U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Federal Information Security Modernization Act

Report Information

Date Issued
Report Number
2026-17628
Report Type
Audit
Description
The Federal Information Security Modernization Act of 2014 (FISMA) requires each agency’s Inspector General (IG) to conduct an annual independent evaluation to determine the effectiveness of the information security program (ISP) and practices of its respective agency.  Our audit scope was limited to answering the fiscal year (FY) 2025 IG metrics, which include 20 core and 5 supplemental IG metrics.  The FISMA methodology considers metrics at a maturity level 4 (managed and measurable) or higher to be at an effective level of security. Based on our analysis of the 25 IG metrics and associated maturity models, we determined Tennessee Valley Authority’s (TVA) ISP and practices were operating in an effective manner for FY 2026 as defined by the FY 2025 IG FISMA Reporting Metrics.  However, we identified areas for improvement in both the core and supplemental metrics to further improve TVA’s ISP and practices. 
Joint Report
No
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

We recommend the Senior Vice President, Chief Information Officer, Information Technology, develop and consistently maintain a comprehensive and accurate inventory of its system interconnections.

We recommend the Senior Vice President, Chief Information Officer, Information Technology, consistently utilize Tennessee Valley Authority’s standard data elements/taxonomy to inform which mobile software assets can/cannot be introduced into the network.

We recommend the Senior Vice President, Chief Information Officer, Information Technology, consistently implement Tennessee Valley Authority’s policies and procedures for flaw remediation to ensure all deployed software utilizes supported software versions on critical software platforms.

We recommend the Senior Vice President, Chief Information Officer, Information Technology, consistently implement Tennessee Valley Authority’s policies and procedures for sanitization of digital media prior to the destruction or reuse of media containing Personally Identifiable Information or other sensitive agency data.