Take whatever administrative action deemed appropriate concerning the individuals involved in the appropriate and untimely handling of the notification of stolen VA data.
No. 2
to Information and Technology (OIT)
Closure Date: 9/18/2007
Establish one clear, concise VA policy on safeguarding protected information when stored or not stored in VA automated systems, ensure policy is readily available, and employees held accountable.
No. 3
to Information and Technology (OIT)
Closure Date: 9/24/2008
Modify the mandatory Cyber Security and Privacy Awareness training to identify and provide a link to all applicable laws and VA policy.
No. 4
to Human Resources and Administration/Operations, Security, and Preparedness (HRA/OSP)
Closure Date: 6/22/2016
We recommend that the Secretary ensure that all position descriptions are evaluated and have proper sensitivity level designations, that there is consistency nationwide for positions that are similar in nature or have similar access to VA protected information and automated systems, and that all required background checks are completed in a timely manner.
No. 5
to Information and Technology (OIT)
Closure Date: 12/20/2007
Establish VA-wide policy for contracts for services that requires access to protected information, ensures contractor personnel held to same standards, and information is safeguarded.
No. 6
to Information and Technology (OIT)
Closure Date: 9/7/2007
Establish VA policy and procedures that provide clear, consistent criteria for reporting, investigating, and tracking incidents of loss, theft, or potential disclosure of protected information.
The OIG recommends the CO seek a reduction of $10,842,681.30 to the proposed contract amounts by negotiating the recommended amounts identified in table 1.