The United States African Development Foundation’s Information Security Program Needs Improvements To Comply With FISMA

Recommendations

Recommendation
21

The United States African Development Foundation's chief information security officer document and implement a process to change default usernames and passwords before system installation.

Questioned Cost
0
Close Date
Recommendation
22

The United States African Development Foundation's chief information security officer document and implement a process to review and analyze all required audit logs in accordance with National Institute of Standards and Technology standards and the foundation's policy.

Questioned Cost
0
Close Date
Recommendation
23

The United States African Development Foundation's chief information security officer document and implement a process to reevaluate the security categorization of the general support, travel, and
human resources systems in accordance with the Office of Management and Budget and National Institute of Standards and Technology guidance given that the systems contain personally identifiable information.

Questioned Cost
0
Funds for Better Use
0
Close Date
Recommendation
24

The United States African Development Foundation's chief information security officer document and implement a process to maintain a current interconnection security agreement and memorandum of understanding between the foundation and the U.S. Department of Interior's Interior Business Center.

Questioned Cost
0
Close Date
Recommendation
25

The United States African Development Foundation's chief information security officer document and implement a process to provide annual security awareness training to overseas partners.

Questioned Cost
0
Close Date
Recommendation
26

The United States African Development Foundation's chief information security officer document and implement a process to provide annual role-based training to all personnel with significant information security responsibilities.

Questioned Cost
0
Close Date