Independent Evaluation of the DNFSB’s Implementation of the Federal Information Security Modernization Act (FISMA) of 2014 for Fiscal Year 2020
Report Information
Recommendations
Conduct the agency’s annual breach response plan exercise for FY 2021.
OIG Analysis: The OIG confirmed that the agency conducted its annual breach response exercise plan. Hence, this recommendation is now closed.<br />
<br />
Status: Open: Resolved. DNFSB conducted incident response/contingency plan exercises on September 26 & 27, 2022 and May 24, 2023, that included testing the agency’s breach response plan. The exercises and after-action reports can be provided. DNFSB requests confirmation from the OIG if the exercises performed above resolve this Recommendation, and if so, then this recommendation needs to be closed. Based on actions already taken, DNFSB’s position is that this Recommendation needs to be closed.
Continue current efforts to refine existing monitoring and assessment procedures to more effectively support ongoing authorization of the DNFSB system.
Update the DNFSB’s incident response plan to include profiling techniques for identifying incidents and strategies to contain all types of major incidents.
Based on the results of the DNFSB’s supply chain risk assessment included in the recommendation for the Identify function above, update the DNFSB’s contingency planning policies and procedures to address ICT supply chain risk.
<br />