GAO

DOGE: Congress and the Public Lack Assurance That Systems and Data Were Protected at Multiple Agencies

What GAO Found Four agencies in GAO’s review—the Consumer Financial Protection Bureau (CFPB), Department of Education, National Oceanic and Atmospheric Administration (NOAA), and Securities and Exchange Commission (SEC)—established Department of Government Efficiency (DOGE) teams and collectively reported that those teams had access to more than 23 systems. These systems were used to manage contracts, grants, human resources, and finances and contained sensitive information, including personally identifiable information (PII). However, whether DOGE team members had specific system permissions or were allowed certain actions (e.g., view PII or modify data) could not be determined based on the information provided. The other two agencies in GAO’s review—Small Business Administration (SBA) and the Department of Veterans Affairs (VA)—did not respond to requests for information to which systems DOGE team members had access to. CFPB, Education, and SEC provided limited documentation related to the extent to which they implemented controls for ensuring adherence to their IT security rules and their DOGE team members followed the rules. For example, CFPB demonstrated that six DOGE team members received a privacy briefing and four completed security training. Such training is important for ensuring that system users are aware of their responsibilities for addressing cyber and privacy risks. However, the bureau did not provide evidence that the remaining team members completed the necessary training. Education provided IT system rules of behavior documents signed by five of the six DOGE team members. Acknowledgment of these documents is key to holding system users accountable for not following IT security rules. However, the department did not respond to GAO’s repeated requests for the document signed by the remaining team member. SEC demonstrated that a background check was underway for one team member and had been conducted for another team member in 2017. These investigations are important for ensuring that system users can be trusted with sensitive information. However, the agency did not respond to GAO’s requests to confirm that the 2017 investigation was favorably adjudicated. In addition, NOAA, SBA, and VA did not respond to requests for information on whether they implemented controls for ensuring adherence to the IT security rules and their DOGE team members followed those rules. Without the ability to examine the requested information, Congress and the public lack assurance that the six reviewed agencies implemented controls needed to ensure DOGE team members appropriately secured information. GAO has ample statutory authority to both conduct this work and obtain the information in support of Congress. Despite this clear authority, the agencies did not respond to GAO’s requests for the information needed to fully answer the questions posed by members of Congress. Agencies cited various reasons for not fully responding to GAO’s requests, but their stated reasons do not alter or diminish GAO’s statutory right of access to this information. Why GAO Did This Study The United States DOGE Service (USDS) was created by executive order to maximize government efficiency by modernizing technology. The order also called for the heads of executive branch agencies to establish DOGE teams that work with USDS. GAO was asked to review efforts to ensure that agency DOGE teams appropriately protected the systems and information they accessed at multiple agencies. The objectives of this review were to (1) describe the systems to which the DOGE teams at six agencies had been provided access and (2) evaluate the extent to which these agencies implemented controls to ensure that the DOGE team followed the agency’s IT security rules and the DOGE team followed those rules. This report focuses on the following agencies: Education, VA, CFPB, NOAA, SEC, and SBA. GAO analyzed documentation related to DOGE access to agency systems, IT security rules, security and privacy training, and background investigations. GAO provided a draft of this report to the six agencies for review and comment. Education, NOAA, SBA, SEC, and VA stated that they did not have any comments. CFPB expressed concerns with the accuracy of the report. GAO stands by the accuracy of the facts presented in the report. For more information, contact Nick Marinos at marinosn@gao.gov.

Categories -

Coast Guard: Additional Action Needed to Address Marine Firefighting Challenges

What GAO Found Fires on vessels are among the most dangerous and challenging incidents to which firefighters can respond. Vessels may also carry hazardous cargo, like lithium-ion batteries, further complicating marine firefighting responses. According to U.S. Coast Guard data, there were 886 nearshore marine fires that occurred between 2015 and 2025. About one quarter (206) of these resulted in either death, injury, over $200,000 in damage, or a total loss of the vessel. The U.S. Coast Guard is the principal federal agency responsible for overseeing marine safety. For marine firefighting, the Coast Guard plays a coordinating role while land-based fire departments extinguish fires. Following a marine fire that resulted in two firefighter deaths in 2023, the Coast Guard established a task force to address various marine firefighting challenges. The task force has taken several steps to address them but gaps remain. Examples of Firefighting Challenges, Coast Guard Actions, and Gaps Designating consistent Coast Guard field personnel to lead coordination before marine fires occur, facilitating more hands-on training for firefighters on vessels, and establishing an information sharing mechanism would help ensure firefighters have the knowledge and skills necessary to safely and effectively extinguish vessel fires. Further, developing guidance on what warrants vessel response plan activation would help ensure resources are quickly mobilized and better ensure the safety of firefighters. The number of vessels that use alternative fuels continues to grow. However, legal limitations prevent the Coast Guard from requiring nontank vessels that use alternative fuels—such as ferries powered by lithium-ion batteries—to have vessel response plans related to hazardous substance discharges. These limitations predate the widespread use of alternative fuels. Having that authority would empower the Coast Guard to better ensure vessels and firefighters can quickly receive assistance in the event of a fire. Why GAO Did This Study The Coast Guard has issued regulations requiring certain vessels to have response plans that identify the resources that would respond to marine fires related to oil discharges. The National Defense Authorization Act for Fiscal Year 2026 includes a provision for GAO to review, among other things, the Coast Guard’s efforts related to marine firefighting. This report examines (1) how frequently nearshore marine fires occur and the characteristics of those fires and (2) what challenges exist in marine firefighting and how the Coast Guard is addressing them. GAO analyzed Coast Guard data for 2015 through 2025; reviewed Coast Guard guidance and investigative reports; and interviewed Coast Guard officials, fire chiefs based in seven Coast Guard sectors, and representatives from maritime and firefighting stakeholder associations.

Categories -

Pages