U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Independent Evaluation of NRC’s Implementation of the Federal Information Security Modernization Act of 2014 For Fiscal Year 2019

Report Information

Date Issued
Report Number
OIG-20-A-06
Report Type
Inspection / Evaluation
Joint Report
No
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

Use the fully defined ISA to assess enterprise, business process, and information system level risks.

Fully define NRC’s ISA across the enterprise and business
processes and system levels.

Identify and implement a software whitelisting tool to detect
authorized software and block the risk of unauthorized software on its network.

Perform an assessment of role-based privacy training gaps.

Identify individuals having specialized role-based responsibilities for PII or activities involving PII and develop role-based privacy training for them.

Agency Response Dated March 20, 2024: As a result of the assessment referenced in recommendation 4, the NRC will identify individuals having specialized role-based responsibilities for PII or activities involving PII and develop role-based privacy training for them. The agency plans to complete the associated training development and implementation by the first quarter (Q1) of FY 2025. Target Completion Date: FY 2025, Q1
OIG Analysis: The OIG will close this recommendation after getting assurance from evidence that the agency has identified individuals having specialized role-based responsibilities for PII [personally identifiable information] or activities involving PII and has developed role-based privacy training for them. Status: Open: Resolved.