Evaluation of the U.S. AbilityOne Commission’s Compliance with FISMA for Fiscal Year 2020
The objective of the evaluation was to assess the effectiveness of the Commission’s security program and practices across key functional areas as of September 30, 2020. The Commission made progress through implementation of security policies, procedures, and strategies, but lacked quantitative and qualitative measures to assess them. During FY20, there were six findings and nine corresponding recommendations regarding the Commission’s information security program including: 1. Vulnerabilities not being remediated in a timely manner; 2.