Improving Controls over IT Equipment
- VA faces continuing challenges in controlling IT equipment.
- Problems with accuracy and completeness of IT equipment inventory data, the lack of user-level accountability, and physical security weaknesses at IT equipment storage locations leave VA vulnerable to loss, theft, and misappropriation of VA IT assets.
- VA reported tens of thousands of missing IT equipment items as a result of its fiscal year 2007 inventory—including computers that may have stored sensitive personal and medical data—posing a risk that these data could be compromised.
^ Back to topWhat Needs to Be Done
To improve accountability of IT equipment inventory and reduce the risk of disclosure or compromise of sensitive personal and medical information, VA should
- review property inventory records and confirm that all IT equipment, regardless of the organizational equipment inventory listing, is identified in the property system;
Highlights of GAO-08-918 (PDF)
- establish and implement a policy requiring development of standardized naming classifications for IT equipment—including item name, manufacturer, and model—for recording IT equipment into local property inventory systems;
Highlights of GAO-08-918 (PDF)
- develop a list of medical equipment with data storage capability that should be considered as IT equipment for inventory control purposes;
Highlights of GAO-08-918 (PDF)
- develop a procedure for identifying hard drive serial numbers with both the property identification numbers and serial numbers of host computers; and
Highlights of GAO-08-918 (PDF)
- revise the definition of IT storage locations in VA's Handbook 0730/1, Security and Law Enforcement, to include informal IT storage locations and require these locations to be included in physical security inspections.
Highlights of GAO-08-918 (PDF)
^ Back to topKey Reports
- Veterans Affairs: Continued Action Needed to Reduce IT Equipment Losses and Correct Control Weaknesses
- GAO-08-918, July 31, 2008
- Summary (HTML) Highlights Page (PDF) Full Report (PDF, 52 pages) Accessible Text Recommendations (HTML)
- Veterans Affairs: Lack of Accountability and Control Weaknesses over IT Equipment at Selected VA Locations
- GAO-07-1100T, July 24, 2007
- Summary (HTML) Highlights Page (PDF) Full Report (PDF, 15 pages) Accessible Text
- Veterans Affairs: Inadequate Controls over IT Equipment at Selected VA Locations Pose Continuing Risk of Theft, Loss, and Misappropriation
- GAO-07-505, July 16, 2007
- Summary (HTML) Highlights Page (PDF) Full Report (PDF, 59 pages) Accessible Text Recommendations (HTML)