The Federal Risk and Authorization Management Program (FedRAMP) standardizes security and risk assessments for cloud technologies for federal agencies, including VA. In April 2019, the VA Office of Inspector General (OIG) received allegations that VA’s Office of Information and Technology’s (OIT’s) Project Special Forces (PSF) was not following FedRAMP policies or VA policy for deploying software-as-a-service (SaaS) applications. The OIG found that OIT granted security authorizations for applications that were not authorized by FedRAMP. Eight of the nine applications cited by the complainant were in use on the VA network—some without FedRAMP or VA authorization. Another three applications were approved to operate on VA’s network without FedRAMP authorization. The OIG did not substantiate that PSF-developed applications were improperly managed outside the VA Enterprise Cloud group. However, PSF did not follow VA security requirements in developing interfaces that allow third parties to “plug into” the VA to send and retrieve data. OIT personnel stated that there was no formal OIT authorization process until April 2019. After that date, the review team did not find instances of VA-authorized applications without FedRAMP authorization. OIT staff also misunderstood the FedRAMP authorization requirements for SaaS applications containing data classified as less sensitive.Failure to comply with FedRAMP standards increases the risk that VA and veterans’ data could be compromised. The OIG made four recommendations to the acting chief information officer (1) to determine whether to prevent use of the unauthorized SaaS applications and (2) whether the reviewed applications should be authorized or reported to the Federal Chief Information Officer. The remaining recommendations were (3) to implement alerts for interface-related abuse and (4) to either use application programming interfaces that transmit sensitive information and requirements for cross-origin resource sharing or seek exceptions to the standards. VA concurred with all recommendations.
| Report Date | Agency Reviewed / Investigated | Report Title | Type | Location | |
|---|---|---|---|---|---|
| Department of Veterans Affairs | VA Applications Lacked Federal Authorizations, and Interfaces Did Not Meet Security Requirements | Review | Agency-Wide | View Report | |
| U.S. Postal Service | Management Alert — International Export Package Advanced Electronic Data | Audit | Agency-Wide | View Report | |
| Federal Trade Commission | Audit of the FTC's Contracting Officer’s Representative Program | Audit | Agency-Wide | View Report | |
| Federal Deposit Insurance Corporation | DOJ Press Release: Three South Florida Men Sentenced for Conspiring to Launder Fraudulently Obtained Covid-19 Relief Money and Proceeds from Business Email Compromise Schemes | Investigation |
|
View Report | |
| Department of Commerce | USPTO Has Opportunities to Improve its Patent Examination Process and to Advance Patent Decision-Making | Inspection / Evaluation | Agency-Wide | View Report | |
| Federal Maritime Commission | Semiannual Report to Congress: Covering April 1, 2021 - September 30, 2021 | Semiannual Report | Agency-Wide | View Report | |
| Department of Health & Human Services | Fall 2021 Semiannual Report to Congress | Semiannual Report | Agency-Wide | View Report | |
| U.S. Agency for International Development | Financial Audit of USAID Resources Managed by Ministry of Health and Social Welfare Senegal Under Multiple Implementation Letters, January 1 to December 30, 2019 | Other |
|
View Report | |
| U.S. Agency for International Development | Financial Audit of USAID Resources Managed by N'weti Comunicao para Sade in Mozambique Under Multiple Awards, January 1 to December 31, 2020 | Other |
|
View Report | |
| Department of Education | FY 2022 Management Challenges Facing the U.S. Department of Education | Top Management Challenges | Agency-Wide | View Report | |