All Reports

Date Issued
|
Report Number
06-02238-163

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 8/25/2016
Take whatever administrative action deemed appropriate concerning the individuals involved in the appropriate and untimely handling of the notification of stolen VA data.
No. 2
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 9/18/2007
Establish one clear, concise VA policy on safeguarding protected information when stored or not stored in VA automated systems, ensure policy is readily available, and employees held accountable.
No. 3
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 9/24/2008
Modify the mandatory Cyber Security and Privacy Awareness training to identify and provide a link to all applicable laws and VA policy.
No. 4
Closed and Implemented Recommendation Image, Checkmark
to Human Resources and Administration/Operations, Security, and Preparedness (HRA/OSP)
Closure Date: 6/22/2016
We recommend that the Secretary ensure that all position descriptions are evaluated and have proper sensitivity level designations, that there is consistency nationwide for positions that are similar in nature or have similar access to VA protected information and automated systems, and that all required background checks are completed in a timely manner.
No. 5
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 12/20/2007
Establish VA-wide policy for contracts for services that requires access to protected information, ensures contractor personnel held to same standards, and information is safeguarded.
No. 6
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
Closure Date: 9/7/2007
Establish VA policy and procedures that provide clear, consistent criteria for reporting, investigating, and tracking incidents of loss, theft, or potential disclosure of protected information.