Follow us! >

Review of the Postal Regulatory Commission’s Compliance With the Federal Information Security Modernization Act of 2014 for Fiscal Year 2025

Read full article athttps://www.uspsoig.gov

Background 

This report presents a review of the U.S. Postal Regulatory Commission’s (PRC) information security program and practices for fiscal year (FY) 2025. The Federal Information Security Modernization Act, amended in 2014 (FISMA) requires agencies to develop, implement, and document agencywide information security programs and practices. FISMA also requires inspectors general to conduct annual reviews of their agencies’ information security programs and report the results to the Office of Management and Budget.

What We Did 

To meet the annual review requirement, we contracted with KPMG LLP (KPMG) to conduct this audit subject to our oversight. The audit objectives were (1) to determine the effectiveness of the PRC’s information security program and practices in six framework function areas: Govern,1 Identify, Protect, Detect, Respond, and Recover, and (2) to follow up on the status of corrective actions taken by the PRC to implement the prior year performance audit recommendations and determine whether corrective actions for open FISMA recommendations were effectively implemented.

What We Found 

The PRC has made incremental advancements in its information security program since the FY 2024 FISMA audit. However, it has opportunities to continue to improve its information security program. While the PRC has developed plans of actions and milestones to address all of the recommendations from FY 2024’s FISMA audit finding, policies, procedures, and processes to manage its information security program are not finalized or implemented. As a result, the IG FISMA Metrics were rated a Defined (Level 2) maturity level for the six framework functions. KPMG reported one repeat finding (see Section III) pertaining to the functions and their respective 10 metric domains.

Recommendations and Management’s Comments 

KPMG made two new recommendations and referenced the six open prior recommendations to address the issues identified in the report across the 10 FISMA metric domains. The PRC agreed with all recommendations. KPMG considers management’s comments responsive to all recommendations, and corrective actions should resolve the issues identified in this report.

Sign up to receive our Daily Postal News blast

Related Articles

Tell us what you think below!

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Hot this week

Mail exposed to snow and rain at Billings post office

BILLINGS— An anonymous email about poor conditions at the downtown Billings post office led to positive change after MTN News investigated the claims.

USPS Stand Up Talk on Employee Conduct and Law Enforcement

If you encounter an incident involving active law enforcement activity you should not interfere or intercede in the activity.

How the Largest USPS Mail-Trucking Collapse Since Yellow Will Hit U.S. Line haul and Rural Delivery

One of the United States Postal Service’s largest highway contractors, 10 Roads Express, is shutting down after nearly 50 years on the road.

Defense challenges evidence in Warren mail carrier murder case

CLEVELAND, Ohio - Attorneys for one of the men accused of killing a Warren mail carrier filed motions this week seeking to block evidence seized during the investigation.

250,000 packages stolen per day, study finds, as lawmakers push stiffer penalties

As online holiday shopping ramps up, seeing thieves take off with goods is on the rise and has even prompted lawmakers to mull over new legislation for stiffer penalties.
spot_img

Related Articles

Popular Categories

spot_imgspot_img
Secret Link
0
Would love your thoughts, please comment.x
()
x