Report 25-13

Fiscal Year 2024 Federal Information Security Modernization Act

This SBA OIG report summarizes the results of our fiscal year 2024 Federal Information Security Modernization Act (FISMA) evaluation and assessment of the U.S. Small Business Administration’s (SBA) information security program.

About this document and download

This report summarizes the results of our fiscal year 2024 Federal Information Security Modernization Act (FISMA) evaluation and assessment of the U.S. Small Business Administration’s (SBA) information security program. Our objectives were to determine whether SBA complied with FISMA and assessed the maturity of controls used to address risks in each of the nine security domains.

We found SBA generally responded to previously identified vulnerabilities and made progress in one of the nine domains, in the area of security training. The agency met the baseline in the area of incident response but fell below the baseline for an effective security program in several areas. We rated SBA’s overall information security program as “not effective.”

This fiscal year there are seven new recommendations for improvement. There are 11 open recommendations from 3 prior evaluations. Repeat recommendations from prior years were not included in this report because they have not yet been implemented. The agency successfully closed four recommendations from fiscal year 2023. SBA managers agreed with six recommendations and partially agreed with one. Their corrective actions resolved all the recommendations.

Download .pdf
File size: 812KB
Effective: April 29, 2025
Owned by: Office of Inspector General
Related Programs: Related programs: Agency Management
Last updated April 29, 2025