Improve the existing vulnerability management process to make sure all vulnerabilities are identified, plans of action and milestones are created for vulnerabilities that cannot be mitigated by VA deadlines, and software is updated before vendor support ends.
Implement a baseline configuration process to make sure network devices and databases are running authorized software that is configured to approved baselines and free of vulnerabilities.
Implement a process to disable access to the active directory and the electronic health record when temporary staff leave before their expected end date.
Separate the duties of maintaining physical blank key stock and making keys to improve physical access controls over key inventories.
Secure network infrastructure in accordance with VA environmental protection standards.
Complete the installation of grounding measures for all telecommunication closets to protect information technology equipment.
Routinely monitor and service uninterruptible power supplies that support the network infrastructure.
Establish a process to make sure a witness observes the destruction of temporary paper files that contain personally identifiable information and protected health information.