fismatrade-pressNewsThe Broadside2 min read

VA Rejects All 19 FISMA Recommendations as CIO Vacancy Hits Two Years

Zero-trust dollars are appropriated, but the department rates itself at the lowest maturity rung for its core defenses, and there's no published plan to change that.


TL;DR

A FISMA audit found VA's information security program deficient in seven areas, yielding 19 OIG recommendations. VA concurred with none, dismissing the audit as "a snapshot in time." The department has operated without a Senate-confirmed CIO for two years and has cycled through two acting CISOs. Meanwhile, zero-trust funding increased in the FY2026 budget, but VA's own assessment puts its defenses at the lowest maturity rung, with no published plan connecting the spending to outcomes.

The Department of Veterans Affairs' information security program is deficient across seven areas, according to an independent FISMA audit conducted this summer. The VA Office of Inspector General made 19 recommendations. The department concurred with none of them. Its response: the audit was "a snapshot in time."

That phrase is more revealing than VA likely intended. An audit is supposed to be a snapshot: a clear look at one moment so you can fix what it shows. Dismissing it as "just a snapshot" is what an organization says when it has no process for turning findings into fixes. And the organizational chart explains why.

VA has operated without a Senate-confirmed CIO for two years. The administration's third nominee had his hearing in June and remains unconfirmed. The CISO seat has cycled through two acting holders in a row. The two seats most responsible for enterprise IT risk have been empty, in practice, for going on two years. Acting officials can keep the lights on. They rarely have the standing to force policy and practice to meet, or to tell a secretary that they aren't.

The consequences are visible in the numbers. VA's fiscal 2026 budget included a substantial increase in zero-trust funding, real money appropriated to close the cybersecurity gap. Yet when asked at a recent industry day how its zero-trust maturity stacks up, the department rated identity, network, and application defenses at the lowest rung: "Initial." VA has the money. It doesn't have a published plan mapping that funding to prioritized risks, and Congress has no way to check whether the spending is moving the department off "Initial."

A recent VA memo adds another data point: contracts can no longer require FedRAMP certification. The secretary owns the risk of serving veterans; accepting risk instead of deferring to FedRAMP is defensible in principle. But accepting risk requires analysis, tracing what a non-FedRAMP system means for the veteran at the other end. Without a CISO driving that analysis, "risk acceptance" becomes a procurement shortcut, not a security decision.

The pattern is enterprise risk governance by vacancy. Policy exists. Funding exists. What's missing is someone in the seat long enough to make them meet, and a department willing to treat an audit as something other than a snapshot to dismiss.


Published ·Updated ·Deep Fathom

VA Rejects All 19 FISMA Recommendations as CIO Vacancy Hits Two Years — The Broadside