U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

The U.S. Department of Education’s Federal Information Security Modernization Act of 2014 Report For Fiscal Year 2019

Report Information

Date Issued
Report Number
A11T0002
What We Did

Our statutory Federal Information Security Modernization Act (FISMA) review sought to determine whether the Department and Federal Student Aid’s (FSA) overall information technology security programs and practices were effective as they relate to Federal information security requirements.

What We Found

The Department’s and FSA’s overall information security programs were not effective in any of the five security functions reviewed. We also identified weaknesses in all of the metric domains reviewed, which included findings with the same or similar conditions identified in previous FISMA reports. Similar to our previous FISMA reports, we did find that both the Department and FSA are making progress in strengthening their information security; however, weaknesses remain, leaving their systems and resources vulnerable to compromise and loss.

What We Recommend

We made 37 recommendations to assist the Department with increasing the effectiveness of their information security programs.

Management Challenge Area

Information Technology Security

Related Work Products

See other OIG reports on FISMA.