OIG releases 2024 audit of the Fed’s information security program

Orrick, Herrington & Sutcliffe LLP
Contact

Orrick, Herrington & Sutcliffe LLP

On October 31, OIG for the Fed and the CFPB released its 2024 Audit of the Board’s Information Security Program. The audit found that the Board’s information security program continues to operate at a level-4 (managed and measurable) maturity. Since the 2023 Federal Information Security Modernization Act (FISMA) audit report, the Fed has improved, such as updating personnel security processes to ensure position risk designations are clearly documented and used. However, the audit identified areas where the program’s maturity has decreased, including the need for a supply chain risk management strategy, a review and escalation process for data loss prevention alerts, consistent documentation of systems, vulnerability scanning on mobile devices, annual testing of the incident notification and breach response plan, role-based privacy training, targeted phishing exercises, and ensuring timely incident reporting by cloud service providers.

The report included nine recommendations regarding the Board’s information security program in risk management, supply chain risk management, data protection and privacy, and security training. The Fed concurred with the recommendations and plans to address them with action plans and milestones. Additionally, 14 recommendations from prior FISMA audit reports remain open, and the audit warned that failure to address these could lead to a decline in the program’s maturity rating in 2025.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Orrick, Herrington & Sutcliffe LLP

Written by:

Orrick, Herrington & Sutcliffe LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Orrick, Herrington & Sutcliffe LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide