home >
back
Federal Emergency Management Agency (FEMA) IT Audit
Challenges
Audits of Department of Homeland
Security (DHS) Information Systems that
process financial data are critical in that they assure
stakeholders that the financial data produced by the
Information Systems is accurate and verifiable. Therefore,
adverse audit findings must be reduced and eventually
eliminated. When FEMA was faced with unfavorable Federal
Information System Management Act (FISMA) audit findings
they turned to DRC for support with remediation and
resolution.
Solutions
DRC provides a full set of services to
support IT audits. We assist in determining root causes and
required corrective actions to address audit findings,
resolve audit issues, and implement recommendations. We
provide subject matter expertise, conduct training on root
cause analysis within DHS, and leverage this knowledge to
help FEMA confirm whether root causes are being addressed in
remediation plans.
DRC supports DHS by providing guidance,
training, and feedback to the components on the development
and maintenance of Plan of Action and Milestones (POA&Ms).
DRC also reviews POA&M data and presents current information
to FEMA system security officers, managers, and owners.
Additionally, DRC utilizes the existing audit database and
shared network drive to track audit requests and remediation
efforts to further ensure timely delivery of information.
Our work evaluating the results of remediation activities
ensures successful completion of remediation activities, as
well as follow up to validate that the remediation was
effective.
DRC's institutional knowledge of FEMA's
unique environment allowed us to lead and train internal
teams in evaluating implemented system security and internal
controls against required DHS and FEMA policies and
procedures. DRC leveraged knowledge gained at the ISO level
and from past work at DHS to ensure that controls meet
requirements at FEMA and USCG.
Benefits/Achievements
-
Developed a strong working
relationship with DHS external and internal auditors
involved in the FEMA audits.
-
Established an open, two-way line of
direct communication with DHS auditors.
-
Cut through bureaucratic stonewalls
to obtain clarifications and resolutions to important
audit issues faster.
-
Enabled FEMA to provide auditors
with requested information in a more timely fashion.
Interested in more information?
|