DOGE: Congress and the Public Lack Assurance That Systems and Data Were Protected at Multiple Agencies

Government Accountability Office Version 1 original current

Imported from official source

What GAO Found Four agencies in GAO’s review—the Consumer Financial Protection Bureau (CFPB), Department of Education, National Oceanic and Atmospheric Administration (NOAA), and Securities and Exchange Commission (SEC)—established Department of Government Efficiency (DOGE) teams and collectively reported that those teams had access to more than 23 systems. These systems were used to manage contracts, grants, human resources, and finances and contained sensitive information, including personally identifiable information (PII). However, whether DOGE team members had specific system permissions or were allowed certain actions (e.g., view PII or modify data) could not be determined based on the information provided. The other two agencies in GAO’s review—Small Business Administration (SBA) and the Department of Veterans Affairs (VA)—did not respond to requests for information to which systems DOGE team members had access to. CFPB, Education, and SEC provided limited documentation related to the extent to which they implemented controls for ensuring adherence to their IT security rules and their DOGE team members followed the rules. For example, CFPB demonstrated that six DOGE team ...

This version

Version
1 of 1
Recorded
October 03, 2026 20:42
Change
Initial
Content hash
6be0d66448f801025461b2bae976eb25
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.