Separate audit totals describe the same systems

A federal cloud-security audit reported incomplete continuous monitoring in five selected systems and incomplete incident-response practices in five systems. Were those ten separate problem systems, or did the weaknesses overlap? What’s the Scoop With Broach matched the agency and system-type rows in the report’s three evaluation tables. The same five systems accounted for both sets of incomplete practices.

The overlap represents five of the eight selected systems, or 62.5%. Three of those five also fell short on the third practice: service-level agreements defining security performance metrics, measurement and enforcement. The analysis therefore identifies a concentration of overlapping oversight weaknesses rather than three independent tallies that can be added together.

Newsroom crosswalk of GAO Tables 1–3; final report evaluations
Agency / system typeMonitoringIncident responseService-level agreement
State / platformPartialPartialFull
State / softwareFullFullFull
Transportation / platformFullFullFull
Transportation / softwareFullFullFull
Veterans Affairs / platformPartialPartialNot implemented
Veterans Affairs / softwarePartialPartialPartial
Small Business Administration / platformPartialPartialFull
Small Business Administration / softwarePartialPartialNot implemented
Sources: GAO-26-108443, Tables 1, 2 and 3

Contract language and day-to-day oversight are different checks

State’s selected platform system and SBA’s selected platform system met the service-level-agreement practice while falling short on monitoring and incident response. That comparison shows why a complete agreement is not, by itself, evidence that every operational oversight practice has been carried out.

For example, GAO found that State had not supplied evidence of reviewing its provider’s continuous-monitoring deliverables for the platform system. For the two VA systems, the monitoring shortfall involved collection and review of audit logs. These are agency responsibilities in the reviewed arrangements; a cloud provider’s security authorization does not erase the customer agency’s obligations.

The table’s “partial” rating also does not mean every underlying control was absent. GAO evaluated several criteria within each practice. Some systems met most criteria but lacked a specific procedure, review or record. The crosswalk preserves those final practice-level ratings rather than converting them into an invented vulnerability score.

An agency response changed the final findings

Transportation challenged a draft finding concerning vulnerability-management tools for its software system and supplied additional documentation. GAO accepted that evidence, removed the finding and withdrew the associated recommendation. Its final tables therefore show both Transportation systems fully implementing all three selected practices. This report uses those final results.

State neither agreed nor disagreed with its two recommendations and described procedures it had developed or drafted. GAO said the response still did not demonstrate that the provider-deliverable reviews had occurred. VA agreed with five recommendations and described planned actions by November 2026. SBA did not provide comments on the draft, according to GAO. Those are responses to the federal audit; this publication did not conduct separate agency interviews.

A targeted comparison, not a government-wide breach estimate

The underlying report was published June 25, 2026. GAO’s tracker still listed its 12 recommendations as open when checked October 3. That status does not prove that no corrective work has occurred; it means GAO has not confirmed closure.

The original contribution here is a row-by-row join of three primary-record tables using agency and platform-or-software system type as the key. “Platform” means Platform as a Service; “software” means Software as a Service. The analysis establishes which selected systems share gaps across practices and incorporates the draft-to-final correction documented in the agency responses.

Eight selected systems at four agencies are not a representative census of federal cloud services. This investigation did not test systems, access agency data or establish that an attacker exploited any weakness. The accountability issue supported by the records is overlapping gaps in how the selected agencies monitor and prepare to respond to incidents—not an allegation that five systems suffered breaches.

Sources and further reading

GAO-26-108443, June 25, 2026; recommendation status checked October 3 ↗

Full report, evaluation tables and agency responses ↗