Corrective action plan: For awareness, effective February 1, 2025, Anil Koindala was hired as the Health and
Human Services (HHS) Chief Information Security Officer (CISO).
At HHSC, the Deputy Executive Commissioner for each HHS organizational area is responsible for assigning an
information owne...
Corrective action plan: For awareness, effective February 1, 2025, Anil Koindala was hired as the Health and
Human Services (HHS) Chief Information Security Officer (CISO).
At HHSC, the Deputy Executive Commissioner for each HHS organizational area is responsible for assigning an
information owner (IO) for each of their area’s HHS information systems which also includes performing Risk
Assessments for the systems they are responsible for.
To ensure Risk Assessment compliance is met, the CISO will send out quarterly reminders to the IO for the
completion of risk assessments. The reminders have started to be sent on July 31, 2024. While the risk
assessment will be completed by the IO, the CISO will assist any non-compliant area with training that will be
provided by their Information Security Portfolio Manager (ISPM). Additionally, the CISO office ensures that a risk
assessment and System Security Plan (SSP) are in place before granting an Authority to Operate (ATO).
The CISO is currently developing policies and procedures to establish and publish a process for the successful
completion of Risk Assessments, including roles and responsibilities, processes, and procedures to ensure timely
completion and ongoing compliance.
Implementation date: August 31, 2025
Responsible persons: Anil Koindala, Chief Information Security Officer, Information Technology
Jeremy Sadler, Director, Information Security Risk
Cristina Denz, Manager, Policy and Compliance