11/15/2024 | Press release | Archived content
Overall, through the evaluation of FISMA metrics, it was determined that HHS's information security program rated "Not Effective" for FY 2024, which is the same as the "Not Effective" program rating from FY 2023.
The determination that HHS's information security program was "Not Effective" was made based on HHS's inability to meet the "Managed and Measurable" maturity level for the Core and Supplemental Inspector General metrics in the function areas of Identify, Protect, Detect, Respond, and Recover.
We made a series of six recommendations to HHS to strengthen its information security program through improved oversight and information security controls implementation.
HHS concurred with five of our recommendations. HHS did not concur with the recommendation to complete implementation of a cybersecurity risk management strategy, because it believes its current strategy is sufficient.
This report may be subject to section 5274 of the National Defense Authorization Act Fiscal Year 2023, 117 Pub. L. 263.