Board Report: 2018-IT-B-008R March 21, 2018
The Board's public website provides a large and diverse audience with timely and accurate information about the mission and work of the Board. Per the requirements of the Federal Information Security Modernization Act of 2014, we evaluated the adequacy of select information security controls for protecting the Board's public website from compromise.
Overall, the information security controls that we tested were adequately designed and implemented. However, we identified improvement opportunities in the areas of configuration management and risk management.
As a result, we are making recommendations to strengthen the security of the Board's public website in these areas.
Given the sensitivity of information security review work, our reports in this area are generally restricted. Such is the case for this audit report.