Changeflow GovPing Consumer Protection FBI Information Security Management Program Audit
Routine Guidance Added Final

FBI Information Security Management Program Audit

Favicon for oig.justice.gov DOJ Inspector General Reports
Published March 31st, 2026
Detected April 1st, 2026
Email

Summary

DOJ OIG published Audit Report 26-039 reviewing the FBI's information security management program under the Federal Information Security Modernization Act of 2014 for Fiscal Year 2025. The audit assessed the FBI's compliance with federal information security requirements and made 12 recommendations for improvement. This internal government audit does not impose new regulatory obligations on private sector entities.

What changed

The DOJ Office of the Inspector General conducted an audit of the FBI's information security management program pursuant to FISMA FY 2025, assessing the Bureau's implementation of information security controls and compliance with federal cybersecurity requirements. The audit resulted in 12 recommendations addressing identified weaknesses in the FBI's security posture.

This audit report is directed at the FBI as an internal executive branch review. Federal agencies and contractors supporting government systems may wish to review the findings to benchmark their own FISMA compliance programs against identified gaps. No immediate action deadlines or penalties are associated with this report for external parties.

Source document (simplified)

  1. Home
  2. Reports

Audit of the Federal Bureau of Investigation’s Information Security Management Program Pursuant to the Federal Information Security Modernization Act of 2014, Fiscal Year 2025

Read Report
Posted Date

March 31, 2026

Report Number 26-039 Component Federal Bureau of Investigation Report Type Audit Number of Recommendations 12

Named provisions

Information Security Management Program FISMA Compliance

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
DOJ OIG
Published
March 31st, 2026
Instrument
Guidance
Legal weight
Non-binding
Stage
Final
Change scope
Minor
Document ID
Report No. 26-039

Who this affects

Applies to
Government agencies
Industry sector
9211 Government & Public Administration
Activity scope
Cybersecurity Information Security
Geographic scope
United States US

Taxonomy

Primary area
Cybersecurity
Operational domain
Compliance
Compliance frameworks
NIST CSF
Topics
Data Privacy Defense & National Security

Get Consumer Protection alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when DOJ Inspector General Reports publishes new changes.

Optional. Personalizes your daily digest.

Free. Unsubscribe anytime.