ARTICLE
14 January 2022

GAO Finds Inconsistencies In Implementation Of FISMA Cyber Requirements

HL
Hogan Lovells Cadwalader

Contributor

Hogan Lovells Cadwalader is a global law firm trusted by clients to deliver on complex, high-stakes matters.

Operating at the intersection of business, finance, and government, we bring an unwavering commitment to client service and the decisive counsel that helps clients achieve exceptional results.

Consistently recognized for innovation across legal services, we combine sharp judgment with deep commercial perspective and intellectual rigor to address critical, cutting-edge challenges.

With 3,100 lawyers worldwide, we offer global scale with strong local insight in the markets that matter most. Our commitment extends beyond client work through pro bono activities, community investment, and responsible business practices.

GAO found that federal agencies were inconsistent in implementing cybersecurity requirements under the Federal Information Security Modernization Act ("FISMA").
United States Technology

GAO found that federal agencies were inconsistent in implementing cybersecurity requirements under the Federal Information Security Modernization Act ("FISMA").

GAO evaluated (i) the effectiveness of federal agencies' implementation of cybersecurity policies and practices, and (ii) the extent to which relevant officials at federal agencies consider FISMA to be effective at improving the security of agency information systems.

In its report covering fiscal year 2020, GAO found that 23 civilian Chief Financial Officers Act ("CFO") agencies reported progress toward meeting federal cybersecurity targets. A majority of those, however, said they were not fully meeting the requirements. GAO stated that Inspectors General found uneven implementation and concluded that only seven CFO agencies had effective agency-wide information security programs.

Agencies that implemented FISMA cybersecurity requirements into their security programs benefited from, among other things, (i) the standardization of security program requirements, (ii) the improvement of cybersecurity posture, (iii) more effective communication within the agencies, (iv) the ability to track the performance of security programs over time, and (v) the ability to establish responsibilities and authorities with respect to cybersecurity programs.

GAO noted that since 2010, it has made approximately 3,700 recommendations related to the nation's cybersecurity efforts, of which about 900 have not yet been fully implemented as of November 2021.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More