U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Independent Evaluation of NRC's Implementation of the Federal Information Security Modernization Act of 2014 for FY 2018

Report Information

Date Issued
Report Number
OIG-19-A-08
Report Type
Inspection / Evaluation
Joint Report
Yes
Participating OIG
Nuclear Regulatory Commission OIG
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

Develop and implement a process to remove all non-standard software that has not been approved by an authorized agency official.

Implement a process to manage non-standard software toensure the software is properly approved and inspected forsecurity weaknesses before the software is installed on NRC’s network.

Monitor the approved installed software on NRC’s network todetermine whether it is still in use, periodically inspect thesoftware for known vulnerabilities, and mitigate any vulnerabilities found.

Develop and establish processes and procedures to governthe installation of non-standard software, including processes and procedures on determining impact to agency operations or cybersecurity.

Implement a process to remove unsupported software fromNRC networks.