An official website of the United States government
Here's how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Brought to you by the Council of the Inspectors General on Integrity and Efficiency
Federal Reports
Report Date
Agency Reviewed / Investigated
Report Title
Type
Location
Legal Services Corporation
Audit of Selected Internal Controls at Legal Services Vermont
An Amtrak carman based in Beech Grove, Indiana, was terminated from employment on January 9, 2021, following his administrative hearing. Our investigation found the former employee violated company policy when he failed to report multiple drug or alcohol related convictions on his initial background investigation questionnaire.
Independent Attestation Review: Centers for Disease Control and Prevention 2020 Detailed Accounting Report, Performance Summary Report for National Drug Control Activities, Budget Formulation Compliance Report, and Accompanying Required Assertions
Independent Attestation Review: Indian Health Service Fiscal Year 2020 Detailed Accounting Report, Performance Summary Report for National Drug Control Activities, Budget Formulation Compliance Report, and Accompanying Required Assertions
Independent Attestation Review: National Institutes of Health Fiscal Year 2020 Detailed Accounting Report, Performance Summary Report for National Drug Control Activities, Budget Formulation Compliance Report, and Accompanying Required Assertions
The objective of this audit was to determine the effectiveness of security measures for select IT systems that support the 2020 Census. Our audit scope included the Bureau’s risk management program, security operations center (SOC) capabilities, security of Active Directory, and implementation of multi-factor authentication. We found the following: (1) The Bureau’s inadequate risk management program left significant risks present in decennial IT systems. (2) The Bureau’s Decennial security operations center lacked fundamental capabilities during periods of decennial census data collection. (3) The Bureau inadequately managed its Active Directory that supports decennial census operations. (4) The Bureau had not fully enforced personal identity verification in accordance with federal and Department requirements.