The Health and Human Services Department is getting better at cybersecurity but still has a ways to go before being in full compliance, according to a recent audit report conducted by Ernst & Young on behalf of the agency inspector general.
Auditors conducted a review of HHS’s compliance with the Federal Information Security Management Act (FISMA) and found deficiencies in 10 major areas.
Download: Review of HHS FISMA Compliance
“Despite the progress made to improve the HHS and its operating divisions’ information security program, opportunities to strengthen the program exist,” they wrote. “Exploitation of these weaknesses could result in unauthorized access to and disclosure of sensitive information and disruption of critical operations for HHS.”
Federal Times explored some of these possibilities during a deep dive into years of cybersecurity incident reports, including the ramifications of the persistent malware problems plaguing the Center for Disease Control and Prevention and the National Institutes of Health.
Get in on the game: There’s still time to play with the data through Federal Times’ partnership with data visualization company Datawrapper. Head here for everything you need to do your own data journalism.
The Ernst & Young audit looked directly at the procedures for detecting and dealing with incidents and offered suggestions for strengthening the department’s posture in 10 areas.
From the report:
1. Continuous Monitoring Management: HHS has formalized its information security continuous monitoring (ISCM) program through development of ISCM policies, procedures and strategies. However, HHS has not implemented a departmentwide fully-implemented continuous monitoring program which includes continuously monitoring, updating and finalizing policies and procedures indicating how divisions address, implement strategies and report on DHS metrics. This includes vulnerability management, software assurance, information management, patch management, license management, event management, malware detection, asset management and network management.
2. Configuration Management: Some divisions did not consistently review and remediate or address the risk presented by vulnerabilities discovered in configuration baseline compliance and vulnerability scans performed through Security Content Automation Protocol tools.
3. Identity and Access Management: Some divisions did not consistently implement account management procedures for shared accounts, new personnel, transferred personnel and terminated personnel.
4. Incident Response and Reporting: Oversight processes had not been implemented by HHS to enforce incident response and reporting procedures at the divisions.
5. Risk Management: HHS did not implement procedures to oversee that system inventories are complete, accurate and effectively managed, including reconciling to the division-managed system inventory tools.
6. Security Training: Some divisions did not monitor the completion of role-based training for significant security responsibilities and other security training for personnel using IT systems.
7. Plan of Action and Milestones: Plan of Action & Milestones (POA&Ms) were not consistently documented and tracked by the divisions and HHS.
8. Remote Access Management: Some divisions had not developed formal and finalized remote access policies and procedures.
9. Contingency Planning: Some divisions did not complete required contingency planning documentation, including business impact analysis, continuity of operation plans, and information system contingency plans.
10. Contractor Systems: Some divisions did not have effective contractor oversight protocols.
The full report goes into more detail on each area, including making recommendations on how HHS can achieve its security goals.
HHS officials agreed with most of the recommendations, though individual components are digging into some of the specifics as they relate to those divisions.




