An official website of the United States government
Here's how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Brought to you by the Council of the Inspectors General on Integrity and Efficiency
Federal Reports
Report Date
Agency Reviewed / Investigated
Report Title
Type
Location
Department of Health & Human Services
CMS Has Opportunities To Strengthen States' Oversight of Medicaid Managed Care Plans' Reporting of Medical Loss Ratios
The U.S. International Trade Commission’s (Commission) Office of Inspector General conducted this audit to determine if the Commission effectively patches critical and high vulnerabilities on the International Trade Commission Network, known as ITCNet. The ITCNet includes the hardware, software, applications, databases, communications, and Internet access to support the Commission’s mission and daily operations.
The Federal Information Security Modernization Act of 2014 (FISMA) requires each agency’s Inspector General (IG) to conduct an annual independent evaluation to determine the effectiveness of the information security program (ISP) and practices of its respective agency. Our audit objective was to determine the effectiveness of Tennessee Valley Authority’s (TVA) ISP and practices as defined by the Fiscal Year (FY) 2022 Core IG Metrics Implementation Analysis and Guidelines (see Appendix B). Our audit scope was limited to answering the core IG metrics.The FISMA methodology considers metrics at a level 4 (managed and measurable) or higher to be at an effective level of security. Based on our analysis of the core IG metrics and associated maturity models, we found 12 of the 20 core IG metrics were at a level 1 (ad-hoc), level 2 (defined), or level 3 (consistently implemented); therefore, TVA's ISP was not operating in an effective manner as defined by the FY 2022 Core IG Metrics Implementation Analysis and Guidelines.