Independent Evaluation of NRC’s Use and Security of Social Media
Report Information
Recommendations
Revise the Problem Report to include a link to the Interim Guidance on the Use of Social Media.
Include social media security articles in the IT Security Awareness Newsletter, which is published and disseminated by the Computer Security Office (CSO) on a quarterly basis.
Establish a social media governance structure including representatives from the OGC, CSO (Policy Standards and Training Team, Cyber Situational Awareness, Analysis and Response Team), OIS (ICOD, Enterprise Architecture Team, Records and Archives Services Section, FOIA/Privacy Section) and OPA, and convene periodic meetings to guide NRC policies and practices around social media content, security, privacy, and records management.
Develop an SOP to track, monitor, and escalate to other NRC offices, comments posted on the NRC blog that do not adhere to NRC policies