Take corrective actions to ensure that facilities and programs remove unauthorized sensitive information from collaborative application sites.
Direct facilities and programs to standardize SharePoint administration, inventory and consolidate their SharePoint sites, and enforce the recommended architecture to better control access and content at the facility or program level.
Implement enforcement mechanisms to ensure that facilities and programs are following standardized processes to secure SharePoint and Teams sites.
Expand roles and responsibilities of facility and program information system security officers and privacy officers to include the routine review of SharePoint and Teams site permissions and content.
Implement automated tools and policies, supported with training, to enable the timely and routine detection and correction of improper sharing and unauthorized content throughout VA.
Mandate standardized training for SharePoint administrators and owners to clarify and reinforce data security requirements.