Skip to main content
Date Issued
Submitting OIG
Department of Transportation OIG
Other Participating OIGs
Department of Transportation OIG
Agencies Reviewed/Investigated
Surface Transportation Board
Report Number
QC2022001
Report Description

What We Looked AtThe Federal Information Security Modernization Act of 2014 (FISMA) requires agencies to implement information security programs. FISMA also requires agencies to have annual independent evaluations performed to determine the effectiveness of their programs and report the results of these reviews to the Office of Management and Budget (OMB). To meet this requirement, the Surface Transportation Board (STB) requested that we perform its fiscal year 2021 FISMA review. We contracted with Williams Adley & Company-DC LLP (Williams Adley), an independent public accounting firm, to conduct this audit subject to our oversight. The audit objective was to determine the effectiveness of STB’s information security program and practices in five function areas—Identify, Protect, Detect, Respond, and Recover. What We FoundWe performed a quality control review (QCR) of Williams Adley’s report and related documentation. Our QCR disclosed no instances in which Williams Adley did not comply, in all material respects, with generally accepted Government auditing standards. RecommendationsSTB concurs with Williams Adley’s 27 recommendations.

Report Type
Audit
Agency Wide
Yes
Number of Recommendations
0
Questioned Costs
$0
Funds for Better Use
$0

Open Recommendations

This report has 4 open recommendations.
Recommendation Number Significant Recommendation Recommended Questioned Costs Recommended Funds for Better Use Additional Details
1 Yes $0 $0

Develop an enterprise architecture that includes information security considerations and the resulting risk to the Agency, as well as incorporates STBs existing cyber security architecture.

17 Yes $0 $0

Complete the transition from traditional three (3) year authorizations to ongoing authorizations for STB-LAN.

18 Yes $0 $0

Implement documented processes for collecting and reporting performance metrics at the organization and system level to assess the effectiveness of Information Security Continuous Monitoring program.

19 Yes $0 $0

Develop a process to make improvements to the effectiveness of its ISCM program through the collection and reporting of quantitative and qualitative performance metrics, and lessons learned.

Department of Transportation OIG

United States