Sorry, you need to enable JavaScript to visit this website.

Breadcrumb

  1. Home
  2. Reports
  3. Audit

Pension Benefit Guaranty Corporation FY 2023 Federal Information Security Modernization Act of 2014 Report

Report Information

Date Issued
Report Number
AUD-2024-06
Report Type
Audit
Joint Report
No
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

PBGC should reconfigure administrative interfaces with strong, unique passwords that are difficult to guess. Ideally, passphrases should be used instead of passwords. These passphrases should contain a mixture of uppercase characters, lowercase characters, numbers and symbols.

Software that is no longer supported or receiving regular security updates from the vendor should be upgraded to supported versions with relevant security patches.

PBGC should replace invalid certificates with those issued by a trusted Certificate Authority. Additionally, user security training should be implemented to promote user skepticism when dealing with invalid certificates while accessing web resources.