U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Management Assistance Report: The Process to Authorize and Track Information Technology Systems Needs Improvement

AUD-IT-17-56
    Report Contents
    Unclassified
    Recommendation Number
    1
    Closed Implemented Significant

    OIG recommends that the Bureau of Information Resource Management formally designate a central repository to track the status of systems authorizations and documentation for Department information systems, including Federal Information Security Management Act reportable systems.

    Recommendation Number
    2
    Closed Implemented

    OIG recommends that the Bureau of Information Resource Management update Department policies and procedures to reflect the designation of the central repository in Recommendation 1.

    Recommendation Number
    3
    Closed Implemented Significant

    OIG recommends that the Bureau of Consular Affairs, in coordination with the Bureau of Information Resource Management, fully comply with Department policy by completing the Systems Authorization Process with an authorization memorandum for the Consular Consolidated Database.

    Recommendation Number
    4
    Closed Implemented Significant

    OIG recommends that the Bureau of Consular Affairs, in coordination with the Bureau of Information Resource Management, fully comply with Department policy by completing the Systems Authorization Process with an authorization memorandum for the Passport Information Electronic Records System.

    Recommendation Number
    5
    Closed Implemented Significant

    OIG recommends that the Bureau of Diplomatic Security, in coordination with the Bureau of Information Resource Management, fully comply with Department policy by completing the Systems Authorization Process with an authorization memorandum for the Classified Investigative Management System.

    Recommendation Number
    6
    Closed Implemented Significant

    OIG recommends that the Bureau of Diplomatic Security, in coordination with the Bureau of Information Resource Management, fully comply with Department policy by completing the Systems Authorization Process with an authorization memorandum for the SY Namecheck.

    Recommendation Number
    7
    Closed New Report Significant

    OIG recommends that the Bureau of Information Resource Management develop and implement a corrective action plan that addresses how the Department will comply with Department policy on the Systems Authorization Process. The corrective action plan should identify the root cause of compliance failures, action steps to resolve such compliance failures, improvement benchmarks and a timeframe for completion, and an escalation process to hold system owners accountable.