U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Assessment of NRC’s Wireless Devices

Report Information

Date Issued
Report Number
OIG-10-A-18
Report Type
Audit
Joint Report
No
Agency Wide
No (location specific)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

Revise the NRC Remote E-mail and Wireless Policy addendum to Management Directive 12.5 to include a policy statement that specifies high-level guidance for configuration of the BlackBerry-based remote access capability. This policy statement should be general but should include guidance regarding organizational needs for remote access to e-mail, remote access to files and servers, text messaging and other communications functions with handheld devices, and use of handheld devices to provide network connectivity (tethering).

Revise the NRC Remote E-mail and Wireless Policy addendum to Management Directive 12.5 to include a policy statement that provides guidance for BlackBerry account management. This policy statement should be general but should include guidance for account creation, deletion, and periodic review. In addition, the policy statement should describe organizational policy for implementing “least privilege” for BlackBerry user groups.

Provide refresher training for ITI security and system administrators on separation of duties.

Revise and implement procedures for audit log storage and review of BlackBerry Enterprise Server (BES) logs, and use the existing audit log management system to support auditing of BES.

Conduct a review of the configuration settings and functions for the BES to ensure only required services are provided and that the configuration is correct and consistent with organizational policy.