The FDIC OIG issued its 2026 report on the FDIC’s Information Security Program per statutory FISMA requirements. The objective of this evaluation was to assess the effectiveness of the FDIC’s information security program and practices. The OIG contracted with KPMG LLP to perform this work.
Inspectors General assign maturity level ratings to each FISMA metric, as well as an overall rating, using a scale of 1-5, where 5 represents the highest level of maturity. KPMG determined that the FDIC’s overall information security program was operating at a Maturity Level 4 (Managed and Measurable).
KPMG found the FDIC’s information security program was generally effective and that the FDIC established several information security program controls and practices that were consistent with FISMA requirements. KPMG did not identify any new findings specific to this year’s metrics. However, the report references previously identified security control weaknesses that reduced the effectiveness of the FDIC’s information security program and practices that the FDIC should continue to improve in order to enhance the agency’s security program. The report cites two recommendations from prior FISMA reports that remain open and warrant continued attention.
The FDIC’s response indicates that the FDIC is committed to completing corrective actions to address these outstanding recommendations and further strengthen its information security program.