The objective of the evaluation is to determine the effectiveness of the Commission’s information security program and practices. The evaluation will assess information security program controls to support the OIG’s reporting of FISMA metrics into the Department of Homeland Security’s CyberScope application.