U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Fiscal Year 2018 Federal Information Security Modernization Act (FISMA) Evaluation of the Corporation for National and Community Service

Date Issued
Report Number
19-03
Report Type
Inspection / Evaluation
Description
We have determined that the Corporation for National and Community Service’s (CNCS’s) information security program is NOT EFFECTIVE. CNCS has in place the basic information technology policies, procedures and system security documentation needed for effective cybersecurity. To progress beyond the current maturity level, the Corporation must consistently implement and monitor security controls. We continued to find severe vulnerabilities on the network. CNCS has still not fully implemented baseline security configuration settings specific to the existing information technology environment. Further, CNCS has not implemented multifactor authentication for information system users and administrators. These gaps limit the protection of CNCS systems and data, and may expose sensitive information, including Personally Identifiable Information (PII), to unauthorized access and use. The independent IG report offers 25 recommendations to assist CNCS in strengthening its information security program and reach an Effective rating. CNCS should undertake a strategic analysis of the government-wide metrics and the weaknesses identified in this evaluation, to develop a multi-year approach designed to realize steady, measurable improvements in information security in each of the component areas. Implementing such a plan will require CNCS to allocate sufficient resources, including staffing, and to be accountable for interim milestones in order to reach an overall Effective rating.
Joint Report
No
Agency Wide
Yes
Questioned Costs
$0
Funds for Better Use
$0

Open Recommendations