GAO:优先公开建议:国务院(2025) 15页

VIP文档

ID:73437

阅读量:0

大小:0.57 MB

页数:15页

时间:2025-04-19

金币:10

上传者:PASHU
Page 1 GAO-25-108069 State Priority Recommendations
441 G St. N.W.
Washington, DC 20548
Comptroller General
of the United States
April 11, 2025
The Honorable Marco Rubio
Secretary of State
U.S. Department of State
2201 C Street, NW
Washington, DC 20520
Priority Open Recommendations: Department of State
Dear Secretary Rubio:
Congratulations on your appointment. The purpose of this letter is to call your personal attention
to three areas based on GAO’s past work and 13 open priority recommendations, which are
enclosed.
1
Additionally, there are 619 other open recommendations that we will continue to
work with your staff to address.
We are highlighting the following areas that warrant timely and focused attention. Specifically:
Addressing weaknesses in cybersecurity. State has not fully implemented its program to
identify and monitor risk to assets and the information maintained on its systems. As we
reported in September 2023, until the department implements required risk management
activities, it lacks assurance that its security controls are operating as intended.
2
Moreover,
State is likely not fully aware of information security vulnerabilities and threats affecting mission
operations.
GAO recommends that State take several actions, including (1) mitigating known vulnerabilities,
(2) conducting bureau-level risk assessments for the 28 bureaus that owned information
systems that GAO reviewed, (3) ensuring that its information systems have valid authorizations
to operate in accordance with department policies and federal guidance, (4) ensuring that the
Chief Information Officer (CIO) has access to assets at bureaus and posts to continuously
monitor for threats and vulnerabilities that may affect mission operations, (5) ensuring that all
system contingency plans for high value assets are tested annually as required by department
policies, and (6) directing the CIO to update an October 2020 matrix to better ensure
compliance with applicable department policies and federal guidance. In addition, there are
about 500 recommendations related to technical security control deficiencies in State's IT
infrastructure that also warrant attention.
1
GAO considers a recommendation to be a priority if, when implemented, it may significantly improve government
operations, for example, by realizing large dollar savings; eliminating mismanagement, fraud, and abuse; or making
progress toward addressing a high-risk or duplication issue.
2
GAO, Cybersecurity: State Needs to Expeditiously Implement Risk Management and Other Key Practices, GAO-23-
107012 (Washington, D.C.: Sept. 28, 2023).
资源描述:

这是美国政府问责局(GAO)于2025年4月11日致国务卿马尔科·卢比奥的信,指出国务院需关注的三个领域及相关建议。一是网络安全存在弱点,未全面实施资产风险识别与监控计划,可能导致信息系统受攻击,建议采取减轻漏洞、开展风险评估等行动;二是加强对外援助监测,在对乌援助及对墨援助中,存在对实施伙伴监督不足、未制定监测和评估计划的问题,建议定期监测实施伙伴筛选分包商的情况,制定相关计划;三是改善海外不动产规划,存在延迟维护和自然灾害风险,且未制定应对计划和使自然灾害恢复计划与人员配置相匹配,建议制定解决延迟维护的计划,调整相关规划。

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭