Report Contents
Report Terms
Report Recommendations
OIG recommends that the Chief Information Officer develop a strategy to realign information technology resources to balance operational needs with the need for an effective information security risk management strategy.
OIG recommends that the Chief Information Officer develop and implement an organization-wide information risk management strategy to identify, assess, respond to, and monitor information security risk at all levels of the organization in accordance with National Institute of Standards and Technology Publication 800-39. Specifically, the risk management strategy should align risk management decisions with business functions and objectives, which includes processes that respond to and monitor risk to operations and assets as well as performance-based outcomes by measuring, monitoring, and reporting risk management metrics to ensure that Broadcasting Board of Governors objectives are met.
Sensitive Information Redacted
