Report Contents
Report Terms
Report Recommendations
OIG recommends that the Bureau of Information Resource Management formally designate a central repository to track the status of systems authorizations and documentation for Department information systems, including Federal Information Security Management Act reportable systems.
OIG recommends that the Bureau of Information Resource Management update Department policies and procedures to reflect the designation of the central repository in Recommendation 1.
OIG recommends that the Bureau of Consular Affairs, in coordination with the Bureau of Information Resource Management, fully comply with Department policy by completing the Systems Authorization Process with an authorization memorandum for the Consular Consolidated Database.
OIG recommends that the Bureau of Consular Affairs, in coordination with the Bureau of Information Resource Management, fully comply with Department policy by completing the Systems Authorization Process with an authorization memorandum for the Passport Information Electronic Records System.
OIG recommends that the Bureau of Diplomatic Security, in coordination with the Bureau of Information Resource Management, fully comply with Department policy by completing the Systems Authorization Process with an authorization memorandum for the Classified Investigative Management System.
OIG recommends that the Bureau of Diplomatic Security, in coordination with the Bureau of Information Resource Management, fully comply with Department policy by completing the Systems Authorization Process with an authorization memorandum for the SY Namecheck.
OIG recommends that the Bureau of Information Resource Management develop and implement a corrective action plan that addresses how the Department will comply with Department policy on the Systems Authorization Process. The corrective action plan should identify the root cause of compliance failures, action steps to resolve such compliance failures, improvement benchmarks and a timeframe for completion, and an escalation process to hold system owners accountable.
