Performance Audit of the Defense Nuclear Facilities Safety Board's Implementation of the Federal Information Security Modernization Act of 2014 for Fiscal Year 2026
Report Information
Recommendations
We recommend that the DNFSB develop and document a formal security assessment plan for the GSS and perform an independent security control assessment, ensuring that the assessors document the results in an assessment report that includes all identified control deficiencies.
We recommend that the DNFSB document mitigating controls in the POA&Ms in accordance with its System and Information Integrity Operating Procedures for vulnerabilities it cannot remediate within the required timeframe.
We recommend that the DNFSB review its POA&Ms monthly and re-evaluate the mitigating controls identified in the POA&Ms to ensure the system remains protected, in accordance with its System and Information Integrity Operating Procedures.
We recommend that the DNFSB develop, document, and implement a process to conduct system-specific BIAs for the GSS and other information systems, in accordance with applicable NIST SP 800-34 contingency planning guidance.