From a recent study by Social Security's Office of Inspector General (OIG):
Our objective was to determine whether the Social Security Administration’s (SSA) overall information security program and practices were effective and consistent with the requirements of the Federal Information Security Modernization Act of 2014 (FISMA), as defined by the Department of Homeland Security(DHS). ...
Although SSA established an Agency-wide information security program and practices, we identified a number of deficienciesrelated to Risk Management, Configuration Management, Identity and Access Management, Data Protection and Privacy, Security Training, Information Security Continuous Monitoring, Incident Response, and Contingency Planning. Many of the weaknesses we identified were similar to the deficiencies reported in past FISMA performance audits. SSA’s information security program was “Not Effective” according to DHS criteria. ...No details are given in the brief stub of a report released to the public.
