Our objective was to determine whether the U.S. Department of Education’s (Department) and Federal Student Aid’s (FSA) overall information technology security programs and practices were effective as they relate to Federal information security requirements. The Fiscal Year 2018 Inspector General Federal Information Security Modernization Act of 2014 Reporting Metrics (FY 2018 IG FISMA Metrics) are grouped into five cybersecurity framework security functions that have a total of eight metric domains. Per the FY 2018 IG FISMA Metrics, we found the Department and FSA were not effective in any of the five security functions—Identify, Protect, Detect, Respond, and Recover. We also identified findings in all eight metric domains, of which seven are repeat findings.
Report File
Date Issued
Submitting OIG
Department of Education OIG
Other Participating OIGs
Department of Education OIG
Agencies Reviewed/Investigated
Department of Education
Components
Office of Deputy Secretary
Report Number
A11S0001
Report Description
Report Type
Audit
Agency Wide
Yes
Number of Recommendations
45
Questioned Costs
$0
Funds for Better Use
$0
Additional Details