U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

EAC's FY 2021 FISMA Final Audit Report

Report Information

Date Issued
Report Number
I-PA-EAC-04-21
Report Type
Audit
Subject
IT
Description

EAC OIG, through the independent public accounting firm of Brown & Company, PLLC, audited EAC's compliance with the Federal Information Security Modernization Act of 2014 (FISMA) and related information security policies, procedures, standards, and guidelines for fiscal year 2021.

Questioned Costs
$0
Funds for Better Use
$0

Status of Recommendations

Closed

We recommend EAC OIT perform Security Content Automation Protocol (SCAP) scanning to identify vulnerabilities in all systems on the network to assess both code-based and configuration-based vulnerabilities as required by Office of Management and Budget (...

Closed

We recommend EAC OIT ensure its Windows 10 devices comply with its Center for Internet Security (CIS) security benchmarks as required by its system security plan.

Closed

We recommend EAC OIT implement software patches in its information systems in a timely manner and process patches through its change control process as required by its system security plan.

Closed

We recommend EAC develop and implement a supply risk chain management strategy that aligns with NIST and as required by OMB.

Closed

We recommend EAC develop and implement an anti-counterfeit policy and procedures that include detecting and preventing counterfeit components from entering the system.

Closed

We recommend EAC provide training for the OIT staff to detect counterfeit system components (including hardware, software, and firmware).

Closed

We recommend EAC OIT update its PO&AM workbook to include all known weakness and add the appropriate level of detail required as instructed by OMB.