An official website of the United States government
Here's how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Brought to you by the Council of the Inspectors General on Integrity and Efficiency
Federal Reports
Report Date
Agency Reviewed / Investigated
Report Title
Type
Location
Department of the Treasury
Information Technology: Department of the Treasury Federal Information Security Modernization Act Fiscal Year 2018 Performance Audit for Collateral National Security Systems is Sensitive But Unclassified.
After consulting with the Department of the Treasury's Departmental Offices, this report was determined to be releasable pursuant to the Freedom of Information Act.
The objective of this review was to perform an independent assessment of the Peace Corps’ information security program, including testing the effectiveness of security controls for a subset of systems as required, for FY 2018. Our results demonstrate that the Peace Corps lacks an effective information security program. We found problems relating to people, processes, and technology. Furthermore, OIG found weaknesses across all the FISMA reportable areas. To ensure the agency’s information, operations, and assets are protected, it is critical that the Peace Corps achieve full compliance with FISMA and other Federal laws and regulations that apply to managing its IT security infrastructure.
This evaluation focused on the appropriateness of programming, training, and evaluation; the adequacy of Volunteer support; and the effectiveness of post leadership and management. This report contains 24 recommendations, which, if implemented, should strengthen post operations and correct the deficiencies detailed in the report.
The Office of Inspector General for the National Credit Union Administration (NCUA) engaged CliftonLarsonAllen LLP (CLA) to independently evaluate the NCUA's information security and privacy management programs and controls for compliance with the Federal Info1mation Security Modernization Act of 2014 and federal regulations and standards.CLA evaluated the NCUA's information security and privacy management programs through interviews, documentation reviews, technical configuration reviews, and sample testing. This year, CLA also conducted a vulnerability assessment of NCUA's network.