Federal Information Security Modernization Act
Report Information
Recommendations
We recommend the Vice President and Chief Information and Digital Officer, Technology and Innovation, define policies, procedures, and processes for developing and maintaining a comprehensive and accurate inventory of its information system and system interconnections that can be used for system authorizations and monitor the inventory as part of TVA’s information system continuous monitoring strategy.
We recommend the Vice President and Chief Information and Digital Officer, Technology and Innovation, improve the hardware asset management processes to include standard data elements/taxonomy that are used to inform what assets can be or cannot be introduced into the network as part of network authentication process.
We recommend the Vice President and Chief Information and Digital Officer, Technology and Innovation, define standard data elements/taxonomy for software assets that are used to (a) develop and maintain an up-to-date inventory of software assets and licenses, including mobile applications, and (b) inform what assets can or cannot be introduced to the network.
We recommend the Vice President and Chief Information and Digital Officer, Technology and Innovation, ensure the configuration management process is consistently implemented for all information systems.
We recommend the Vice President and Chief Information and Digital Officer, Technology and Innovation, ensure contingency plans are consistently tested as required by policy.