An official website of the United States government
Here's how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Brought to you by the Council of the Inspectors General on Integrity and Efficiency
Federal Reports
Report Date
Agency Reviewed / Investigated
Report Title
Type
Location
Office of Personnel Management
Open Recommendations Over Six Months Old as of March 31, 2022
Office of the Inspector General of the Intelligence Community
Report Description
(May 2022) The Office of the Inspector General of the Intelligence Community (IC IG) recently released its Semiannual Report to the Director of National Intelligence (DNI) and Congress for the period of October 1, 2021, through March 31, 2022. The National Security Act of 1947 (as amended) requires the IC IG to prepare and submit to the DNI a classified and, as appropriate, unclassified report summarizing the work of the IC IG for the preceding six-month period.
The VA Office of Inspector General (OIG) conducts information technology (IT) inspections to assess whether VA facilities are meeting federal security requirements. They are typically conducted at selected facilities that have not been assessed in the sample for the annual audit required by the Federal Information Security Modernization Act of 2014 (FISMA) or at facilities that previously performed poorly. The OIG selected the Dallas Consolidated Mail Outpatient Pharmacy (CMOP) because it had not been previously visited as part of the annual FISMA audit.The OIG inspections are focused on four security control areas that apply to local facilities and have been selected based on their level of risk: configuration management controls, contingency planning controls, security management controls, and access controls. The OIG found deficiencies in configuration management and access controls at the Dallas CMOP, but none in contingency planning or security management controls.Without effective configuration management, users do not have adequate assurance that the system and network will perform as intended and to the extent needed to support the CMOP’s missions. The access control deficiencies create risks of unauthorized access to critical network resources, inability to respond effectively to incidents, loss of personally identifiable information, or loss of life.The OIG made 10 recommendations to the Dallas CMOP director aimed at fixing the control deficiencies. The assistant secretary for information and technology provided comments for the Dallas CMOP. The assistant secretary concurred with nine recommendations and did not concur with one recommendation. The OIG disagrees with the nonconcurrence.
In accordance with our Annual Performance Plan Fiscal Year 2022. dated November 2021, the Office of Inspector General (OIG) conducted a review of the United States Capitol Police (USCP or the Department) Communications Section's Dispatch and Call Taking Process. The scope of the review included existing policies and procedures related to the Communications Section for Fiscal Year 2021 through December 31. 2021. OIG objectives were to determine if the Department (1) established adequate internal controls and processes for ensuring compliance with select Department policies and (2) complied with select policies and procedures, laws, regulations, and best practices.
The Office of the Inspector General for the Nuclear Regulatory Commission and the Defense Nuclear Facilities Safety Board presents its Semiannual Report to Congress. This report highlights the work the OIG has completed from October 1, 2021, to March 31, 2022.