Sorry, you need to enable JavaScript to visit this website.
U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Performance Audit of the U.S. NRC’s Implementation of the Federal Information Security Modernization Act of 2014 for Fiscal Year 2026

Report Information

Date Issued
Report Number
ROA-OIG-NRC-26-A-04
Report Type
Audit
Joint Report
No
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

We recommend that the NRC Chief Data Officer, in coordination with the Office of the Chief Information Officer (OCIO) Division of Data, Artificial Intelligence, Technology and Applications, complete ongoing efforts to develop and maintain a comprehensive inventory of data and corresponding metadata in accordance with the requirements of the Open Government Data Act and OMB M-25-05.

We recommend that the NRC OCIO, in coordination with the ITI, ADAMS, and HPCS ISSMs, remediate identified vulnerabilities within the timeframes defined in the NRC Information Security Continuous Monitoring Process.

We recommend that the NRC OCIO, in coordination with the ITI, ADAMS, and HPCS ISSMs, ensure that vulnerabilities not remediated within the required timeframes are documented and tracked through plans of action and milestones or formally approved deviations, including documented remediation plans, milestones, and risk acceptance decisions, as applicable.