Breadcrumb

Federal Information Security Modernization Act Audit for Fiscal Year 2025

Report Information

Issue Date
Report Number
25-01698-70
VA Office
Information and Technology (OIT)
Report Author
Office of Audits and Evaluations
Report Type
Audit
Report Topic
FISMA
Information Technology and Security
Major Management Challenges
Information Systems and Innovation
Recommendations
19
Questioned Costs
$0
Better Use of Funds
$0
Congressionally Mandated
Yes

Summary

Summary

Agency program officials, chief information officers, and inspectors general must annually review information security programs and report to the Department of Homeland Security and Congress on agency compliance with the Federal Information Security Modernization Act (FISMA). The OIG contracted with an independent public accounting firm, CliftonLarsonAllen LLP (CLA), to evaluate VA’s information security program for fiscal year 2025. After assessing 24 major applications and general support systems hosted at 11 VA facilities and on the VA Enterprise Cloud, CLA concluded that VA continues to face significant challenges meeting FISMA requirements because of the nature and maturity of its information security program.

The audit found continuing deficiencies related to access controls, configuration management controls, security management controls, and service continuity practices designed to protect mission-critical systems from unauthorized access, alteration, or destruction. These deficiencies can be remedied by improving the deployment of security patches, system upgrades, and system configurations; improving performance monitoring to ensure controls operate as intended; and communicating identified security deficiencies to appropriate personnel.

CLA made 19 recommendations, some of which addressed repeat deficiencies from previous FISMA reports over multiple years; two were new recommendations. CLA also closed six previous recommendations due to improvements. VA did not concur with the recommendations. CLA will follow up on the outstanding recommendations and evaluate the adequacy of corrective actions in the fiscal year 2026 audit of VA’s information security program.

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology consistently implement an improved continuous monitoring program in accordance with the NIST Risk Management Framework. Specifically, regarding the independent evaluation of the effectiveness of security controls prior to granting authorization decisions. 

No. 2
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology implement improved processes for reviewing and updating key security documentation, including Security Control Assessments and Privacy Impact Assessments as needed. Such updates will ensure all required information is included and accurately reflects the current environment, new security risks, and applicable Federal standards.

No. 3
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the VA Office of Personnel Security, Human Resources, and Contract Offices strengthen processes to ensure appropriate levels of background investigations are performed timely and completed for applicable VA employees and contractors. 

No. 4
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology ensure contingency plans for all systems and applications are updated and tested in accordance with VA requirements.

No. 5
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology implement improved procedures to ensure that system outages are resolved within stated recovery time objectives. 

No. 6
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology ensure backups are conducted periodically and tested in accordance with established standards for VA system and application data. 

No. 7
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology ensure system owners consistently implement processes for periodic reviews of user account access and maintain access authorization documentation. Remove unnecessary and inactive accounts on systems and networks. 

No. 8
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology ensure system owners consistently follow termination procedures for the timely disablement of user accounts and the proper completion of termination checklists for separated personnel.

No. 9
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology work with system owners and change implementers to improve adherence to standards and best practices across the Systems Development Lifecycle (SDLC) for testing and approval of system changes for VA systems and networks. 

No. 10
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology work with system owners and application teams to implement and enforce standards for processes related to preventing and detecting potential unauthorized changes across all platforms and applications in the environment.

No. 11
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology ensure that all systems and platforms are monitored for compliance with documented VA standards for baseline configurations. Ensure that system owners consistently implement and monitor their configurations. 

No. 12
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology implement automated software management processes on all agency platforms to identify and prevent the use of unauthorized software on agency devices.

No. 13
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology work with system owners to ensure adherence to established procedures for maintaining, documenting, and monitoring an accurate software and logical hardware inventory for system boundaries across the enterprise.

No. 14
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology implement improved processes for monitoring and analyzing significant system audit events for unauthorized or unusual activities across all systems and platforms in accordance with VA policy. 

No. 15
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology enable system audit logs on all critical systems and platforms and conduct centralized reviews of security violations across the enterprise.

No. 16
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology implement improved mechanisms to continuously identify and remediate security deficiencies on VA’s network infrastructure, database platforms, and Web application servers in accordance with established policy timeframes. If patches cannot be applied or are unavailable, other protections or mitigations should be documented and implemented to address the specific risks.

No. 17
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology continue to implement controls that restrict vulnerable medical devices from unnecessary access from the general network. 

No. 18
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology implement improved processes to require system owners and management to provide adequate credentials to ensure security scans are authenticated to end devices where feasible and the subsequent vulnerabilities are remediated in a timely manner.

No. 19
Open Recommendation Image, Square
to Information and Technology (OIT)

We recommended the Assistant Secretary for Information and Technology improve the process for tracking and resolving vulnerabilities that cannot be addressed by enterprise processes within policy timeframes. Implement mitigations for identified security deficiencies by applying security patches, system software updates, or configuration changes to reduce applicable security risks. Additionally, VA should enhance their process for updating baseline images to ensure aged vulnerabilities are not introduced into the environment.