← oversight.gov

DODIG-2023-057 - Recommendation D-2023-0057-D000CR-0001-0004.A4b

Closed · 2023-03-24

From report

Report
Audit of DoD Actions Taken to Implement Cybersecurity Protections Over Remote Access Software in the Coronavirus Disease–2019 Telework Environment
OIG report number
DODIG-2023-057
Recommendation number
D-2023-0057-D000CR-0

Recommendation text

(U) Rec. A.4.b: The DoD OIG recommended that the Chief Information Officer of the Defense Intelligence Agency direct network and system administrators to disable inactive user accounts after no more than 35 days of inactivity in accordance with the Windows 10 Security Technical Implementation Guide, develop compensating controls, or formally accept the risk of not disabling the inactive user accounts.