ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Nuke commission operated several systems without authorization — audit

criticalExploit / PoC exploited in the wildimportance 60
Full article762 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The Nuclear Regulatory Commission operated several national security systems without authorization, potentially making classified information vulnerable or subject to unauthorized disclosure, according to an agency watchdog.

The Nuclear Regulatory Commission operated several national security systems without authorization, potentially making classified information vulnerable or subject to unauthorized disclosure, according to an agency watchdog.

The recently released Cybersecurity Act of 2015 audit of the NRC found seven national security systems did not have authorization to operate. The problem stemmed from a “lack of clarity in the agencywide policies and procedures over the systems and no integrated process across relevant offices,” according to the NRC inspector general’s report on its audit findings.

The IG found additionally that four national security systems did not have an “authority to use,” which NRC grants to systems owned by another agency (the agency would issue authority to operate as well); and two laptops were used without an authorization to operate.

Those laptops are no longer being used and will be taken out of service, the report noted.

On top of all of this, the inspector general noted there was no agencywide inventory of national security systems.

“A national security system is any information system (including any telecommunications system)… which involves intelligence and cryptologic activities, control of military forces, and weapons,” according to the report.

The report noted the IG didn’t find any instances of unauthorized access to classified information, but it cautioned that “without the appropriate level of protection, there is also a potential risk of unauthorized access to classified information.”

The report also explained the authorization process’ importance for analyzing the level of risk to information in a system.

“If a system is not characterized correctly, it may not have the appropriate level of protection,” the report explains. “For example, if a hard drive with classified information is put into a computer only authorized for unclassified information, there could be an information spill and the information may be vulnerable because the computer does not have the proper protections in place.”

The report recommends NRC clarify “agencywide policies and procedures over national security information systems” and assign responsibilities for implementing them. The IG also recommended the agency complete an inventory of its national security systems and periodically review it.

NRC management generally agreed with the report.

More Scoops

(Getty Images)

In most cities, nobody owns the whole network

July’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions…

(Getty Images)

How companies could share cyber risks without exposing their secrets

LONDON, ENGLAND – APRIL 14: SubConnect display a cable-mounted wet instrament sensor pod enabling remote monitoring away from the main sensor for subsea fibre optic cables during the UDT, Undersea Defence Technology 2026 at ExCel London on April 14, 2026 in London, England. Part of the Global Marine Group, SubConnect is a market leader in fibre-based cable jointing technology and subsea fibre optic cables from the design, testing, and supply of subsea joints and interconnectors, to their deployment, installation and maintenance operations. UDT 2026 brings together defence experts, industry leaders and innovators to address the challenges of the undersea domain, highlighting advanced technologies, including autonomous systems, sonar and secure communication networks. (Photo by John Keeble/Getty Images)

FCC passes new cybersecurity rules for emergency systems, undersea cables

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/nuke-commission-operated-several-systems-without-authorization-audit/