The Government Accountability Office has called on the National Telecommunications and Information Administration to develop and implement organization-wide risk assessment, establish a data governance plan and implement other leading cybersecurity and interoperability practices to enhance the spectrum and broadband agency.
In a report published Thursday, GAO pointed out that implementing these practices would enable the NTIA to mitigate, reduce, identify and track risks.
Table of Contents
NTIA’s Modernization Journey
According to the congressional watchdog, NTIA has been in the process of modernizing its spectrum IT for over three years. In December 2024, the telecommunications agency awarded two contracts with a total value of $110 million to support the effort.
However, the watchdog pointed out that NTIA will continue to use its legacy IT.
GAO Recommendations
In the report, GAO found that NTIA did implement all leading cybersecurity practices during the planning stage of its modernization project. While the agency categorized and managed risks associated with its legacy spectrum IT systems, the NTIA did not have a risk management strategy and did not conduct an organization-wide risk assessment. NTIA also did not fully define user privilege levels for its systems.
In terms of interoperability, NTIA followed and implemented GAO’s leading practices for collaboration. The report also noted that NTIA fully adopted three of the five leading practices for data governance. However, the agency has no data governance plan to address conflicts that might arise from new standards.
GAO made five recommendations, all of which NTIA concurred with.