GAO calls out agency trio for IT recommendation failures
Briefly

The Government Accountability Office reported failures by the General Services Administration, Environmental Protection Agency, and Department of Homeland Security in implementing IT cybersecurity recommendations. DHS has 43 unresolved recommendations, including seven priority items, while GSA has four and EPA has eleven outstanding issues. A consistent failure among the agencies is the inadequate logging of cybersecurity events and the lack of annual IT portfolio reviews. Additionally, the EPA faces issues with cloud software management, failing to submit required documentation and maintain service level agreements with cloud providers.
The Government Accountability Office criticized the General Services Administration, Environmental Protection Agency, and Department of Homeland Security for failing to implement IT-related cybersecurity recommendations.
DHS has 43 unresolved recommendations dating back to 2018, with seven identified as priority. GSA and EPA have four and eleven outstanding items, respectively.
Common failures among GSA, EPA, and DHS include improper logging of cybersecurity events and failure to conduct annual IT portfolio reviews as required by policy.
EPA's unresolved recommendations related to poor cloud software management and failure to submit necessary documentation for compliance with cloud security requirements.
Read at Theregister
[
|
]