VA’s Office of Information Technology (OIT) manages more than 50,000 mobile devices that store and transmit veteran information that must be protected. The VA Office of Inspector General (OIG) conducted this audit to determine whether OIT’s policies and procedures provide enough security for that information. The OIG found OIT’s security practices for mobile devices generally minimized security weaknesses within VA’s network. However, the OIG did find vulnerabilities associated with configuration management. OIT did not block the use of applications to prevent malicious, vulnerable, or flawed software (“blacklisting”) as required by VA policy, increasing the risk of lost data. In addition, VA did not ensure mobile device users are completing the required annual information security training and had no way to validate the effectiveness of that training. VA also did not use configuration management tools to control and automate update releases for its mobile devices and applications—the OIG found 12,298 out of 50,618 mobile devices had unapproved operating systems. According to OIT’s director of mobile technology and endpoint security engineering, OIT decided not to use blacklisting or other configuration management tools because of concerns about workload. OIT has now awarded a contract to Lookout for a new application vetting tool, but it was not available for OIG review in time for publication of this report. The OIG recommended the assistant secretary for information and technology either enforce blacklisting or formally assess and document whether training would work to prevent users from downloading and using non-VA-approved applications. The OIG also recommended that the assistant secretary ensure users do not update devices and applications until after testing is conducted by the Mobile Device Management team and ensure mobile device users complete required annual training before accounts are activated.
| Report Date | Agency Reviewed / Investigated | Report Title | Type | Location | |
|---|---|---|---|---|---|
| Department of Veterans Affairs | VA’s Management of Mobile Devices Generally Met Information Security Standards | Audit | Agency-Wide | View Report | |
| Smithsonian Institution | Contract Management: Smithsonian Needs to Enhance Controls for Managing and Monitoring Revenue Generating Contracts | Audit | Agency-Wide | View Report | |
| Amtrak (National Railroad Passenger Corporation) | Marketer Pleads Guilty in Illegal Kickback Scheme | Investigation |
|
View Report | |
| Tennessee Valley Authority | Organizational Effectiveness Follow-up – Human Resources | Inspection / Evaluation | Agency-Wide | View Report | |
| U.S. Agency for International Development | Audit of Aksyon Kominote nan Sante pou Ogmante Nitrisyon, Managed by Fondasyon Kole Zepl, Cooperative Agreement AID-521-A-16-00002, October 1, 2017 to December 31,2018 | Other |
|
View Report | |
| U.S. Agency for International Development | Closeout Audit of the Schools Building Peace in the North of Mexico Program Managed by Fundacin Mexicana de Apoyo Infantil, Cooperative Agreement AID-523-A-15-00007, January l to October 29, 2018 | Other |
|
View Report | |
| U.S. Agency for International Development | More Guidance and Tracking Would Bolster USAID's Health Systems Strengthening Efforts | Audit | Agency-Wide | View Report | |
| U.S. Agency for International Development | Audit of the Fund Accountability Statement of Locally Incurred Costs by Hagar: Jewish-Arab Education for Equality, Education for All: Expanding Extended Education in Israeli's Negev Project, Cooperative Agreement AID 294-A-13-00008, August 21, 2013, to Fe | Other |
|
View Report | |
| U.S. Agency for International Development | Audit of the Fund Accountability Statement of Mission Armenia Charitable Non-Governmental Organization, Support to Social Sector Reforms Project in Armenia, Cooperative Agreement AID-111-A-15-00003, for the Year Ended December 31, 2015 | Other |
|
View Report | |
| U.S. Agency for International Development | Closeout Audit of Locally Incurred Costs by Rostropovich-Vishnevskaya Foundation, Introduction of Rotavirus Vaccine for Children of the West Bank, Cooperative Agreement AID-294-G-16-00001, May 1, 2018 to January 31, 2019 | Other |
|
View Report | |