Breadcrumb

Mission Accountability Support Tracker Lacked Sufficient Security Controls

Report Information

Issue Date
Report Number
21-03080-142
VA Office
Office of the Secretary (SVA)
Report Author
Office of Audits and Evaluations
Report Type
Review
Report Topic
Information Technology and Security
Major Management Challenges
Benefits for Veterans
Recommendations
4
Questioned Costs
$0
Better Use of Funds
$0
Congressionally Mandated
No

Summary

Summary
The VA Office of Inspector General (OIG) evaluated the merits of a May 2021 hotline complaint alleging that the Veterans Benefits Administration (VBA) disregarded privacy procedures so it could more quickly use a workload tracking system without receiving the appropriate security authorization. The Mission Accountability Support Tracker (MAST) helps quantify the work VBA’s support services staff perform in response to employee requests for facility, equipment, and vehicle management; reasonable accommodation; and identification card issuance and renewal. Because staff use personally identifiable information (PII) in their work, the information could be compromised in an unauthorized, unsecure application. The complaint also alleged that VBA knew that MAST did not have an approved privacy threshold analysis or privacy impact assessment, yet trained staff on using the system and knowingly “loaded” PII into the application. The privacy threshold analysis and privacy impact assessment mitigate the risk of unauthorized access and subsequent data misuse, changes, loss, or disclosure. The assessments also help ensure that systems or applications have security controls that are appropriate for the sensitivity of the information stored. The OIG found that VBA and the Office of Information and Technology (OIT) did not correctly follow privacy and security procedures. VBA’s privacy threshold analysis was inaccurate, and OIT did not conduct a privacy impact assessment. OIT’s misclassification of MAST as an asset resulted in insufficient security controls. Further, VBA lacked the authority to operate MAST before using it in regional offices. The OIG made four recommendations to ensure future information technology projects follow an approved management process and that VBA provides sufficient guidance to staff to ensure MAST is used as intended while keeping the PII of VA employees and contractors safe and secure.

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
The OIG recommends the Assistant Secretary for Information and Technology develop controls to help ensure minor applications are not misclassified as assets and undergo the appropriate security accreditation and certification process.
No. 2
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT),Veterans Benefits Administration (VBA)
The OIG recommends the Assistant Secretary for Information and Technology in conjunction with the Under Secretary for Benefits, make certain that appropriate security and privacy controls are implemented during the development of information technology systems before being hosted on VA’s network.
No. 3
Open Recommendation Image, Square
to Information and Technology (OIT),Veterans Benefits Administration (VBA)
The OIG recommends the Under Secretary for Benefits, in conjunction with the Assistant Secretary for Information and Technology, establish a mechanism to gain assurance that proper Office of Information Technology project management processes and protocols are followed when establishing information technology systems and applications.
No. 4
Closed and Implemented Recommendation Image, Checkmark
to Veterans Benefits Administration (VBA)
The OIG recommends the Under Secretary for Benefits establish policies and procedures to ensure the Mission Accountability Support Tracker is used appropriately and does not contain unnecessary personally identifiable information.