OBJECTIVE
In accordance with the Federal Information Security Management Act and OMB Circular A-130, Federal agencies are required to ensure external service providers that are processing, storing, or transmitting Federal information or operating information systems on behalf of the Federal Government meet the same security requirements as Federal agencies. These requirements include policies and procedures for detecting and reporting security incidents. We will conduct an audit to evaluate the effectiveness of controls at selected HHS divisions to ensure service providers are identifying and reporting cybersecurity incidents. The purpose of this audit is to determine whether HHS has effective controls that ensure service providers identify and report cybersecurity incidents in a timely manner.
TIMELINE
-
February 24, 2022Announced
-
September 22, 2025Complete
Reporting of Security Incidents by HHS Contracted Service Providers has been marked as complete. This audit resulted in 2 recommendations.
REPORT PUBLISHED
View in Recommendation Tracker