TSA Overhauled IT Access Controls After Audit
The agency automated account management to address persistent gaps in privileged user security.
Updated on Oct. 2, 2026 in Cybersecurity

Live Poll
Do you trust federal agencies to properly secure sensitive IT systems and employee data?
The Transportation Security Administration has implemented five audit recommendations to fix vulnerabilities in IT account oversight. The changes follow findings that the agency failed to consistently secure privileged access or disable accounts for departing employees.
Why it matters
The shift from manual, spreadsheet-based account management to an automated workflow addresses significant security risks in federal identity and access management. This remediation aims to prevent unauthorized access by closing systemic gaps that persisted for years due to staffing and procedural delays.
The agency previously managed thousands of accounts across 79 systems using manual spreadsheets. It has since applied mandated configuration fixes to two access management platforms to ensure compliance.
The players
Transportation Security Administration
A component of the Department of Homeland Security responsible for the security of public transportation systems.
Department of Homeland Security Office of Inspector General
An independent oversight body that audits and investigates programs within the Department of Homeland Security.
The details
TSA transitioned from a manual, spreadsheet-based management system to a centralized automated workflow via ServiceNow, a cloud-based platform for IT service management. This new process triggers an automated request flow from the Human Capital department to the Office of Information Technology when an employee separates from the agency. Staff also instituted monthly compliance meetings to ensure all privileged accounts—those with elevated system permissions—are reviewed and remediated according to federal standards.
Timeline
• 2019: Contractor security review work concluded.
• FY 2023-2024: TSA missed required privileged and service account reviews.
• April 2025: System assessment confirmed no unpatched vulnerabilities.
• July 24, 2026: TSA launched the new ServiceNow account-disable process.
• December 31, 2026: Expected completion of notification policy updates.
The Tech Race
The transition replaces antiquated, spreadsheet-based oversight with automated digital workflows now standard across secure federal networks. This alignment brings the agency closer to the centralized, audit-ready identity management protocols required of modern government IT infrastructure.
These changes improve internal security hygiene by automating account deactivation, reducing the window of opportunity for unauthorized access after a staff departure. The new process ensures that privileged accounts are audited monthly rather than through ad-hoc manual reviews.
The takeaway
The Transportation Security Administration has replaced legacy manual processes with automated identity management to resolve long-standing oversight vulnerabilities. Stakeholders should monitor the agency's policy update deadline on December 31, 2026, to assess full institutional compliance.
What happens next
The agency is scheduled to finalize updates to employee notification policies by December 31, 2026.
Further reading
Learn more about evolving Cybersecurity standards and federal agency compliance.
Source note: This article includes information reported by Executive Gov.
Live Poll
Do you trust federal agencies to properly secure sensitive IT systems and employee data?








