The U.S. Department of Education's Federal Information Security Modernization Act of 2014 Report: For Fiscal Year 2025. ED-OIG/A25IT0212
Saved in:
| Title: | The U.S. Department of Education's Federal Information Security Modernization Act of 2014 Report: For Fiscal Year 2025. ED-OIG/A25IT0212 |
|---|---|
| Language: | English |
| Authors: | Office of Inspector General (OIG) (ED) |
| Source: | Office of Inspector General, US Department of Education. 2025. |
| Availability: | Office of Inspector General, US Department of Education. Available from: ED Pubs. P.O. Box 1398, Jessup, MD 20794-1398. Tel: 877-433-7827; e-mail: edpubs@edpubs.ed.gov; Web site: https://oig.ed.gov/reports/list |
| Peer Reviewed: | N |
| Page Count: | 68 |
| Publication Date: | 2025 |
| Document Type: | Reports - Research |
| Descriptors: | Public Agencies, Federal Legislation, Educational Legislation, Information Security, Information Technology, Information Systems, Computer Security, Program Effectiveness, Program Evaluation, Audits (Verification), Risk Management, Privacy, Training, Prevention, Database Management Systems, Federal Aid, Student Financial Aid, Contingency Management, Organizational Objectives |
| Abstract: | The main objective of the Fiscal Year (FY) 2025 Federal Information Security Modernization Act of 2014 (FISMA) audit was to determine whether the United States Department of Education (Department)'s overall information security program and practices are effective as they relate to federal information security requirements. To meet this objective, Williams Adley utilized the FY 2025 Inspector General (IG) FISMA reporting metrics, issued on April 3, 2025, by the Office of Management and Budget (OMB). The reporting metrics provide independent assessors and IGs with a standardized framework to evaluate and report on the effectiveness and maturity of an agency's information security program. To properly conclude on the effectiveness of the Department's information security program and practices, Williams Adley utilized a rotational strategy to select five in-scope systems. The Background section of this report provides additional context on the Department, FISMA and the FY 2025 IG reporting metrics. At the conclusion of the FY 2025 audit, Williams Adley determined that the Department's overall information security program and practices are effective as nine out of the ten FISMA domains met the requirements needed to operate at a Level 4 maturity rating or higher. Although the Department has an effective information security program, Williams Adley identified a total of sixteen conditions across the ten FISMA domains -- five of which resulted in a Notice of Finding and Recommendations -- which represent potential areas of improvement for the Department. The identified conditions were evaluated from a risk-based standpoint and within the context of the overall information security program to determine their root cause and associated level of risk. Within this report, Williams Adley offers the Department recommendations on how to address each identified root cause. Williams Adley's secondary objective was to follow up on the status of outstanding recommendations to determine whether the Department has implemented their proposed corrective actions. Overall, Williams Adley determined that eight prior year recommendations were closed during the audit period and the status of the remaining open recommendations are found within Appendix B, along with their proposed target action dates. Lastly, Williams Adley prepared the responses to the core and supplemental metric questions identified within the CyberScope questionnaire, as shown in Appendix C. All Federal agencies are required to submit their IG FISMA metric determinations into the Department of Homeland Security's CyberScope application by August 1, 2025. [This audit and report was conducted and created by Williams, Adley & Company -- DC, LLC (Williams Adley).] |
| Abstractor: | ERIC |
| Entry Date: | 2025 |
| Accession Number: | ED677433 |
| Database: | ERIC |
| FullText | Text: Availability: 0 CustomLinks: – Url: https://eric.ed.gov/contentdelivery/servlet/ERICServlet?accno=ED677433 Name: ERIC Full Text Category: fullText Text: Full Text from ERIC |
|---|---|
| Header | DbId: eric DbLabel: ERIC An: ED677433 AccessLevel: 3 PubType: Report PubTypeId: report PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: The U.S. Department of Education's Federal Information Security Modernization Act of 2014 Report: For Fiscal Year 2025. ED-OIG/A25IT0212 – Name: Language Label: Language Group: Lang Data: English – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Office+of+Inspector+General+%28OIG%29+%28ED%29%22">Office of Inspector General (OIG) (ED)</searchLink> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="SO" term="%22Office+of+Inspector+General%2C+US+Department+of+Education%22"><i>Office of Inspector General, US Department of Education</i></searchLink>. 2025. – Name: Avail Label: Availability Group: Avail Data: Office of Inspector General, US Department of Education. Available from: ED Pubs. P.O. Box 1398, Jessup, MD 20794-1398. Tel: 877-433-7827; e-mail: edpubs@edpubs.ed.gov; Web site: https://oig.ed.gov/reports/list – Name: PeerReviewed Label: Peer Reviewed Group: SrcInfo Data: N – Name: Pages Label: Page Count Group: Src Data: 68 – Name: DatePubCY Label: Publication Date Group: Date Data: 2025 – Name: TypeDocument Label: Document Type Group: TypDoc Data: Reports - Research – Name: Subject Label: Descriptors Group: Su Data: <searchLink fieldCode="DE" term="%22Public+Agencies%22">Public Agencies</searchLink><br /><searchLink fieldCode="DE" term="%22Federal+Legislation%22">Federal Legislation</searchLink><br /><searchLink fieldCode="DE" term="%22Educational+Legislation%22">Educational Legislation</searchLink><br /><searchLink fieldCode="DE" term="%22Information+Security%22">Information Security</searchLink><br /><searchLink fieldCode="DE" term="%22Information+Technology%22">Information Technology</searchLink><br /><searchLink fieldCode="DE" term="%22Information+Systems%22">Information Systems</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+Security%22">Computer Security</searchLink><br /><searchLink fieldCode="DE" term="%22Program+Effectiveness%22">Program Effectiveness</searchLink><br /><searchLink fieldCode="DE" term="%22Program+Evaluation%22">Program Evaluation</searchLink><br /><searchLink fieldCode="DE" term="%22Audits+%28Verification%29%22">Audits (Verification)</searchLink><br /><searchLink fieldCode="DE" term="%22Risk+Management%22">Risk Management</searchLink><br /><searchLink fieldCode="DE" term="%22Privacy%22">Privacy</searchLink><br /><searchLink fieldCode="DE" term="%22Training%22">Training</searchLink><br /><searchLink fieldCode="DE" term="%22Prevention%22">Prevention</searchLink><br /><searchLink fieldCode="DE" term="%22Database+Management+Systems%22">Database Management Systems</searchLink><br /><searchLink fieldCode="DE" term="%22Federal+Aid%22">Federal Aid</searchLink><br /><searchLink fieldCode="DE" term="%22Student+Financial+Aid%22">Student Financial Aid</searchLink><br /><searchLink fieldCode="DE" term="%22Contingency+Management%22">Contingency Management</searchLink><br /><searchLink fieldCode="DE" term="%22Organizational+Objectives%22">Organizational Objectives</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: The main objective of the Fiscal Year (FY) 2025 Federal Information Security Modernization Act of 2014 (FISMA) audit was to determine whether the United States Department of Education (Department)'s overall information security program and practices are effective as they relate to federal information security requirements. To meet this objective, Williams Adley utilized the FY 2025 Inspector General (IG) FISMA reporting metrics, issued on April 3, 2025, by the Office of Management and Budget (OMB). The reporting metrics provide independent assessors and IGs with a standardized framework to evaluate and report on the effectiveness and maturity of an agency's information security program. To properly conclude on the effectiveness of the Department's information security program and practices, Williams Adley utilized a rotational strategy to select five in-scope systems. The Background section of this report provides additional context on the Department, FISMA and the FY 2025 IG reporting metrics. At the conclusion of the FY 2025 audit, Williams Adley determined that the Department's overall information security program and practices are effective as nine out of the ten FISMA domains met the requirements needed to operate at a Level 4 maturity rating or higher. Although the Department has an effective information security program, Williams Adley identified a total of sixteen conditions across the ten FISMA domains -- five of which resulted in a Notice of Finding and Recommendations -- which represent potential areas of improvement for the Department. The identified conditions were evaluated from a risk-based standpoint and within the context of the overall information security program to determine their root cause and associated level of risk. Within this report, Williams Adley offers the Department recommendations on how to address each identified root cause. Williams Adley's secondary objective was to follow up on the status of outstanding recommendations to determine whether the Department has implemented their proposed corrective actions. Overall, Williams Adley determined that eight prior year recommendations were closed during the audit period and the status of the remaining open recommendations are found within Appendix B, along with their proposed target action dates. Lastly, Williams Adley prepared the responses to the core and supplemental metric questions identified within the CyberScope questionnaire, as shown in Appendix C. All Federal agencies are required to submit their IG FISMA metric determinations into the Department of Homeland Security's CyberScope application by August 1, 2025. [This audit and report was conducted and created by Williams, Adley & Company -- DC, LLC (Williams Adley).] – Name: AbstractInfo Label: Abstractor Group: Ab Data: ERIC – Name: DateEntry Label: Entry Date Group: Date Data: 2025 – Name: AN Label: Accession Number Group: ID Data: ED677433 |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=eric&AN=ED677433 |
| RecordInfo | BibRecord: BibEntity: Languages: – Text: English PhysicalDescription: Pagination: PageCount: 68 Subjects: – SubjectFull: Public Agencies Type: general – SubjectFull: Federal Legislation Type: general – SubjectFull: Educational Legislation Type: general – SubjectFull: Information Security Type: general – SubjectFull: Information Technology Type: general – SubjectFull: Information Systems Type: general – SubjectFull: Computer Security Type: general – SubjectFull: Program Effectiveness Type: general – SubjectFull: Program Evaluation Type: general – SubjectFull: Audits (Verification) Type: general – SubjectFull: Risk Management Type: general – SubjectFull: Privacy Type: general – SubjectFull: Training Type: general – SubjectFull: Prevention Type: general – SubjectFull: Database Management Systems Type: general – SubjectFull: Federal Aid Type: general – SubjectFull: Student Financial Aid Type: general – SubjectFull: Contingency Management Type: general – SubjectFull: Organizational Objectives Type: general Titles: – TitleFull: The U.S. Department of Education's Federal Information Security Modernization Act of 2014 Report: For Fiscal Year 2025. ED-OIG/A25IT0212 Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Office of Inspector General (OIG) (ED) IsPartOfRelationships: – BibEntity: Dates: – D: 31 M: 07 Type: published Y: 2025 Titles: – TitleFull: Office of Inspector General, US Department of Education Type: main |
| ResultId | 1 |