MCC Generally Implemented an Effective Information Security Program for Fiscal Year 2023 in Support of FISMA

Audit Report
Report Number
A-MCC-23-002-C

MCC Generally Implemented an Effective Information Security Program for Fiscal Year 2023 in Support of FISMA

Why We Did This Audit

  • We contracted with the independent certified public accounting firm of RMA Associates LLC (RMA) to conduct an audit of the Millennium Challenge Corporation’s (MCC’s) information security program in support of the Federal Information Security Modernization act of 2014 (FISMA) and in accordance with generally accepted government auditing standards.
  • FISMA requires federal agencies to develop, document, and implement an agency-wide information security program to protect their information and information systems. FISMA also requires the agency Inspectors General (IGs) to assess the effectiveness of agency information security programs and practices and report the results of the assessments to the Office of Management and Budget.

What We Found

  • RMA concluded that MCC generally implemented an effective information security program. However, RMA found weaknesses in all nine IG FISMA metric domains.
  • RMA also concluded that MCC took final corrective action on four of six open recommendations from the FY2021 FISMA audit.

Why It Matters

  • FISMA provides a comprehensive framework for ensuring effective security controls over information resources supporting Federal operations and assets.
  • We made four recommendations to address the weaknesses identified in the report.

Recommendations

Recommendation
1

Update the agency's policies and procedures to reflect security controls identified in National Institute of Standards and Technology Special Publication 800-53, Revision 5.

Questioned Cost
0
Funds for Better Use
0
Recommendation
2

Develop and implement a plan for Millenium Challenge Corporation's security assessments to be updated.

Questioned Cost
0
Funds for Better Use
0
Recommendation
3

Implement level 2 event logging requirements in accordance with Office of Management and Budget memorandum M-21-31.

Questioned Cost
0
Funds for Better Use
0
Recommendation
4

Develop and implement a process to make periodic updates to the Millenium Challenge Corporation's business impact assessments.

Questioned Cost
0
Funds for Better Use
0