Why It Matters
Only seven of the 22 civilian Chief Financial Officer (CFO) Act agencies reviewed had fully addressed all three of the Office of Management and Budget's networked device requirements, which cover establishing and maintaining device inventories and processing cybersecurity waivers, according to a new audit published Sept. 30 by the Government Accountability Office (GAO). The report says the gaps may leave agencies at risk of cyberattacks that could compromise sensitive data and systems.
The audit covers Internet of Things (IoT) devices and operational technology (OT) devices, including networked hardware such as building maintenance systems and specialized equipment in hospitals and laboratories. The Office of Management and Budget (OMB) has not issued updated guidance covering the current fiscal year, leaving agencies without a clear imperative to prioritize implementation or a timeline to complete their device inventories. Without those inventories, agencies may not know how many connected devices operate within their systems, and without updated OMB guidance and oversight, agencies may continue to struggle to apply appropriate security controls to vulnerable systems.
GAO's High Risk List includes cybersecurity, which identifies federal operations with serious vulnerabilities or in need of transformation.
The Big Picture
IoT and OT devices, including those used in building maintenance systems and specialized equipment in hospitals and laboratories, are part of the information systems that support the nation's infrastructure. Networked technologies face increasing cyber threats worldwide, and in July, cyber threat actors disrupted operations in the water sector by changing passwords to disconnect networked programmable logic controllers, a type of OT device. Emerging technologies such as artificial intelligence can compound the risks these systems face.
The IoT Cybersecurity Improvement Act of 2020 includes provisions for OMB and civilian CFO Act agencies to identify and protect networked devices. The act also directed GAO to report every two years on IoT guidance and the waiver process through the current year, and this report is the final installment in a three-part series.
OMB established its networked device requirements in December 2023 and updated them in January 2025, setting a September 2024 deadline for agencies to complete their initial inventories. That deadline passed approximately two years ago. As of September, of the 22 civilian CFO Act agencies reviewed, 15 had established an inventory, 11 were maintaining their inventories, and 10 had included all required information, such as asset descriptions and software versions, for each device. Overall, only seven agencies had fully addressed all three OMB requirements. No agencies had reported an IoT cybersecurity waiver.
Agencies cited technical and resource constraints and competing priorities as reasons for falling short, but GAO found that OMB's failure to issue updated guidance covering the current fiscal year left agencies without a clear imperative to prioritize implementation of the requirements or a timeline for doing so.
Broader Context
The audit's scope covers the 22 civilian CFO Act agencies. GAO compared those agencies' inventory implementation efforts with OMB requirements and interviewed relevant agency officials to obtain their views and verify the information provided.
GAO recommended that the OMB director issue updated cybersecurity guidance covering requirements for networked IoT and OT devices, including a clear imperative to prioritize implementation and a timeline for doing so, and that OMB oversee agencies' implementation of those requirements. The recommendation is still open, and OMB did not comment on the report. GAO said it will provide updated information when it confirms what actions OMB has taken in response.
The Bottom Line
The report is the final installment in a series of three reviews required by the IoT Cybersecurity Improvement Act of 2020. With only seven of the 22 agencies reviewed fully addressing all three OMB requirements, GAO concluded that updated guidance and oversight are needed to ensure agencies implement networked-device cybersecurity requirements.
Track this recommendation and related legislation at Legis1.com.
Access the Legis1 platform for comprehensive political news, data, and insights.
Spot something wrong? Report an issue with this article