Performance Audit of the U.S. NRC’s Implementation of the Federal Information Security Modernization Act of 2014 for Fiscal Year 2026
Report Information
Recommendations
We recommend that the NRC Chief Data Officer, in coordination with the Office of the Chief Information Officer (OCIO) Division of Data, Artificial Intelligence, Technology and Applications, complete ongoing efforts to develop and maintain a comprehensive inventory of data and corresponding metadata in accordance with the requirements of the Open Government Data Act and OMB M-25-05.
We recommend that the NRC OCIO, in coordination with the ITI, ADAMS, and HPCS ISSMs, remediate identified vulnerabilities within the timeframes defined in the NRC Information Security Continuous Monitoring Process.
We recommend that the NRC OCIO, in coordination with the ITI, ADAMS, and HPCS ISSMs, ensure that vulnerabilities not remediated within the required timeframes are documented and tracked through plans of action and milestones or formally approved deviations, including documented remediation plans, milestones, and risk acceptance decisions, as applicable.