FedCFO Search Engine

@FedCFO Twitter Feed

Showing posts with label FISMA. Show all posts
Showing posts with label FISMA. Show all posts

Friday, May 30, 2014

Outdated DHS Financial Systems May Be Inhibiting Internal IT Controls, OIG Audit Says

In recent years, said a new Department of Homeland Security (DHS) Office of Inspector General (OIG) IT management report for the Fiscal Year 2013 DHS financial statement audit, “DHS’s financial system functionality may be inhibiting the agency’s ability to implement and maintain internal controls, notably IT applications controls supporting financial data processing and reporting at some components.”

“At most components,” OIG report, “the financial systems have not been substantially updated since being inherited from legacy agencies several years ago. Therefore, in FY 2013, we continued to evaluate and consider the impact of financial system functionality over financial reporting.”

In FY 2013, a total of 103 findings were issued, of which approximately 69 percent are repeated from last year.

According to the audit, approximately 35 percent of repeat findings were for IT deficiencies that management represented were corrected during FY 2013. The new findings in FY 2013 resulted both from additional IT systems and business processes within the scope of the audit this year and from control deficiencies identified in areas which were effective in previous years, and were noted at all DHS components.

Customs and Border Protection (CBP) and the Federal Law Enforcement Training Center (FLETC) had the greatest number of new findings.

OIG reported that “many key DHS financial systems are not compliant with the financial management systems requirements of the Federal Financial Management Improvement Act of 1996 and Office of Management and Budget (OMB) Circular Number A-127, Financial Management Systems, revised. DHS financial system functionality limitations add substantially to the department’s challenges of addressing systemic internal control weaknesses and limit the department’s ability to leverage IT systems to effectively and efficiently process and report financial data.”

With respect to DHS and its components’ financial systems’ IT controls, the audit “noted certain matters in the areas of security management, access controls, configuration management, segregation of duties and contingency planning.”

During the audit, “certain matters involving financial reporting internal controls (comments not related to IT) and other operational matters, including certain deficiencies in internal control” were discovered that are considered “to be significant deficiencies and material weaknesses,” and were communicated in writing to management and those charged with governance in KPMG’s Independent Auditors’ Report and in a separate letter to the Office of Inspector General and the DHS Chief Financial Officer.

-Anthony Kimery, HStoday.us
READ MORE...

Tuesday, June 03, 2008

GSA Announces BAAR Bid Opening

WASHINGTON –The U. S. General Services Administration (GSA) today invited interested parties to compete for a project to replace the agency’s Billing and Accounts Receivable (BAAR) system.

GSA’s Office of the Chief Financial Officer (OCFO) also posted a Request for Quotation (RFQ) on the agency’s eBuy web site for a 45-day period. Solicitations and/or questions related to the RFQ may be submitted through 2 PM June 12, 2008. The RFQ is for a base period of three years and one two-year option period.

The new system will establish standard accounting business processes across GSA’s financial management enterprise architecture, and produce bills for GSA’s many business lines in large volumes. The solution will address federal compliance issues required by Federal Information Security Management Act (FISMA), Federal Financial Management Improvement Act (FFMIA), Financial Management Enterprise Architecture (FMEA), and other federal rules and regulations to support GSA’s capabilities as a Financial Management Line of Business (FMLOB).

For more information on the RFQ, please visit http://www.ebuy.gsa.gov.

READ MORE...

Tuesday, March 06, 2007

DHS to Manage and Improve IT Operations

Paul A. Schneider, U.S. Department of Homeland Security Under Secretary For Management, testified before the U.S. House of Representatives Committee on Homeland Security Subcommittee on Management, Investigations, and Oversight. The following is the portion of his testimony regarding aspects of Federal financial management.

The DHS CIO and Chief Financial Officer (CFO) are working through the Internal Controls Assessment Project to bring information security policy and actions to the Federal Information Security Management Act (FISMA) standards.

READ MORE...

Saturday, December 02, 2006

Private-sector shared-services providers must be FISMA-compliant

Karen Evans has a message for industry about being a shared-services provider to the government for human resources or financial management services: She doesn’t care what you call yourself—center of excellence or shared-services provider or whatever—but don’t bother jumping into the scrum if you don’t comply with the Federal Information Security Management Act.

While it is obvious that agencies have to comply with the computer security mandate, Evans, the Office of Management and Budget’s administrator for e-government and IT, said there have been a lot of questions about exactly what being FISMA compliant means.

“Vendors’ shared-services providers need to have their systems certified and accredited under the FISMA guidelines,” said Evans after speaking at an event on the Financial Management Line of Business in Washington sponsored by IBM Corp. and SAP of America Inc. of Newton Square, Pa. “Agencies and their inspector[s] general need to check to make sure contractors have met FISMA.”

But, she added, it is incumbent on agency officials to ask vendors for the documentation that proves FISMA compliance. Evans said it also will show how much “residual risk” the systems have.

Evans said the foundation for the lines of business have been laid, and now it is a matter of moving to them. She said that while the focus has been on larger departments, the smaller agencies have benefited most from the shared-services provider concept.

“The service centers help small agencies accelerate … [their] compliance with financial-management requirements,” Evans said.

Evans also pointed to the Interior Department’s recent launch of its new financial management system as a good example of a public-private partnership. Interior partnered with IBM to implement its Financial Business Modernization System at two bureaus last month.

“I was there when it came up live, and it was a noneventful event, which is what we like,” she said. “We got to see the policies operationalized, and that was exciting.”

-Jason Miller, GCN.com