Performance Audit of the U.S. Nuclear Regulatory Commission’s Implementation of the Federal Information Security Modernization Act of 2014 for Fiscal Year 2024 Region IV: Arlington, Texas
Report Information
Recommendations
We recommend that NRC management investigate methods of identifying inactive user accounts and improving its internal controls over inactivity to ensure that it disables network user accounts after 90 days of inactivity.
Target Completion Date: Fiscal Year 2026, Quarter 1.<br />
OIG Analysis: The OIG will close this recommendation after reviewing and confirming the evidence that NRC management investigated methods of identifying inactive user accounts and improved its internal controls over inactivity to ensure that network user accounts are disabled after 90 days of inactivity.
We recommend that Region IV management ensure that the Region IV – Sensitive Area Access Review includes the data center and that Region IV management maintains evidence of this review.
OIG Analysis: The OIG reviewed and confirmed the evidence that the Region IV—Sensitive Area Access Review includes the data center, and that Region IV management maintains evidence of this review. This recommendation is now closed.