Changeflow GovPing Consumer Protection FBI Security Controls Audit - FISMA 2025
Routine Notice Amended Final

FBI Security Controls Audit - FISMA 2025

Favicon for oig.justice.gov DOJ Inspector General Reports
Published March 31st, 2026
Detected April 1st, 2026
Email

Summary

The DOJ Office of the Inspector General issued Audit Report 26-040 examining the FBI's security controls for the Bureau Investigative Document Management and Analysis System and the Global Mission Analytics Cloud System under FISMA requirements for Fiscal Year 2025. The audit assessed compliance with federal information security standards and identified control deficiencies requiring remediation.

What changed

The DOJ OIG conducted an audit of the FBI's security controls for two major IT systems: the Bureau Investigative Document Management and Analysis System and the Global Mission Analytics Cloud System. The audit evaluated compliance with the Federal Information Security Modernization Act of 2014 requirements. Report Number 26-040 documents findings regarding the design and operating effectiveness of security controls.

The FBI should review the audit findings and develop corrective action plans to address identified security control deficiencies. While Inspector General audit reports are non-binding, agencies typically respond with remediation steps. This audit applies to FBI operations and provides a framework for federal agencies undergoing similar FISMA assessments.

What to do next

  1. Review audit findings and assess current security controls against reported deficiencies
  2. Develop corrective action plans for any identified control gaps
  3. Implement remediation measures and document progress for follow-up review

Source document (simplified)

  1. Home
  2. Reports

Audit of the Federal Bureau of Investigation’s Security Controls, Bureau Investigative Document Management and Analysis System, and Global Mission Analytics Cloud System Pursuant to the Federal Information Security Modernization Act of 2014, Fiscal Year 2025

Read Report
Posted Date

March 31, 2026

Report Number 26-040 Component Federal Bureau of Investigation Report Type Audit

Named provisions

Bureau Investigative Document Management and Analysis System Global Mission Analytics Cloud System Federal Information Security Modernization Act

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
DOJ OIG
Published
March 31st, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Minor
Document ID
Report No. 26-040

Who this affects

Applies to
Government agencies Law enforcement
Industry sector
9211 Government & Public Administration
Activity scope
Cybersecurity Information Security Controls
Geographic scope
United States US

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF FISMA NIST 800-53
Topics
Defense & National Security Data Privacy

Get Consumer Protection alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when DOJ Inspector General Reports publishes new changes.

Optional. Personalizes your daily digest.

Free. Unsubscribe anytime.