Nuke commission operated several systems without authorization — audit
Full article762 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The Nuclear Regulatory Commission operated several national security systems without authorization, potentially making classified information vulnerable or subject to unauthorized disclosure, according to an agency watchdog.
The Nuclear Regulatory Commission operated several national security systems without authorization, potentially making classified information vulnerable or subject to unauthorized disclosure, according to an agency watchdog.
The recently released Cybersecurity Act of 2015 audit of the NRC found seven national security systems did not have authorization to operate. The problem stemmed from a “lack of clarity in the agencywide policies and procedures over the systems and no integrated process across relevant offices,” according to the NRC inspector general’s report on its audit findings.
The IG found additionally that four national security systems did not have an “authority to use,” which NRC grants to systems owned by another agency (the agency would issue authority to operate as well); and two laptops were used without an authorization to operate.
Those laptops are no longer being used and will be taken out of service, the report noted.
On top of all of this, the inspector general noted there was no agencywide inventory of national security systems.
“A national security system is any information system (including any telecommunications system)… which involves intelligence and cryptologic activities, control of military forces, and weapons,” according to the report.
The report noted the IG didn’t find any instances of unauthorized access to classified information, but it cautioned that “without the appropriate level of protection, there is also a potential risk of unauthorized access to classified information.”
The report also explained the authorization process’ importance for analyzing the level of risk to information in a system.
“If a system is not characterized correctly, it may not have the appropriate level of protection,” the report explains. “For example, if a hard drive with classified information is put into a computer only authorized for unclassified information, there could be an information spill and the information may be vulnerable because the computer does not have the proper protections in place.”
The report recommends NRC clarify “agencywide policies and procedures over national security information systems” and assign responsibilities for implementing them. The IG also recommended the agency complete an inventory of its national security systems and periodically review it.
NRC management generally agreed with the report.
More Scoops
In most cities, nobody owns the whole network
July’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions…
How companies could share cyber risks without exposing their secrets
FCC passes new cybersecurity rules for emergency systems, undersea cables
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/nuke-commission-operated-several-systems-without-authorization-audit/