About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline

GAO-24-107307 1 (2024-06-06)

handle is hein.gao/gaoqna0001 and id is 1 raw text is: U.S. GOVERNMENT ACCOUNTABILITY OFFICE
441 G St. N.W.                                                  Comptroller General
Washington, DC 20548                                            of the United States
June 6, 2024
The Honorable Thomas J. Vilsack
Secretary of Agriculture
U.S. Department of Agriculture
1400 Independence Avenue, SW
Washington, D.C. 20250
Priority Open Recommendations: Department of Agriculture
Dear Secretary Vilsack:
The purpose of this letter is to provide an update on the overall status of the U.S. Department of
Agriculture's (USDA) implementation of GAO's recommendations and to call your continued
personal attention to areas where open recommendations should be given high priority.1 In
November 2023, we reported that, on a government-wide basis, 75 percent of our
recommendations made 4 years ago were implemented.2 USDA's recommendation
implementation rate was 82 percent. As of May 2024, USDA had 109 open recommendations.
Fully implementing these open recommendations could significantly improve agency operations.
I appreciate your leadership and commitment to strengthening USDA's efforts to implement our
recommendations, including the continued use of a working group to address priority and other
open recommendations. Since our May 2023 letter, USDA has implemented five of our 12 open
priority recommendations.
*  In October 2023, USDA provided updated policies and procedures that address coordination
between cybersecurity risk management and enterprise risk management functions, as we
recommended in July 2019.3 Specifically, the updated policies and procedures describe
USDA's enterprise risk management program, including the elevation of cybersecurity risks,
which involves every USDA mission area and staff office. By taking these steps, USDA is
better positioned to address significant cybersecurity risks in the context of other risks, and
their potential impacts on the mission of the agency.
*  In July 2023, USDA updated procedures for its risk management process that specify the
roles of the senior agency official for privacy and other officials in key risk management
1Priority recommendations are those that GAO believes warrant priority attention from heads of key departments or
agencies. They are highlighted because, upon implementation, they may significantly improve government
operations, for example, by realizing large dollar savings; eliminating mismanagement, fraud, and abuse; or making
progress toward addressing a high-risk or duplication issue.
2GAO, Performance and Accountability Report: Fiscal Year 2023, GAO-24-900483 (Washington, D.C.: Nov. 15, 2023).
3GAO, Cybersecurity: Agencies Need to Fully Establish Risk Management Programs and Address Challenges, GAO-
19-384 (Washington, D.C.: July 25, 2019).

GAO-24-107307 USDA Priority Open Recommendations

Page 1

What Is HeinOnline?

HeinOnline is a subscription-based resource containing thousands of academic and legal journals from inception; complete coverage of government documents such as U.S. Statutes at Large, U.S. Code, Federal Register, Code of Federal Regulations, U.S. Reports, and much more. Documents are image-based, fully searchable PDFs with the authority of print combined with the accessibility of a user-friendly and powerful database. For more information, request a quote or trial for your organization below.



Contact us for annual subscription options:

Already a HeinOnline Subscriber?

profiles profiles most