type
Audit
Agency Wide
Yes
Number of Recommendations
4
Questioned Costs
$0
Funds for Better Use
$0
Report updated under NDAA 5274
No

Open Recommendations

This report has 4 open recommendations.
Recommendation Number Significant Recommendation Recommended Questioned Costs Recommended Funds for Better Use Additional Details
1 No $0 $0

Periodically perform a physical inventory of all mobile devices, including those pending disposal, to ensure all assets are accounted for and accurately reflected in the asset tracking system.

2 No $0 $0

Assign assessors to perform tests of effectiveness on all DFC’s System Security Plan with a sufficient degree of independence in accordance with National Institute of Standards and Technology Special Publication 800-53A, Assessing Security and Privacy Controls in Information Systems and Organizations, Revision 5.1.1.

3 No $0 $0

Document the independence of the assessment team in the risk assessment, including organizational relationships, contract structures, if applicable, and oversight arrangements.

4 No $0 $0

Ensure the risk assessment is reviewed and approved by an Authorizing Official prior to the commencement of any assessment activity.

U.S. Development Finance Corporation OIG

United States