We recommended the Assistant Secretary for Information and Technology consistently implement an improved continuous monitoring program in accordance with the NIST Risk Management Framework. Specifically, regarding the independent evaluation of the effectiveness of security controls prior to granting authorization decisions.
We recommended the Assistant Secretary for Information and Technology implement improved processes for reviewing and updating key security documentation, including Security Control Assessments and Privacy Impact Assessments as needed. Such updates will ensure all required information is included and accurately reflects the current environment, new security risks, and applicable Federal standards.
We recommended the VA Office of Personnel Security, Human Resources, and Contract Offices strengthen processes to ensure appropriate levels of background investigations are performed timely and completed for applicable VA employees and contractors.
We recommended the Assistant Secretary for Information and Technology ensure contingency plans for all systems and applications are updated and tested in accordance with VA requirements.
We recommended the Assistant Secretary for Information and Technology implement improved procedures to ensure that system outages are resolved within stated recovery time objectives.
We recommended the Assistant Secretary for Information and Technology ensure backups are conducted periodically and tested in accordance with established standards for VA system and application data.
We recommended the Assistant Secretary for Information and Technology ensure system owners consistently implement processes for periodic reviews of user account access and maintain access authorization documentation. Remove unnecessary and inactive accounts on systems and networks.
We recommended the Assistant Secretary for Information and Technology ensure system owners consistently follow termination procedures for the timely disablement of user accounts and the proper completion of termination checklists for separated personnel.
We recommended the Assistant Secretary for Information and Technology work with system owners and change implementers to improve adherence to standards and best practices across the Systems Development Lifecycle (SDLC) for testing and approval of system changes for VA systems and networks.
We recommended the Assistant Secretary for Information and Technology work with system owners and application teams to implement and enforce standards for processes related to preventing and detecting potential unauthorized changes across all platforms and applications in the environment.
We recommended the Assistant Secretary for Information and Technology ensure that all systems and platforms are monitored for compliance with documented VA standards for baseline configurations. Ensure that system owners consistently implement and monitor their configurations.
We recommended the Assistant Secretary for Information and Technology implement automated software management processes on all agency platforms to identify and prevent the use of unauthorized software on agency devices.
We recommended the Assistant Secretary for Information and Technology work with system owners to ensure adherence to established procedures for maintaining, documenting, and monitoring an accurate software and logical hardware inventory for system boundaries across the enterprise.
We recommended the Assistant Secretary for Information and Technology implement improved processes for monitoring and analyzing significant system audit events for unauthorized or unusual activities across all systems and platforms in accordance with VA policy.
We recommended the Assistant Secretary for Information and Technology enable system audit logs on all critical systems and platforms and conduct centralized reviews of security violations across the enterprise.
We recommended the Assistant Secretary for Information and Technology implement improved mechanisms to continuously identify and remediate security deficiencies on VA’s network infrastructure, database platforms, and Web application servers in accordance with established policy timeframes. If patches cannot be applied or are unavailable, other protections or mitigations should be documented and implemented to address the specific risks.
We recommended the Assistant Secretary for Information and Technology continue to implement controls that restrict vulnerable medical devices from unnecessary access from the general network.
We recommended the Assistant Secretary for Information and Technology implement improved processes to require system owners and management to provide adequate credentials to ensure security scans are authenticated to end devices where feasible and the subsequent vulnerabilities are remediated in a timely manner.
We recommended the Assistant Secretary for Information and Technology improve the process for tracking and resolving vulnerabilities that cannot be addressed by enterprise processes within policy timeframes. Implement mitigations for identified security deficiencies by applying security patches, system software updates, or configuration changes to reduce applicable security risks. Additionally, VA should enhance their process for updating baseline images to ensure aged vulnerabilities are not introduced into the environment.