2019 Review of the Peace Corps' Information Security Program
Report Information
Recommendations
Disclaimer: Open/Closed recommendations are updated semiannually.That the Director move the chief information security officer position and staff to a new office that is independent from the chief information officer. These two separate offices should both report to the same senior executive.
That the Director appoint the chief information officer and the chief information security officer to serve on the Senior Policy Committee.
That the Director appoint the chief information security officer to serve on the Technical Advisory Board.
That the Director dedicate resources, with the knowledge, skills, and abilities, to fully implement a comprehensive Enterprise Risk Management program.
That the Director provide training to all senior management and Office of Chief Information Officer staff on risk-based, security focused approach, including FISMA framework and how it ties into business and IT operations.