-
24
pages
-
English
-
Documents
Description
REPORT ON AUDIT OF FLRA SECURITY PROGRAMS SEPTEMBER 2004 Task Order No. FLRA-IG-2004-1 Cotton & Company LLP Auditors • Advisors 333 North Fairfax Street, Suite 401 Alexandria, Virginia 22314 703.836.6701 chayward@cottoncpa.com CONTENTS Section Page Introduction 1 Background 2 Methodology 3 Statutory and Related Requirements 4 Physical Security4 Information Security6 Findings and Recommendations 6 A. Physical Security7 B. Information Security 10 Management Comments 20 Risk Assessment 20 REPORT ON AUDIT OF FLRA SECURITY PROGRAMS EXECUTIVE SUMMARY Cotton & Company LLP, on behalf of the Federal Labor Relations Authority (FLRA), Office of Inspector General, conducted an independent assessment of the agency’s security programs. This work was designed to assess FLRA’s compliance with the Federal Information Security Management Act of 2002 (FISMA) and Federal security requirements. FLRA has established adequate security controls in some areas. Overall, however, its information security programs do not meet responsibilities required for Federal agencies stipulated in FISMA, Section 3544, Federal Agency Responsibilities. The weaknesses identified by this audit focus on lack of security policy, access controls, system software controls, service continuity controls, and contingency plans to recover critical operations when interruptions occur. Other common vulnerabilities ...
-
Publié par
-
Langue
English