logo

HHS OIG Report Underscores Challenges of Securing the Cloud

ID: d3b996dd-ab03-5538-b363-df5fd865068d

STIX ID: report--d3b996dd-ab03-5538-b363-df5fd865068d

Feed Name: Qualys Blog

Date Published: 2024-08-15

Date Updated: 2026-04-28

Author: Jason White

...
...

On July 22, 2024, HHS OIG reported significant cloud security shortcomings at HHS Office of the Secretary, including 13 undocumented cloud systems, skills gaps among System Security Officers, and 12 noncompliant controls such as missing MFA for privileged accounts and inadequate access controls on storage. The audit recommended establishing procedures to ensure complete/accurate cloud inventories, remediating control gaps per NIST SP 800-53, implementing a strategy for continuous configuration assessment and rapid remediation, and ensuring qualified SSOs. The document also advocates for CNAPP-driven approaches—asset discovery, CSPM, vulnerability detection, CDR, and risk prioritization—and markets Qualys TotalCloud as a FedRAMP-authorized solution to automate visibility, compliance, and threat protection across multi-cloud environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.