Skip to main content
Report File
Date Issued
Submitting OIG
Smithsonian Institution OIG
Agencies Reviewed/Investigated
Smithsonian Institution
Report Number
OIG-A-25-03
Report Description

The Office of the Inspector General contracted with Castro & Company, LLC to evaluate the effectiveness ofthe Smithsonian's information security program in fiscal year 2024.  For Fiscal year 2024, Castro found that the Smithsonian Institution’s Information security program was effective overall because it was operating at a managed and measurable level (Level 4) in all five cybersecurity functions (Identify, Protect, Detect, Respond, and Recover).
 

Castro noted Smithsonian continues to make improvements to their information security program.  Castro made six recommendations to improve Smithsonian’s configuration management.  Management concurred with all six recommendations.

Report Type
Audit
Agency Wide
Yes
Questioned Costs
$0
Funds for Better Use
$0
Report updated under NDAA 5274
No

Smithsonian Institution OIG

United States