CFPB Report: 2017-IT-C-019 October 31, 2017
The Federal Information Security Modernization Act of 2014 requires us to review the CFPB's information security program every year. We did so according to U.S. Department of Homeland Security guidelines, which involves evaluating the program's maturity level (from a low of 1 to a high of 5) across several areas.
The CFPB's information security program is operating at level 3 (consistently implemented), with the agency performing several activities indicative of a higher maturity level. However, the agency can mature its information security program to ensure that it is effective, or operating at level 4 (managed and measurable).
We are making recommendations to strengthen the CFPB's information security program in the areas of risk management, identity and access management, security training, incident response and contingency planning.