Open Recommendations
| Recommendation Number | Significant Recommendation | Recommended Questioned Costs | Recommended Funds for Better Use | Additional Details | |
|---|---|---|---|---|---|
| 001 | Yes | $0 | $0 | ||
| We recommended the CIO: Develop and implement an unambiguous standard operating procedure, utilizing Federal Risk and Authorization Management Program guidance and leading practices, to monitor cloud service providers and escalate non-compliance effectively to the agency Authorizing Official, including defined risk management deficiency triggers. | |||||
| 003 | Yes | $0 | $0 | ||
| We recommended the CIO: Complete in progress efforts to modernize impacted systems and subsequently enable multi-factor authentication. | |||||
| 004 | Yes | $0 | $0 | ||
| We recommended the CIO: Enhance the validation process for the quarterly Chief Information Officer FISMA Metrics to ensure all metrics are reported accurately and are in accordance with applicable guidance and standards. | |||||
| 006 | Yes | $0 | $0 | ||
| We recommended the CIO: Develop, implement, and track privacy-focused, role-based training for employees and contractors with significant privacy responsibilities. | |||||