Weaknesses Identified During the FY 2016 Federal Information Security Modernization Act Review

Date Issued: 
Thursday, June 15, 2017
Report Number: 
17-14

The Federal Information Security Modernization Act (FISMA) requires that the OIG review the SBA’s Information Technology Security Program. To determine SBA’s compliance with FISMA, OIG contracted with an independent public accountant, KPMG, to perform review procedures relating to FISMA. OIG monitored KPMG’s work and reported SBA’s compliance with FISMA in the Agency FISMA filings in November 2016.  We also assessed the Agency’s progress in implementing open recommendations and compared our current year assessment with our fiscal year 2015 FISMA evaluation.  In addition to the 28 open FISMA recommendations noted in Appendix II, OIG made 9 new recommendations to address FISMA-related vulnerabilities.  SBA agreed with all nine recommendations.