DHS OIG finds TSA privileged accounts unsecured, separated staff still active
The fifth DHS component access-control failure uncovered by OIG audits in recent years points to a systematic FISMA compliance gap that no one appears to be closing.
TL;DR
The DHS Office of Inspector General found TSA failed to secure privileged accounts, perform annual access reviews, and consistently disable accounts for separated employees across its 60,000-person workforce. The vulnerabilities could allow attackers to compromise TSA networks and cause what OIG called "serious or catastrophic damage to operations and assets." TSA attributed the gaps to staff shortages, resource constraints, and inadequate policies. The agency has since begun monthly access reviews and is developing a formal account-disablement process for departing staff. This is the most recent of several DHS-component access-control audits OIG has conducted, Customs and Border Protection was flagged for similar neglect last month.
The DHS Office of Inspector General audit of TSA's access controls, published earlier this week, found the agency wasn't securing privileged accounts, wasn't conducting annual access reviews, and wasn't consistently disabling accounts for employees who had separated. For an agency of roughly 60,000 people responsible for screening passengers, detecting explosives, and coordinating pipeline and surface-transportation security, OIG said the vulnerabilities could allow threat actors to compromise networks and cause "serious or catastrophic damage to operations and assets."
TSA attributed the findings to staff shortages, resource constraints, time limitations, and inadequate policies, the same operational pressures that surface in virtually every federal IT audit. The agency has made partial progress since the audit concluded: it evaluated privileged-account permissions, implemented monthly access reviews, and is developing a formal process to rescind access when employees leave. But OIG did not publicly specify what remediation threshold would trigger a re-audit, leaving the timeline for closure uncertain.
This is not TSA's problem alone. OIG's office confirmed this is its fifth access-control audit of a DHS component. Customs and Border Protection was cited for similar neglect last month, and the three earlier audits stretch back to 2024. When five separate DHS components produce materially identical findings (unsecured privileged accounts, stale permissions, no reliable offboarding) it stops looking like component-level mismanagement and starts looking like a department-wide failure of FISMA accountability.
FISMA requires agencies to implement and annually test controls for identifying and authenticating users, authorizing access, and auditing system activity. The pattern across these OIG reports suggests DHS is not consistently meeting that obligation at the component level, and the department hasn't demonstrated a corrective mechanism that prevents the next component from failing the same audit.
For contractors and vendors who connect to TSA systems (whether for screening equipment maintenance, IT support, or surface-transportation cybersecurity programs) the risk transfers. A contractor whose credentials remain active after a contract ends is the same access-control failure viewed from outside the perimeter. Until TSA's formal account-disablement process is operational and verified, that risk persists.
Published ·Deep Fathom