Expands the main menu

Breadcrumb

Audit Reports

  • Image
    Management of PRC Smartphones Cover
Jun
26
2023
Report Number:
23-024-R23
Report Type:
Audit Reports
Category: Postal Regulatory Commission

Management of the Postal Regulatory Commission’s Smartphones

Background

The Postal Regulatory Commission (Commission) is an independent agency that exercises regulatory oversight of the U.S. Postal Service. With five commissioners, supported by a staff of approximately 70 individuals, the Commission uses smartphones to facilitate greater working efficiencies and operations, making them a core element of the Commission’s IT program.

Smartphones help facilitate communications, share on-the-go information, and run various software applications based on individual need. Often, these devices provide access to much of the same data and systems that would be available from an office desktop. Due to their mobile nature, this can present significant cybersecurity issues if the smartphones are not fully protected.

What We Did

Our objective was to assess the management of the inventory, security, and utilization of the Commission’s smartphones. We used a combination of data analytics, interviews, and control tests to determine if appropriate controls were in place and functioning as intended.

What We Found

Overall, we identified opportunities for improvement in the Commission’s management of inventory, security, and utilization of smartphones. Specifically, the Commission did not have (1) a standardized process for reviewing and maintaining its inventory; (2) key components to effectively manage the security of its smartphones; and (3) a written policy or procedure to review smartphone utilization billing. These issues occurred because the Commission did not follow a standardized process for inventory and utilization reviews, and it prioritized other IT projects over the security of its smartphones.

Recommendations

We made nine recommendations, including performing routine inventory and utilization reviews in compliance with industry best practices, developing a mobile device security policy, and providing end user smartphone security training.

Report Recommendations

# Recommendation Status Value Initial Management Response USPS Proposed Resolution OIG Response Final Resolution
1

Develop a standard operating procedure for smartphones, documenting how inventories should be performed and outlining the key elements to record for each smartphone.

Closed $0 Agree
2

In coordination with the Chief Information Security Officer and the Chief Information Officer, include smartphones in its automated asset discovery and vulnerability enumeration scans to comply with the Cybersecurity and Infrastructure Security Agency Binding Operational Directive 23-01.

Closed $0 Agree
3

Develop and implement a smartphone security policy that aligns with National Institute of Standards and Technology Special Publication 800-124.

Closed $0 Agree
4

Develop and provide training and awareness activities for smartphone users on smartphone threats, recommended security practices, and policies.

Closed $0 Agree
5

In coordination with the Chief Information Security Officer and the Chief Information Officer, perform threat profile modeling for smartphones to identify cybersecurity risks specific to smartphones at the Postal Regulatory Commission.

Closed $0 Agree
6

Develop and implement a standardized process for capturing and reviewing security logs that includes specific use cases to monitor for smartphones.

Open $0 Agree
7

In coordination with the Chief Information Security Officer and the Chief Information Officer, identify and document hardening standards and configuration settings for smartphones before issuing to end users.

Closed $0 Agree
8

Enroll all smartphones in a mobile device management program and enforce established configuration settings to include strong password credentials, restricted application downloads, automatic operating system patches, and data loss prevention measures.

Closed $0 Agree
9

Establish a utilization policy and operating procedures to review utilization data that better aligns with Executive Order 13589.

Closed $0 Agree