Key Takeaways
- The Department of Veterans Affairs (VA) failed its Fiscal Year 2025 Federal Information Security Modernization Act (FISMA) audit, with deficiencies identified in vulnerability management, incident response, configuration management, identity and access controls, contingency planning, background investigations, and the agency‑wide security management program.
- CliftonLarsonAllen LLP (CLA), the independent auditor, concluded that the VA remains non‑compliant with FISMA despite progress on prior audit recommendations.
- The VA disagreed with the audit’s findings and its 19 recommendations, asserting that many noted issues are already addressed, underway, or do not reflect the current state of its cybersecurity program.
- The agency highlighted recent accomplishments, including completion of its Cybersecurity Supply Chain Risk Management Strategy, deployment of automated log‑analysis tools, and a 93 % reduction in legacy plans of action and milestones.
- Looking ahead, the VA plans to enroll 100 % of enterprise identities in an Identity Governance Administration solution, protect half of medical devices with next‑generation firewall‑based zone isolation, and remediate all priority‑one vulnerabilities within two weeks by FY 2029.
- A vacant Chief Information Officer (CIO) position has been cited by the Government Accountability Office as a contributing factor to the VA’s software‑management challenges; a deputy CIO was recently appointed, while the nominee for CIO awaits Senate scheduling.
Introduction and Audit Findings
The Department of Veterans Affairs continues to struggle with meeting the requirements of the Federal Information Security Modernization Act (FISMA). In its Fiscal Year 2025 audit, the VA’s Office of the Inspector General reported that the independent audit firm CliftonLarsonAllen LLP (CLA) identified multiple areas where the department fell short of compliance. The audit, which serves as a snapshot of the VA’s information‑security posture at a specific point in time, concluded that the agency remains deficient despite having closed several recommendations from previous FISMA reviews. The findings underscore persistent gaps in the VA’s ability to protect its information systems and data, raising concerns about the safeguards surrounding veteran health records, benefits information, and other critical VA data.
Specific Deficiencies Noted
CLA’s report enumerated a series of concrete shortcomings across eight broad categories. First, vulnerability management was found lacking, with the VA failing to consistently identify, prioritize, and remediate software weaknesses. Second, incident response and monitoring processes were insufficient, meaning that security events were not always detected, analyzed, or contained in a timely manner. Third, configuration management weaknesses left systems exposed due to improperly hardened settings. Fourth, identity management and access controls exhibited failures, notably the inconsistent disabling of accounts belonging to former employees or contractors. Fifth, contingency planning—particularly disaster recovery and continuity of operations—did not meet required recovery time objectives. Sixth, background investigations for certain higher‑risk positions were deemed inadequate, potentially exposing the agency to insider‑threat risks. Seventh, outdated operating systems and unpatched applications persisted across the VA’s network. Finally, the agency‑wide security management program, which should provide overarching governance, risk management, and compliance oversight, was judged immature and insufficiently integrated across the VA’s disparate components.
VA’s Response and Non‑concurrence
In reaction to the audit, the VA issued a formal response stating that it did not concur with CLA’s findings or its 19 recommendations. The department argued that the audit “captured a snapshot in time” and did not fully account for the security controls, monitoring mechanisms, and risk‑based decision‑making processes already in place across the organization. The VA emphasized that non‑concurrence does not equate to disagreement with the need for improvement; rather, it reflects the belief that many of the recommended actions are already underway, have been implemented, or do not accurately represent the current state of its cybersecurity program. This stance highlights a recurring tension between external auditors’ point‑in‑time assessments and the VA’s assertion of continuous, dynamic security management.
Ongoing Efforts and Improvements
Despite its disagreement with the audit’s conclusions, the VA pointed to several recent accomplishments that it contends demonstrate progress. In FY 2025, the agency completed its Cybersecurity Supply Chain Risk Management Strategy, a framework designed to mitigate risks introduced by third‑party vendors and contractors. It also deployed automated log‑analysis tools aimed at improving anomaly detection and enabling faster identification of potential threats. Additionally, the VA reported a 93 % reduction in plans of action and milestones that were more than a year old, indicating a concerted effort to close legacy remediation items. These initiatives suggest that the VA is investing in technology and process enhancements intended to bolster its security posture, even if external auditors view the results as insufficient for full FISMA compliance.
Future Goals for FY 2026‑2029
Looking forward, the VA outlined a set of ambitious objectives to be achieved between fiscal years 2026 and 2029. Chief among these is the goal to enroll 100 % of enterprise identities into an Identity Governance Administration (IGA) solution, which would centralize user provisioning, de‑provisioning, and access‑rights management across the department. The VA also aims to protect 50 % of medical devices through next‑generation firewall‑based zone isolation, thereby segmenting critical clinical equipment from broader network traffic. Another priority is the remediation of all priority‑one vulnerabilities within two weeks of detection, a target that would significantly shrink the window of exposure to known exploits. Meeting these goals would address several of the deficiencies highlighted in the CLA audit, particularly around identity management, vulnerability management, and network segmentation.
Impact of CIO Vacancy and Leadership Changes
The Government Accountability Office (GAO) recently noted that some of the VA’s software‑management challenges are exacerbated by a prolonged vacancy in the Chief Information Officer role. While the nominee, Gary Shatswell, has not yet been placed on the Senate’s confirmation schedule, the department announced that Keith Rhodes—previously the deputy director of enterprise network services at the Department of Agriculture—has begun serving as the VA’s deputy CIO. This leadership infusion may help bridge the gap left by the absent CIO, providing additional oversight and strategic direction for the VA’s IT and cybersecurity initiatives. Nonetheless, the absence of a confirmed CIO continues to be cited as a structural impediment to cohesive, department‑wide security governance.
Conclusion
The VA’s ongoing FISMA audit failures reveal a complex picture of an agency striving to modernize its cybersecurity defenses while contending with legacy systems, staffing gaps, and the sheer scale of its operations. Although external auditors identify substantial shortcomings in vulnerability management, incident response, configuration management, identity and access controls, contingency planning, background investigations, and overall security program management, the VA maintains that many of these issues are already being addressed or mischaracterized by a point‑in‑time assessment. Recent accomplishments—such as the completion of a supply‑chain risk strategy, deployment of automated log‑analysis tools, and dramatic reduction in aged remediation plans—demonstrate measurable progress. The agency’s forward‑looking targets for identity governance, medical‑device protection, and rapid vulnerability remediation signal a commitment to closing the identified gaps. Leadership developments, including the appointment of a deputy CIO amid a lingering CIO vacancy, may further strengthen the VA’s ability to execute its cybersecurity roadmap. Ultimately, aligning external audit perspectives with the VA’s internal view of continuous improvement will be essential for achieving sustained FISMA compliance and safeguarding the sensitive data of the nation’s veterans.

