In May 2023, U.S. Customs and Border Protection‘s leadership issued a formal directive requiring all information technology applications to consolidate their access controls under a centralized security system. It was a reasonable mandate: CBP recognized that its IT infrastructure had become fragmented and chaotic, with different applications using different security protocols. Centralization would improve security and make it easier to track who had access to what.
Three years later, the order remains largely unenforced.
The directive, issued as IPL-2022-05-0253 in May 2023, required all CBP application owners to “evaluate the feasibility of enrolling in” CBP’s Access Management System (AMS)—the centralized platform designed to manage user access across the agency’s 100 major IT applications.
According to a Department of Homeland Security Office of Inspector General audit released September 4, 2026, CBP never followed up.
“The directive required all CBP application owners to evaluate the feasibility of enrolling in the AMS. Yet this policy was neither fully implemented nor enforced because CBP did not develop a process to track and monitor compliance with the directive, and some application teams disagreed with the directive’s requirements.”
In other words: CBP issued an order, and then failed to build any mechanism to ensure the order was obeyed.
Why This Matters: The Fragmentation Problem
CBP operates approximately 100 major IT applications. Each one stores, processes, or accesses sensitive information: law enforcement data, biometric records, border security intelligence, personal information of travelers.
For security to work at scale, CBP needs to know, at any given moment, who has access to what systems and why. This requires a centralized system of record—a single source of truth for user access across all applications.
Before the May 2023 directive, CBP didn’t have that. Instead, the agency relied on individual application owners to manage access for their own systems. This approach created what the OIG audit describes as “oversight challenges for ensuring all accounts were monitored in accordance with requirements.”
It’s a diplomatic way of saying: CBP had no idea whether its access controls were actually working.
“CBP acknowledged that it could not identify all applications on its network,” the OIG audit states. Think about that: CBP couldn’t account for all of its own applications.
This is not a minor technical issue. If CBP can’t identify all applications on its network, then CBP can’t secure them. Unidentified applications are unmonitored applications. Unmonitored applications are vulnerable applications.
The Directive’s Core Requirement
The May 2023 Identity Credential and Access Management Directive was CBP’s attempt to fix this problem at the structural level. The order required all application owners to evaluate whether their systems could be integrated into the centralized AMS.
For applications that *could* be integrated, the directive implied they *should* be integrated. For applications that couldn’t be integrated (due to technical limitations), the directive required them to maintain their own rigorous access control standards while remaining outside the centralized system.
In principle, this makes sense: Consolidate what you can, and tightly control what you can’t.
In practice, CBP didn’t build any mechanism to enforce it.
“CBP did not develop a process to track and monitor compliance with the directive,” the OIG found.
This is a critical failure point. A directive without enforcement is merely a suggestion. And in a large bureaucracy, suggestions are easy to ignore.
The OIG identified specific cases of non-compliance. “During our audit, we found not all application owners appropriately monitored their accounts. For example, one major application team we met with did not review their application service accounts in fiscal years 2023 and 2024, as required.”
One major application team. Not reviewing accounts. For an entire two-year period. As required by policy.
And no one noticed, because no one was checking.
Organizational Resistance
The OIG audit includes a phrase that deserves close attention: “some application teams disagreed with the directive’s requirements.”
This is remarkable. A formal directive from CBP’s leadership on a critical security matter, and application teams simply disagreed with it.
The audit does not elaborate on which teams disagreed, what their objections were, or what CBP leadership did in response to the disagreement. But the fact that disagreement existed and persisted suggests CBP’s leadership lacked either the authority or the will to enforce compliance.
There are legitimate reasons why an application team might resist centralization:
- Technical concerns: Their legacy system might not be compatible with the centralized platform
- Operational concerns: Integration might cause service disruptions or performance degradation
- Resource constraints: Integration requires staff time and potentially licensing costs
- Autonomy concerns: Application teams might prefer maintaining control over their own access management
Any of these reasons could be valid. But a security directive isn’t something that gets negotiated away because a team prefers autonomy or fears disruption. Security is not optional.
The fact that CBP issued a directive and then allowed disagreement to derail it suggests that application teams had more power than the directive issuer. This is an organizational dysfunction issue.
The Audit Timeline: How CBP Fell Behind
The chronology is revealing:
– May 2023: CBP’s Identity Credential and Access Management Directive is issued
– October 2024 – December 2025: OIG audit is conducted
– September 4, 2026: OIG audit is released, revealing non-compliance
The audit took place approximately 18 months after the directive was issued. At that point, CBP had not yet developed a process to track compliance.
This isn’t incompetence. This is a pattern: Issue a directive, don’t follow up, and when an auditor asks what happened, explain that enforcement mechanisms weren’t built.
The OIG’s recommended corrective actions are telling:
- “Identify all applications not in compliance with the Identity Credential and Access Management Directive” (Estimated completion: December 31, 2026)
- “Develop and implement a process to monitor and enforce compliance with the Identity Credential and Access Management Directive” (Estimated completion: December 31, 2026)
- “Develop and implement controls to monitor whether applications not integrated with CBP’s access management system comply with DHS and CBP privileged account security requirements” (Estimated completion: December 31, 2026)
In other words: In September 2026, CBP is still in the process of doing things it should have done before issuing the May 2023 directive.
CBP’s Response: Another Directive
In response to the OIG audit, CBP agreed to the recommendations and provided corrective action plans.
The agency’s response to the “monitor and enforce compliance” recommendation is instructive: “CBP’s Office of Information and Technology, Cybersecurity Directorate will develop and implement a standardized process to monitor and enforce compliance with the Identity Credential and Access Management Directive. This process will include regular reviews of application entitlements and coordination with application owners to ensure alignment with access management requirements. CBP will work to address legacy practices that allow certain applications to operate outside the centralized Identity Management platform.”
This is bureaucratic language for: “We will now do what we should have done in May 2023.”
CBP also acknowledges that building the inventory is itself a challenge: “CBP’s Office of Information and Technology, Cybersecurity Directorate will initiate an enterprise-wide effort to catalog all applications in use across the organization. This will include leveraging existing resources such as Mobius, Information Systems Security Manager/Information System Security Officer distribution lists, and other authoritative sources to develop a comprehensive inventory.”
In 2023, CBP issued a directive to fix a security problem. In 2026, CBP is still trying to inventory what applications it owns. The direction of progress is clear, but the pace is glacial.
A Symptom of Larger Dysfunction
The May 2023 directive failure is not an isolated incident. It’s part of a pattern visible throughout the OIG audit.
CBP issued account disablement policy directives in August 2023 (Directive 51715-006 and Directive 1210-007B). The audit found that supervisors and contracting officers still weren’t following them in 2023-2024.
CBP’s access management system existed and was supposed to work, but many applications weren’t enrolled in it, so it didn’t actually manage access to those applications.
CBP had defined processes and had built systems, but the systems weren’t integrated and the processes weren’t enforced.
This is the hallmark of organizational dysfunction: scattered implementation, inconsistent enforcement, and reactive problem-solving instead of proactive governance.
An alternative model would look like this:
- Issue a directive with specific compliance requirements
- Simultaneously build enforcement mechanisms
- Establish timelines and penalties for non-compliance
- Assign clear accountability for each component
- Monitor compliance proactively
- Address non-compliance immediately
CBP’s actual model:
- Issue a directive
- Wait for voluntary compliance
- Eventually, notice that compliance isn’t happening
- When audited, admit that no enforcement mechanism was built
- Promise to build enforcement mechanisms in the future
The Fundamental Question
The May 2023 directive came after years of known, documented access control problems at CBP. The OIG had audited CBP’s access controls before. CBP knew its infrastructure was fragmented and inconsistently managed.
So when CBP’s leadership decided to issue a directive requiring centralization, that decision presumably came with an understanding that centralization would require enforcement and monitoring.
Yet no enforcement mechanism was built. No compliance monitoring was established. No timeline or accountability structure was created.
Why?
Possibilities:
- Resource constraints: Monitoring compliance requires staff and budget that weren’t allocated
- Technical limitations: The systems needed to monitor compliance weren’t ready
- Leadership weakness: CBP’s CIO lacked authority to enforce directive compliance
- Organizational fragmentation: Application owners reported to different chains of command and had different priorities
- Competing demands: CBP’s leadership prioritized other initiatives over security modernization
The OIG audit doesn’t answer this question. CBP’s response doesn’t address it. It remains unexplained.
What Happens Now
CBP’s corrective action plans commit to:
- Completing application inventory by December 31, 2026
- Implementing compliance monitoring and enforcement by December 31, 2026
- Addressing legacy practices that bypass centralized controls by December 31, 2026
If these timelines hold, CBP will finally, in late 2026, be implementing enforcement mechanisms for a directive issued in May 2023.
That’s 3.5 years between issuing a security directive and building the enforcement mechanisms to actually make it work.
The OIG will presumably audit CBP again in a year or two to determine whether the corrective actions actually solved the problem. If history is any guide, the answer will depend on whether CBP maintains the monitoring process over time or lets it atrophy.
A directive that goes unenforced for three years suggests something deeper than a one-time oversight. It suggests that enforcing security directives isn’t actually prioritized in CBP’s organizational culture, even when the directive comes from leadership.
That’s a pattern worth watching.
References and Links
– Full OIG Report (OIG-26-28): CBP’s IT Access Control Deficiencies Introduced Critical Risk to IT Systems and Sensitive Information — OIG-26-28-Sep26.pdf — Released September 4, 2026 by the DHS Office of Inspector General
– OIG Report Section: Key Finding 2: “CBP Did Not Ensure All Accounts Were Periodically Reviewed” (pages 4-5 of report)
– CBP Policy Documents (referenced in audit):
- CBP Identity Credential and Access Management Directive (IPL-2022-05-0253, May 2023)
- CBP Directive 51715-006: Separation and Reassignment Directive for CBP Employees (August 2023)
- CBP Directive 1210-007B: Tracking of Contractor Employees (August 2023)
– DHS Policy (referenced in audit):
- DHS 4300A: Information Technology System Security Program, Sensitive Systems (v. 13.4, December 2024)
- NIST 800-53r5 Control Baselines
– DHS OIG Homepage: www.oig.dhs.gov
Editor’s Notes
– CBP was asked for specifics about: (1) which application teams disagreed with the directive and on what grounds; (2) why no enforcement mechanism was built in May 2023; (3) what resources and timeline were originally planned for the directive’s implementation; and (4) what changed between May 2023 and September 2026 that prompted CBP to prioritize compliance monitoring. CBP declined to provide additional information beyond its written response to the OIG audit.
– The CBP Identity Credential and Access Management Directive (IPL-2022-05-0253) is referenced in the OIG audit but the full text does not appear in the public report. Bureaucracy Times FOIA’d this document for fuller analysis; results pending.
– The OIG audit notes that “CBP was aware of these challenges and took action to address them in May 2023” by issuing the directive. This confirms that CBP’s leadership recognized the fragmentation problem. The failure was in execution, not awareness.
– All of CBP’s corrective action timeline commitments (December 31, 2026 and August 31, 2026) fall within the current fiscal year and represent commitments made to the OIG in response to the audit. These are not yet guaranteed to be achieved.
