← oversight.gov

SBA - 22-19 - 3

Open · 2022-09-27

From report

Report
COVID-19 and Disaster Assistance Information Systems Security Controls
OIG report number
22-19
Recommendation number
3

Recommendation text

Implement in updated agency guidance, the requirements of OMB Circular No. A-123 that stipulate a SOC 1 Type 2 report is needed for all new and existing financial systems. This guidance should also require confirmation at least annually that the controls are functioning as designed.