From a recent report by Social Security's Office of Inspector General (OIG):
Objective
To determine whether the Social Security Administration’s (SSA) overall information security program and practices were effective and consistent with the Federal Information Security Modernization Act of 2014 (FISMA) requirements, as defined in the Fiscal Year (FY) 2022 core Inspector General (IG) FISMA reporting metrics. ...We engaged Grant Thornton LLP (Grant Thornton) to conduct this performance audit ...
Based on the FY 2022 core IG FISMA reporting metrics guidance, Grant Thornton concluded SSA’s overall security program was “Not Effective.”
Although SSA had established an Agency-wide information security program and practices, Grant Thornton identified deficiencies that may limit the Agency’s ability to adequately protect its systems and information. While SSA continued executing its risk-based approach to strengthen controls over its information systems and address weaknesses, Grant Thornton’s audit continued to identify persistent deficiencies in both the design and operation of controls related to the FY 2022 core IG FISMA reporting metrics. ...