Blog
CFPB’s Inspector General Downgrades Bureau’s Information Security Program, Issues New Recommendations in Annual Audit
On October 31, the Fed’s Office of Inspector General (OIG) released its annual Federal Information Security Modernization Act audit of the CFPB’s information security program, concluding the program’s maturity level declined from the prior year and was no longer effective. The report cited lapses in maintaining authorizations to operate various systems, insufficient cybersecurity risk analyses, and continued use of outdated software as contributing to the decline in effectiveness. Specifically,…
By: Orrick, Herrington & Sutcliffe LLP