From: Smithsonian Institution| Office of Inspector General
AUDIT PLAN FISCAL YEAR 2016
***
The fiscal year 2015 FISMA audit will evaluate the Smithsonian’s information security program.
Although the Smithsonian is not subject to FISMA, it has elected to implement FISMA requirements to ensure that it has an effective information security program. In accordance with FISMA, OIG performs an independent annual evaluation of the Institution’s information security program and practices, including the testing and evaluation of controls to safeguard information and systems. Previous OIG information security audits have highlighted the need for improvements in key areas such as network access controls, security awareness and training, disaster recovery, system documentation, and configuration management. We will contract with an independent firm to conduct the review. OIG serves as the contracting officer’s technical representative. [Emphasis added, Editor]
Leave a Reply