Changeflow GovPing Consumer Protection FBI Information Security Management Program Audit
Routine Guidance Added Final

FBI Information Security Management Program Audit

Favicon for oig.justice.gov DOJ Inspector General Reports
Published
Detected
Email

Summary

DOJ OIG published Audit Report 26-039 reviewing the FBI's information security management program under the Federal Information Security Modernization Act of 2014 for Fiscal Year 2025. The audit assessed the FBI's compliance with federal information security requirements and made 12 recommendations for improvement. This internal government audit does not impose new regulatory obligations on private sector entities.

What changed

The DOJ Office of the Inspector General conducted an audit of the FBI's information security management program pursuant to FISMA FY 2025, assessing the Bureau's implementation of information security controls and compliance with federal cybersecurity requirements. The audit resulted in 12 recommendations addressing identified weaknesses in the FBI's security posture.

This audit report is directed at the FBI as an internal executive branch review. Federal agencies and contractors supporting government systems may wish to review the findings to benchmark their own FISMA compliance programs against identified gaps. No immediate action deadlines or penalties are associated with this report for external parties.

Archived snapshot

Apr 1, 2026

GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.

  1. Home
  2. Reports

Audit of the Federal Bureau of Investigation’s Information Security Management Program Pursuant to the Federal Information Security Modernization Act of 2014, Fiscal Year 2025

Read Report
Posted Date

March 31, 2026

Report Number 26-039 Component Federal Bureau of Investigation Report Type Audit Number of Recommendations 12

Named provisions

Information Security Management Program FISMA Compliance

Get daily alerts for DOJ Inspector General Reports

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

About this page

What is GovPing?

Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission

What's from the agency?

Source document text, dates, docket IDs, and authority are extracted directly from DOJ OIG.

What's AI-generated?

The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.

Last updated

Classification

Agency
DOJ OIG
Published
March 31st, 2026
Instrument
Guidance
Legal weight
Non-binding
Stage
Final
Change scope
Minor
Document ID
Report No. 26-039

Who this affects

Applies to
Government agencies
Industry sector
9211 Government & Public Administration
Activity scope
Cybersecurity Information Security
Geographic scope
United States US

Taxonomy

Primary area
Cybersecurity
Operational domain
Compliance
Compliance frameworks
NIST CSF
Topics
Data Privacy Defense & National Security

Get alerts for this source

We'll email you when DOJ Inspector General Reports publishes new changes.

Free. Unsubscribe anytime.

You're subscribed!