The Need for Better Monitoring: Social Security Administration Deficient in Software Approval and Monitoring

The Social Security Administration’s Office of Inspector General found that the agency’s

SSA employees, managers, and contractors did not always comply with the Agency’s software approval policy by obtaining a waiver before installing non-standard software. Further, in all seven software-related security incidents reviewed, we determined that no documented disciplinary action had been taken against the employee for not complying with the Agency’s software approval policy.

The OIG also determined that,

SSA’s monitoring of known Agency-wide software configurations was not sufficient. Moreover, we were unable to determine whether local management was effectively monitoring software because only one software waiver was submitted for approval.

One of the functions that NIST’s forthcoming draft Continuance Monitoring guidance document needs to address is ensuring that any SSA-type monitoring shortfalls are uncovered without the need for an OIG investigation.

The complete SSA OIG report is attached below.

SSA-OIG Evaluation Report

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *