OIG says CBP failed to secure its mobile devices
An audit by the Office of Inspector General (OIG) at the Department of Homeland Security (DHS) has found that U.S. Customs and Border Protection (CBP) did not effectively manage and secure its mobile devices. This, OIG said in its report, resulted in vulnerabilities and higher susceptibility to cyberattacks, potential unauthorized access to law enforcement and operational sensitive information, and waste and abuse from under- or over-usage.
CBP issues mobile devices to its personnel and contractors to aid their work, but OIG found that the agency did not consistently implement required security settings to protect its mobile devices or mitigate risks from applications installed on these devices; use its mobile device management system to fully manage and secure its mobile devices; or address software vulnerabilities within the mobile device management system.
The watchdog said CBP also failed to increase monitoring and protection for devices used outside the United States, which could pose a higher risk of cyberattacks. The agency also did not perform the required steps to reduce risks associated with the disposal, loss, or theft of its mobile devices, or monitor its mobile devices for under- or over-usage.
“CBP allowed mobile devices to operate without completing a security authorization process to ensure required security controls; did not establish or implement sufficient security policies and processes; relied on unclear or contradictory guidance; and did not address its increased mobile device losses,” OIG said. “The deficiencies we identified pose significant vulnerabilities. CBP’s less secure configurations and resulting vulnerabilities could allow an attacker to execute malicious code and compromise DHS systems or access unauthorized or sensitive data. In addition, if CBP does not monitor devices for unauthorized travel or properly prepare mobile devices for international use, it faces an increased risk that foreign adversaries could intercept CBP communications and that bad actors could gain access to DHS systems and information.”
To address the shortcomings, OIG has made 14 recommendations. CBP has concurred and set out planned corrective actions to address these. Much of the policy-based recommended actions are expected to be completed by the end of the calendar year. Others, such as improving property management oversight, are scheduled to be fully addressed by August 2026.