An official website of the United States government
Here's how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Brought to you by the Council of the Inspectors General on Integrity and Efficiency
Federal Reports
Report Date
Agency Reviewed / Investigated
Report Title
Type
Location
Department of Defense
Followup on DoD OIG ReportNo. DODIG-2015-013, “MilitaryHousing Inspections – Republic ofKorea,” October 28, 2014
Transmittal Memorandum for the final Website Security Assessment Follow-up to address recommendations reported in the OIG Website and Infrastructure Security Assessment Report, dated April 24, 2013
The OIG audited the overall effectiveness of the Tennessee Valley Authority's (TVA) patch management process for high-risk, end-user desktops and laptops as they are most vulnerable to spear phishing, a very common tactic used in today's environment to infiltrate computer networks and spread malware. We found (1) TVA is at potential risk for compromise as the patching status was unknown for 12 percent of desktops and laptops in our sample due to desktops and laptops not being managed in patch management tools; (2) 1 of 162 desktops and laptops tested had a missing patch that could lead to remote code execution that has a public exploit available; and (3) the patching process for Mac desktops and laptops is not formally documented. TVA management agreed with our findings and recommendations.