fismatrade-pressNewsThe Broadside2 min read

VA fails FISMA audit, non-concurs on 19 recommendations

VA argues the FISMA audit captured a snapshot that missed its continuous monitoring controls, but GAO data shows some vulnerabilities at the department persisted across multiple assessment cycles.


TL;DR

The VA Office of Inspector General reported Monday that an independent FISMA audit for fiscal 2025 found the department deficient in seven areas: vulnerability management, incident response, configuration management, identity and access controls, contingency planning, background investigations, and agency-wide security management. VA formally non-concurred with all 19 recommendations, arguing the audit captured a "snapshot in time" while the department "manages cybersecurity continuously through ongoing monitoring, automated tools, and risk-based decision making." The non-concurrence is unusual, agencies typically accept or negotiate OIG findings. VA's position is complicated by a December 2025 GAO report showing high-risk vulnerabilities at the department persisted 17 to 21 months, well past VA's own 60-day remediation policy.

VA fails FISMA audit, non-concurs on 19 recommendations
Editorial illustration · drawn by The Broadside

The independent audit, conducted by CliftonLarsonAllen LLP, found VA still not in compliance with FISMA despite closing several recommendations from prior years. CLA flagged deficiencies in all seven assessed domains: vulnerability management, incident response and monitoring, configuration management, identity management and access controls, contingency planning, background investigations, and the agency-wide security management program. Specific failures included accounts of former employees not consistently disabled, insufficient background checks for some higher-risk positions, outdated operating systems, unpatched application vulnerabilities, and system outages exceeding recovery time objectives.

VA didn't just push back. It formally non-concurred with every finding and all 19 recommendations. The department's response, published alongside the OIG report, argues the audit "captured a snapshot in time, while VA manages cybersecurity continuously through ongoing monitoring, automated tools, and risk-based decision making." VA framed non-concurrence not as rejecting the need for improvement but as asserting that "many of the recommended actions are already underway, already implemented, or do not fully reflect the current state of VA's cybersecurity program."

The snapshot defense is harder to sustain against GAO's own data. In a December 2025 report, GAO found that as of July 2025, VA hadn't remediated two high-risk vulnerabilities over a 17-to-21-month period, against a departmental policy requiring remediation within 60 days. The same report noted VA failed to update remediation dates for at least two program findings, and a high-risk vulnerability on one system sat 15 months past its scheduled fix date with no revised timeline. These aren't point-in-time artifacts that a continuous monitoring program would catch and close. They're gaps that survived multiple assessment cycles and multiple opportunities for detection.

The pattern isn't new. VA's OIG has flagged FISMA deficiencies since at least fiscal 2021. Facility-level inspections at St. Cloud and Northern Arizona in 2023 found the same vulnerability management and access control weaknesses that appear in the FY2025 audit. The GAO last week attributed some of VA's software management problems to its vacant CIO position; nominee Gary Shatswell hasn't been scheduled for a Senate hearing, though Keith Rhodes started as deputy CIO this month.

For federal assessors, VA's non-concurrence matters beyond this single audit. When an agency the size of VA rejects findings on methodological grounds, it forces a question FISMA doesn't cleanly answer: what weight should an auditor give to continuous monitoring evidence when the same agency's own data shows controls failing across multiple cycles?


Published ·Updated ·Deep Fathom