Federal Agencies Lag Behind on CISA Cloud Security Mandate, Report Finds
A new watchdog report released Wednesday reveals that almost nine out of ten civilian executive‑branch agencies missed the summer deadline for adopting the Cybersecurity and Infrastructure Security Agency's (CISA) cloud security directives, leaving a substantial portion of the federal IT environment vulnerable to cyber threats.
The review, conducted by the agency's Office of Inspector General, examined compliance records across all 24 civilian departments and agencies. It found that only a handful met the required milestones, while the majority either delayed implementation or failed to document progress altogether.
CISA issued the cloud security guidance last year to standardize how federal entities protect data stored in commercial cloud services. The directives call for a suite of controls, including continuous monitoring, encryption, and identity‑access management, designed to align federal cloud use with the nation’s broader cybersecurity strategy.
Officials warn that the shortfall amplifies the risk of data breaches and ransomware attacks, especially as agencies increasingly rely on third‑party cloud platforms for mission‑critical operations. Non‑compliance could also impede the federal government’s ability to share information securely across departments.
Analysts attribute the lag to a combination of factors: limited staffing, competing modernization projects, and the complexity of integrating legacy systems with new cloud architectures. Budget constraints and a shortage of skilled cybersecurity personnel have further hampered agencies’ ability to meet the tight timeline.
The report recommends that CISA work with lagging agencies to develop realistic rollout plans, while urging congressional oversight to ensure adequate funding and accountability. Agencies are expected to submit remediation timelines in the coming weeks, and failure to do so could trigger additional scrutiny or corrective actions from the administration.
Comments (0)
Be the first to comment.
Join the discussion