DHS Inspector General Finds 86 Percent of Federal Agencies Failed to Meet CISA Cloud Security Directives
A DHS Office of Inspector General report published Sunday found that 88 of 102
The problem is structural, not agency-specific: CISA can issue binding directives but lacks authority to compel compliance, leaving enforcement to voluntary self-reporting with no penalty attached, and the drop from 86% to 76% noncompliance between June and February shows remediation moving too slowly to close exposure windows tied to authentication and PII protections. Sourcing rests on a single DHS OIG report, with CyberScoop's initial treatment repackaged by Federal News Network and SC World without independent findings. The same decline may instead reflect agencies converging toward compliance under existing voluntary mechanisms, cutting against the enforcement-gap thesis. Congress, not CISA, holds the lever: statutory authority or budget conditioning. No such action has followed the report.
4 sources
- CISA Enhanced Cloud Security for Federal Information but Lacks Authority to Enforce Implementation of All Necessary Protective Actions -
DHS Office of Inspector General - Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack -
CyberScoop - Federal agencies fail to meet cloud security directive deadline -
SC World - IG report finds government cyber directives lack teeth -
Federal News Network