OIG satisfied with CFPB information security program, provides recommendations

Orrick, Herrington & Sutcliffe LLP
Contact

Orrick, Herrington & Sutcliffe LLP

On October 31, OIG for the Fed and the CFPB published its 2024 Audit of the CFPB’s Information Security Program, reporting that the CFPB’s information security program operates effectively at a level-4 (managed and measurable) maturity. While the report noted the CFPB has taken steps to improve its security program since the last review, it included eight recommendations:

  1. Complete the finalization of an agencywide data classification policy that accounts for the sensitivity of the data maintained by the CFPB.
  2. Ensure that data classification and sensitivity labels are incorporated into the CFPB’s data loss prevention program.
  3. Strengthen flaw remediation processes by developing and implementing a process to clearly map identified vulnerabilities to system IP addresses, host names, and remediation owners within the CFPB’s configuration management database.
  4. Ensure that adequate resources are allocated to reinvestigate CFPB systems users.
  5. Develop and maintain a ransomware strategy and specific procedures that provide a formal, focused and coordinated approach to respond to ransomware attacks.
  6. Ensure that testing of mission-essential functions identified in the CFPB’s continuity of operations plan is periodically performed.
  7. Renew the authorization to use for the CFPB’s governance, risk and compliance tool.
  8. Implement a process that ensures the cyber risk information in the CFPB’s governance, risk and compliance tool is accurate and maintained.

The CFPB concurred with the recommendations and outlined plans to implement them. OIG will continue to monitor the CFPB’s progress in addressing the recommendations, as well as three unresolved findings from prior audits.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Orrick, Herrington & Sutcliffe LLP

Written by:

Orrick, Herrington & Sutcliffe LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Orrick, Herrington & Sutcliffe LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide