Skip to main content
Report File
Title Full
OIG is issuing this management advisory to bring to SBA’s attention possible security threats from personally owned devices accessing the agency’s information technology network from national and international locations with only a username and password.
Date Issued
Submitting OIG
Small Business Administration OIG
Agencies Reviewed/Investigated
Small Business Administration
Report Number
25-11
Report Description

The Office of Inspector General is issuing this management advisory to bring to the U.S. Small Business Administration’s (SBA) attention possible security threats from personally owned devices accessing the agency’s information technology network from national and international locations with only a username and password.

We identified in our fiscal years 2023 and 2024 Federal Information Security Modernization Act assessments that SBA did not have multifactor authentication enabled for users to access the agency’s secure network. Relying on usernames and passwords alone greatly increases the risk of SBA data being accessed and exploited by cyber criminals and other bad actors. We also determined personally owned devices could access the SBA network from foreign locations, which is prohibited by SBA information technology policy.

We made five recommendations, and SBA management agreed with all five. All of the recommendations have been closed or resolved.

Report Type
Other
Agency Wide
Yes
Number of Recommendations
5
Questioned Costs
$0
Funds for Better Use
$0
Report updated under NDAA 5274
No

Small Business Administration OIG

United States