We evaluated the U.S. Department of the Interior’s (DOI’s) and the U.S. Geological Survey’s (USGS’) implementation of Phase 1 of the Continuous Diagnostics and Mitigation (CDM) program for a USGS system.
Our evaluation revealed control deficiencies for hardware and software asset management and configuration management. Specifically, the DOI did not require bureaus and offices to maintain accurate hardware asset inventories for information systems, which prevented them from monitoring key security metrics through the DOI’s CDM dashboard.