U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

The U.S. Department of Education’s Federal Information Security Modernization Act of 2014

Report Information

Date Issued
Report Number
A21IT0023
What We Did

Our statutory Federal Information Security Modernization Act (FISMA) review sought to assess the effectiveness of the Department’s information security program, including a test of the effectiveness of information security policies, procedures, and practices of a representative subset of its information systems.

What We Found

Although the Department made several improvements in implementing its cybersecurity posture, the Department’s overall information technology security program and practices were not effective in all five security functions reviewed. We had findings in four of the nine metric domains, which included findings with the same or similar conditions identified in prior reports, as well as open findings from previous years where the corrective action plan was not completed.

What We Recommend

We made 16 recommendations in 4 of the 9 metric domains to assist the Department with increasing the effectiveness of their information security programs.

Management Challenge Area

Information Technology Security

Related Work Products

See other FISMA reports.