trade-press
VA Rejects All 19 FISMA Recommendations as CIO Vacancy Hits Two Years
Zero-trust dollars are appropriated, but the department rates itself at the lowest maturity rung for its core defenses, and there's no published plan to change that.
A FISMA audit found VA's information security program deficient in seven areas, yielding 19 OIG recommendations. VA concurred with none, dismissing the audit as "a snapshot in time." The department has operated without a Senate-confirmed CIO for two years and has cycled through two acting CISOs. Meanwhile, zero-trust funding increased in the FY2026 budget, but VA's own assessment puts its defenses at the lowest maturity rung, with no published plan connecting the spending to outcomes.