Background
This report presents a review of the U.S. Postal Regulatory Commission’s (PRC) information security program and practices for fiscal year (FY) 2026. The Federal Information Security Modernization Act of 2014 (FISMA) requires agencies to develop, implement, and document agency wide information security programs and practices. FISMA also requires inspectors general to conduct annual reviews of their agencies’ information security programs and report the results to the Office of Management and Budget. FISMA helps agencies maintain strong cybersecurity programs via a comprehensive framework to ensure the effectiveness of information security controls over information resources that support federal operations and assets and provide a mechanism for improved oversight of federal agency information security programs.
What We Did
To meet the annual review requirement, we contracted with KPMG LLP (KPMG) to conduct this audit subject to our oversight. The audit objectives were (1) to determine the effectiveness of the PRC’s information security program and practices in six framework function areas: Govern, Identify, Protect, Detect, Respond, and Recover, and (2) to follow up on the status of corrective actions taken by the PRC to implement the prior year performance audit recommendations and determine whether corrective actions for open FISMA recommendations were effectively implemented.
What We Found
The PRC has made incremental advancements in its information security program and closed all but one prior year recommendations. The PRC generally established controls and practices consistent with FISMA requirements, Office of Management and Budget policy and guidelines, and applicable NIST standards and guidelines. However, it has opportunities to improve. Overall, we assessed the PRC’s information security program as Defined (Level 2), which was “Not Effective” based on the FY 2026 IG FISMA Reporting Metrics and the associated averages for the metric domains and cybersecurity functions.
Recommendations and Management’s Comments
We made nine recommendations to address the issues identified in the report to help strengthen the effectiveness of the PRC’s information security program controls and practices. The PRC agreed with all recommendations. We consider management’s comments responsive to the recommendations, as corrective actions should resolve the issues identified.
Add your first comment to this post