USAID Needs To Improve Policy and Processes To Better Protect Information Accessed on Personal Devices

Recommendation
1

USAID's Chief Information Officer Conduct a risk-assessment of the current session-termination setting of seven days versus the eight-hour best practice for the [Agency's] external cloud system, and take the necessary action based on the results of the risk-assessment.

Questioned Cost
0
Funds for Better Use
0
Close Date
Recommendation
2

USAID's Chief Information Officer Develop and implement written policies and procedures for Agency-created external cloud-system administrators to clearly define and specify the privileges that should be assigned to each role.

Questioned Cost
0
Funds for Better Use
0
Close Date
Recommendation
3

USAID's Chief Information Officer Conduct a risk-assessment for Agency staff using personal devices to access the external cloud system and determine what actions Agency officials need to take to mitigate any identified risks. This includes updating relevant policies to reflect the acceptable use of personal devices consistently as deemed appropriate by management and providing training to staff on those new policies.

Questioned Cost
0
Funds for Better Use
0
Recommendation
4

USAID's Chief Information Officer Develop and implement policies and procedures to disable network accounts promptly for contractors when the contracted work ends.

Questioned Cost
0
Funds for Better Use
0
Close Date