Follow us! >

USPS OIG – State of Cybersecurity

Background
Cybersecurity, a major enterprise risk consideration, is the practice of protecting systems, networks, and programs from cyberattacks. Cyberattacks targeting the critical infrastructure are increasing in frequency and sophistication, making a well-defined, proactive cybersecurity approach critical. To address these threats, the U.S. Postal Service’s Corporate Information Security Office (CISO) focuses on five cybersecurity strategic objectives: protect, monitor, respond, manage, and innovate.
What We Did
Our objective was to assess the effectiveness of the Postal Service’s state of cybersecurity, specifically evaluating its (1) risk profile and organizational alignment with the cybersecurity strategy, (2) cybersecurity risk management process and vulnerability management program for consistency and appropriateness, and (3) enterprise security architecture processes for alignment with best practices.
What We Found
The Postal Service has made positive strides in implementing improvements to its risk management program, cybersecurity strategy, and organizational structure. However, its state of cybersecurity lacks maturity, which limits its ability to fully understand its risk exposure and protect the agency from cyberattack.
Specifically, we found the Postal Service did not establish a cybersecurity [redacted]  in accordance with agency guidance. We observed that the CISO could not perform [redacted] because they did not have the necessary tools. We also found that formal risk acceptance [redacted] of exceptions was not always conducted in accordance with policy. We further observed applications could operate in [redacted] application owners did not always provide access support for [redacted], and cybersecurity mitigation plans were not consistently managed. This occurred because, although CISO identifies and informs stakeholders of instances of noncompliance, there were no practices to compel compliance.

Sign up to receive our Daily Postal News blast

Related Articles

Tell us what you think below!

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Hot this week

Mail thefts, robberies, fraud and other postal crimes – 11/11/25

Postal crimes are almost a daily event.  These are the ones we found today

Mark Dimondstein Retires as APWU President

Mark Dimondstein, the outgoing president of the American Postal Workers Union (APWU) delivered an emotional farewell message to members on Monday

Sens. Cruz, Hyde-Smith, Capito Introduce Bill to Restore Trust in the USPS

 U.S. Sen. Ted Cruz (R-Texas), Cindy Hyde-Smith (R-Miss.), and Shelley Moore Capito (R-W. Va.) introduced the Upholding a Secure Postal System (USPS) Act to direct the U.S. Comptroller General to submit a report to Congress on nationwide mail theft trends and the security of postal property.

APWU – Peak Season Exception Period Set for Calendar Year 2025

On Nov. 3, the APWU and USPS agreed to the annual Peak Season Exception Period Memorandum of Understanding (MOU), which includes the hiring of Postal Service annuitants as Holiday Clerk Assistants

Here’s what you should know before updating your benefits

The Postal Service wants employees to know some important things concerning the open season benefits enrollment period that began this week.
spot_img

Related Articles

Popular Categories

spot_imgspot_img
Secret Link
0
Would love your thoughts, please comment.x
()
x