FY 2021 Review of the Peace Corps' Information Security Program
Report Information
Recommendations
Disclaimer: Open/Closed recommendations are updated semiannually.We recommend that the Director move the chief information security officer position and staff to a new office that is independent from the chief information officer. These two separate offices should both report to the same senior executive.
We recommend that the Chief Information Officer perform a full security assessment of the General Support System to obtain a complete understanding of system weaknesses.
We recommend that the Peace Corps further defines and implements the ERM program to ensure information security risks are communicated and monitored at the system, business process, and entity levels.
We recommend that the Peace Corps consistently improve and implement its inventory management process to ensure information system, hardware, and software inventories are accurate, complete, and up-to-date.