Recommendation Contents
OIG recommends that the Chief Information Officer, in coordination with the Information Security Steering Committee, document an enterprise-wide continuous monitoring strategy that includes a continuous monitoring policy and assesses the security state of information systems and is consistent with Federal Information Security Management Act requirements, Office of Management and Budget policy, and applicable National Institute of Standards and Technology guidelines.
