Board Report: 2022-IT-B-013 September 30, 2022
The Federal Information Security Modernization Act of 2014 requires us to perform an annual independent evaluation of the Board's information security program.
The Board's information security program continues to operate effectively, and the agency has strengthened the program since our review last year. Nonetheless, the Board can enhance its cybersecurity risk management processes.
This report contains a recommendation and a matter for management consideration to strengthen cybersecurity risk management processes.