FISMA: USAID Implemented an Effective Information Security Program Through April 14, 2025, Despite Some Concerns

Recommendation
1

USAID's Chief Information Officer conduct updated risk assessments for the two systems we identified

Questioned Cost
0
Funds for Better Use
0
Recommendation
2

USAID's Chief Information Officer perform security controls assessments for the two systems we identified.

Questioned Cost
0
Funds for Better Use
0
Recommendation
3

USAID's Chief Information Officer determine whether the Agency included cybersecurity duties in position descriptions and performance plans. If not, take corrective action, including addressing the causes for not doing so.

Questioned Cost
0
Funds for Better Use
0
Recommendation
4

USAID's Chief Information Officer determine whether the Agency developed and implemented policies and procedures for maintaining data and metadata inventories for its various data types, including data from third-party providers. If not, take corrective action, including addressing the causes for not doing so.

Questioned Cost
0
Funds for Better Use
0
Recommendation
5

USAID's Chief Information Officer determine whether the Agency implemented network monitoring and enforcement mechanisms to identify and disconnect or isolate noncompliant devices. If not, take corrective action, including addressing the causes for not doing so.

Questioned Cost
0
Funds for Better Use
0