2022-018 Continue to Strengthen Application Risk Management Program Federal Agency: U.S. Department of Health and Human Services State Entity: Department of Community Health (DCH) Corrective Action Plans: Significant progress has been made in implementing the department's corrective action plan, wh...
2022-018 Continue to Strengthen Application Risk Management Program Federal Agency: U.S. Department of Health and Human Services State Entity: Department of Community Health (DCH) Corrective Action Plans: Significant progress has been made in implementing the department's corrective action plan, which is still in progress. The Agency has acquired additional critical cybersecurity program resources and is recruiting others to assist the department in fully remediating the identified findings. These include hiring a Chief Information Security Officer and Cybersecurity Analyst on September 1, 2022, and December 15, 2022, respectively. Furthermore, ten Cybersecurity student interns will start on May 3, 2023, with ongoing recruitment for a Cybersecurity Architect/Engineer. Likewise, the necessary third-party security services required to remediate the Policy/Procedure findings have been procured via a Statewide contract awarded to Compliance Point. To date, the security services vendor has completed the initial drafting of 12 out of 20 Organization-wide Security Policies based on NIST Federal Computer Security Standards, with an expected completion date for all Organizational Policies by September 11, 2023. The CAP Remediation Plan Project is progressing well, and we should meet the planned completion date of December 31, 2023. Estimated Completion Date: December 31, 2023 Contact Person: Chad Purcell, CTO Telephone: 470-757-7871; E-mail: chad.purcell1@dch.ga.gov