Audit Liaison
Patrick D. Howard · Auerbach Publications eBooks · 2011
Government inspectors generally play a signicant role in ensuring agency compliance with FISMA. Agency-level Oces of the Inspector General (OIG) are required by FISMA to conduct an audit of the agency compliance with FISMA each year. Just as CISOs are provided with guidance each year on what is to be reported, agency OIGs are provided related guidance on areas where they should focus attention, and specic questions they must address in their audit report. One should recognize that the annual FISMA audit may be used by OIG to support other ongoing audit and evaluation eorts they may have planned or that may be under way (i.e., annual nancial statement audit), and the results can be reected in other audit products. e scope of OIG’s annual FISMA audit is to measure compliance with FISMA itself, with NIST guidance related to the information security program and its implementation, as well as agency policy that has been published relative to the information security program. Additionally, the Government Accountability Oce (GAO) is regularly asked by Congress to assess specic aspects of agency information security eorts that touch compliance with FISMA and other legislation and OMB directives as part of governmentwide audits. ere are examples where an Inspector General (IG) audit will be conducted on the basis of ndings of a GAO audit, whether or not the ndings specically relate to the agency.