Follow us! >

Review of the Postal Regulatory Commission’s Compliance With the Federal Information Security Modernization Act of 2014 for Fiscal Year 2025

Background 

This report presents a review of the U.S. Postal Regulatory Commission’s (PRC) information security program and practices for fiscal year (FY) 2025. The Federal Information Security Modernization Act, amended in 2014 (FISMA) requires agencies to develop, implement, and document agencywide information security programs and practices. FISMA also requires inspectors general to conduct annual reviews of their agencies’ information security programs and report the results to the Office of Management and Budget.

What We Did 

To meet the annual review requirement, we contracted with KPMG LLP (KPMG) to conduct this audit subject to our oversight. The audit objectives were (1) to determine the effectiveness of the PRC’s information security program and practices in six framework function areas: Govern,1 Identify, Protect, Detect, Respond, and Recover, and (2) to follow up on the status of corrective actions taken by the PRC to implement the prior year performance audit recommendations and determine whether corrective actions for open FISMA recommendations were effectively implemented.

What We Found 

The PRC has made incremental advancements in its information security program since the FY 2024 FISMA audit. However, it has opportunities to continue to improve its information security program. While the PRC has developed plans of actions and milestones to address all of the recommendations from FY 2024’s FISMA audit finding, policies, procedures, and processes to manage its information security program are not finalized or implemented. As a result, the IG FISMA Metrics were rated a Defined (Level 2) maturity level for the six framework functions. KPMG reported one repeat finding (see Section III) pertaining to the functions and their respective 10 metric domains.

Recommendations and Management’s Comments 

KPMG made two new recommendations and referenced the six open prior recommendations to address the issues identified in the report across the 10 FISMA metric domains. The PRC agreed with all recommendations. KPMG considers management’s comments responsive to all recommendations, and corrective actions should resolve the issues identified in this report.

Sign up to receive our Daily Postal News blast

Related Articles

Tell us what you think below!

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Hot this week

You can set aside more money in 2026

Postal Service employees can set aside more money for flexible spending accounts, health savings accounts and commuter benefits in 2026.

USPS OIG – FY 2025 Selected Financial Activities and Accounting Records

The Postal Service fairly stated selected accounting transactions in the general ledger and controls over those transactions were operating effectively.

One airlifted after postal truck crash in Southwest Miami‑Dade, authorities say

Authorities are investigating a serious crash in Southwest Miami‑Dade involving a postal truck that ended up wedged between trees.

UPS, Postal Service lock in renewed Ground Saver deal, deliveries starting soon

The U.S. Postal Service will soon deliver some UPS Ground Saver packages again after the two delivery giants finalized a renewed agreement

‘Nuisance’ turkeys in Boise’s North End do what rain, snow can’t: Delay the mail

The birds are attacking mail carriers, causing the U.S Postal Service to skip delivery at some homes and on streets where the animals are congregating
spot_img

Related Articles

Popular Categories

Secret Link
0
Would love your thoughts, please comment.x
()
x
Send this to a friend